WhatsApp Now Warns You About Scam Messages—Without Reading Your Chats

WhatsApp has launched Scam Alert, a feature that runs on your phone to flag suspected scam messages in your chats. It does not send your message content to Meta's servers. The feature entered limited beta on August 12, 2026. TechTimes
When the feature spots a message that looks like a scam, the recipient sees a warning directly in the chat. The warning is not visible to the other participant in the conversation. The Verge
Upon seeing a Scam Alert warning, users can block the sender, report the message, or continue the conversation. Users who believe a warning was incorrectly triggered can mark the chat as trusted, which dismisses the warning and prevents Scam Alert from flagging that particular chat again. When marking a chat as trusted, users have the option to share the last five messages they received with WhatsApp to help improve the feature's accuracy. The Verge
The feature is optional and was designed from the outset to preserve WhatsApp's end-to-end encryption. All scam detection runs through a small program on the phone itself, meaning message content does not leave the device or pass through Meta's servers for analysis. PCMag AU TechDogs Meta's engineering team detailed the architecture in an August 12 post, describing the feature as a safeguard built to operate entirely within the encrypted pipeline. Meta Engineering
The design choices here matter as much as the feature itself. WhatsApp uses end-to-end encryption, which means only you and the person you are chatting with can read your messages. If WhatsApp wanted to scan messages on its servers, it would need to decrypt them first, which would break that protection. By running the scam-detection tool on your phone instead, WhatsApp avoids that problem entirely. Your messages stay encrypted while traveling across the network and while stored on Meta's systems, with the warning decision happening on your device.
The opt-in feedback mechanism is worth noting. When a user marks a chat as trusted and chooses to share the last five messages, that data flows to WhatsApp for model improvement. This is a voluntary, user-initiated step, not an automatic background stream. The distinction matters for anyone evaluating the privacy of the system: by default, all message content stays on your phone, and any sharing with Meta requires an affirmative user action tied to a specific chat.
The one-sided visibility of the warning is also a deliberate decision. Only the recipient of a flagged message sees the Scam Alert. The sender does not know whether their message triggered a warning. This prevents the feature from becoming a signal that scammers could use to refine their approaches, testing messages against the model in real time. It also avoids the social friction of a visible warning in legitimate conversations where one party's messages are being flagged.
The broader context here is that this approach offers a viable path for safety features in encrypted messaging. The long-running tension between content moderation and encryption has often been framed as binary: either break encryption to scan messages on company servers, or accept that encrypted platforms cannot detect harmful content. On-device detection does not resolve that tension entirely, but it offers a middle ground where the warning decision happens on your phone, under your control, without compromising encryption.
The limitations are real. A program running on a smartphone has limited processing power and memory, and its training data is constrained by what can be delivered to the device. Server-based systems, with access to full conversation context and large-scale infrastructure, can draw on richer signal. WhatsApp's approach trades some of that analytical depth for strong privacy guarantees, and the beta will reveal how well the on-device model performs in practice.
The five-message feedback window is a narrow but useful training signal. It gives WhatsApp a controlled, consented stream of real scam attempts and false positives to refine the model, without the blanket data collection that would undermine the encryption promise. Whether the volume of opt-in submissions is sufficient to meaningfully improve accuracy is an open question, but the mechanism is sound.
Scam Alert is in limited beta. Its effectiveness, false positive rate, and user adoption will become clearer as the rollout expands. For now, the feature stands as a concrete implementation of on-device content safety within an encrypted messaging platform.


