- WhatsApp is testing a new tool called Scam Alert that spots scam messages right on your phone.
- The tool never sends your chats to Meta, and it keeps your messages fully encrypted.
- Meta built a private checking system so it can see if the tool works, without reading your data.
WhatsApp just rolled out a new safety tool called Scam Alert. It warns you when a message looks like a scam. The tool runs an AI model directly on your phone. It does not touch WhatsApp’s encryption at all.
Scams keep changing, from fake profiles to AI-written messages that sound real. According to Meta’s engineering team, WhatsApp must keep improving its defenses at the same pace as scammers. Scam Alert is the newest piece of that effort.
How Scam Alert Works on Your Phone
Scam Alert is optional. You choose to turn it on. Once you do, WhatsApp sends a small AI model to your device. That model checks messages from people who are not your contacts. It looks for wording and patterns common in known scams.
Nothing about your message ever leaves your phone. The checking happens locally, not on Meta’s servers. WhatsApp also confirmed that no message gets reported automatically. Reports only go out if you choose to send one yourself.
This on-device approach contrasts sharply with pending legislation that would require tech companies to retain user metadata and build government access capabilities. Canada’s Bill C-22 has drawn opposition from Apple, Meta, Google, Signal, and over 42,000 Canadians who argue it would create a “comprehensive surveillance map” of citizens’ communications.
If the model thinks a message looks like a scam, it shows a warning. Only you can see this warning, not the sender. From there, you get choices. You can block the sender, report the message, or ignore it. You can also mark the chat as safe if you think the warning is wrong.
SecurityWeek reports that the whole system rests on three rules. First, everything stays on the device. Second, nothing gets reported without your say-so. Third, you stay in full control at every step.
How WhatsApp Keeps the System Honest
WhatsApp still wants to know if Scam Alert actually works. So it built a separate system just to measure that, without peeking at your messages. This system only counts things, like how many warnings popped up and what people did next. It adds statistical noise to those counts too, so no single person can be identified.
This setup runs inside something called a Trusted Execution Environment. Think of it as a locked box that even Meta’s own engineers cannot open. Data moves through this box, gets counted, then gets sent out as one big anonymous number.
There is also a risk that someone could sneak a fake or targeted AI model onto a specific person’s phone. WhatsApp built a fix for that too. Every version of the model gets logged on a public, tamper-proof ledger before release. Bleeping Computer notes that each version carries a unique digital fingerprint, so devices can check it matches what was officially published.
Downloads also travel through a relay that hides your identity from WhatsApp’s servers. Even Meta cannot tell which person requested which version of the model. Test groups get picked randomly on your own device too, so no one on WhatsApp’s side can single you out for a specific test model.
What Users can Do and What Comes Next
You can check the system yourself. WhatsApp added a transparency log inside the app. Go to Account, then Request Info, then Scam Alert Activity. There, you can see which messages got scanned and which model version did the scanning.
WhatsApp is also opening up its Bug Bounty program. Outside researchers can now test the model and the private counting system for weak spots. This move lets independent experts confirm the tool only fights scams and does nothing else.
Right now, Scam Alert is only in a small beta test. WhatsApp says it plans to keep testing the tool with security researchers first. A wider rollout will come only after that testing wraps up.
WhatsApp also plans to publish a full technical paper on how the system works. That paper builds on earlier research the company shared at a security conference in 2025.
This launch fits a bigger pattern too. Tech companies are trying to build safety tools that protect privacy at the same time. Instead of just asking users to trust them, companies like Meta now publish proof. Scam Alert shows that a company can fight scams and protect your messages at once. For now, users should watch for the update and decide if the extra warning is worth turning on.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
Suspected Chinese Hackers Exploit Critical VMware vCenter Flaw Across 47 Countries
Several servers across 47 countries record a compromise via an exploit of Vmware vCenter directory-t...
Apple Faces Lawsuit Over Claims that iCloud Private Relay Leaks User IP Addresses
A law firm sued Apple, saying its Private Relay tool did not protect user privacy as promised. Exper...
Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates
A hacker group named Head Mare broke into TrueConf video meeting servers and swapped safe installers...
New NatJack Attack Exposes Hidden Weakness in How Networks Handle Internet Connections
Security researcher Malcolm Stagg has uncovered NatJack, a new class of attacks that exploits a fund...
Germany Warns Companies Over Missing Security Contact Files on Most Websites
Germany’s cyber agency BSI wants every website to publish a security.txt file so researchers c...
TP-Link Patches 15 Omada Flaws that could Let Hackers Compromise Entire Networks
TP-Link fixed a total of 15 vulnerabilities in the ZTP solution that powers its Omada networking eco...