WhatsApp Begins Testing On-Device Scam Alert Feature, Starting With Android Beta Users
WhatsApp has started rolling out a new safety feature designed to flag suspicious messages from unknown contacts, without the platform itself ever reading their content. Called Scam Alert, the tool is currently limited to a small group of Android beta testers running version 2.26.34.1 of the app, according to a report from WABetaInfo, which tracks WhatsApp’s beta releases.
The feature works by running a machine learning model directly on a user’s phone. When a message arrives from a number that isn’t saved as a contact, the model scans it locally for patterns commonly associated with scam conversations — impersonation attempts, urgency-driven requests, or social-engineering tactics. If it flags something suspicious, the recipient sees a warning inside the chat itself. The sender is never notified that the alert appeared.
Why On-Device Processing Matters
WhatsApp’s core selling point has always been end-to-end encryption, which means the company cannot read the content of a conversation by design, not just policy. Building a scam-detection tool on top of that architecture required Meta to keep the analysis entirely on the device. In a technical breakdown published on its engineering blog, the company said no message content leaves the phone for classification, and nothing is automatically reported to WhatsApp or Meta unless the user takes a deliberate action, such as tapping report.
That distinction matters for a platform operating in markets where trust in how tech companies handle personal data runs thin. Meta said the model itself is downloaded from a content delivery network rather than baked into the app, allowing it to be updated as scam tactics evolve, without forcing users to install a new app version.
Built-In Checks Against Misuse
A recurring concern with any on-device detection system is whether the company controlling it could quietly target specific users with a different, more invasive version of the model. Meta says it designed Scam Alert to close that door. Every version of the model, including experimental variants used for testing, is published to a public, tamper-evident transparency ledger before it reaches any device, and download requests are routed through a relay that strips identifying information such as IP addresses.
Meta has also widened its Bug Bounty programme to cover Scam Alert specifically, inviting external security researchers to examine both the privacy architecture and the model’s behaviour, checking that it does nothing beyond scam detection.
What Happens When a Message Is Flagged
Once Scam Alert marks a message, the recipient can block and report the sender, or mark the conversation as trusted if they believe the warning was a mistake. Trusting a chat also gives the user the option, entirely voluntary, of sharing the last five messages with WhatsApp to help refine the model. Users can review a private, on-device activity log showing which messages were scanned and what action, if any, followed.
For now, the feature remains restricted to a limited pool of Android beta testers, with no confirmed timeline for a wider release or an iOS version.


