WhatsApp launches the tool we really needed in the AI era
Online fraud and social engineering have become one of the main threats in messaging apps, with over $425 million stolen in the US alone using these methods, according to Federal Trade Commission (FTC) data. To combat this phenomenon, Meta's engineering division unveiled Scam Alert this past weekend — a new security tool embedded in the WhatsApp application. The system is designed to identify fraudulent messages.

Online fraud and social engineering have become one of the main threats in messaging apps, with over $425 million stolen in the US alone using these methods, according to Federal Trade Commission (FTC) data. To combat this phenomenon, Meta's engineering division unveiled Scam Alert this past weekend — a new security tool embedded in the WhatsApp application. The system is designed to identify suspicious messages from profiles not saved in contacts and alert the user, with an emphasis on protecting vulnerable populations such as the elderly and teenagers.
AI-based protection without compromising privacy
Unlike traditional artificial intelligence (AI) tools that require processing on cloud servers, Meta's model operates directly on the mobile phone's hardware (On-Device). The system scans incoming messages and looks for linguistic patterns and conversation structures characteristic of known scams, without the content leaving the device. As soon as a suspicion of fraud is detected, a discreet warning pops up that is not visible to the sender, allowing the user to block the contact, report them, or mark the conversation as safe in case of a false positive.
The main engineering challenge was providing protection without compromising end-to-end encryption. Meta emphasizes that the content of messages is not sent to the company's servers or to third parties at any stage of the process. To test the system's effectiveness, Meta collects only anonymous statistical data — such as the number of warnings triggered — using a Differential Privacy mechanism. This mechanism adds random "mathematical noise" to the information to prevent any theoretical possibility of linking an action to an individual user.
Full transparency and prevention of targeted surveillance
To prevent concerns about using the model for surveillance purposes, Meta is taking an unusual step and publishing the model's weights and digital signatures in a third-party public transparency log (Cloudflare). This step ensures that the company cannot send a different version of the model to a specific user. In addition, security researchers will be able to check the code independently as part of a Bug Bounty program, while users can view security logs directly from the account settings.
The new feature is currently launching in an experimental beta version for a limited number of users and is not enabled by default. Users will be able to turn the protection on or off at any time through the app's privacy menu. The move marks a new engineering approach where small language models provide an autonomous protective layer within the personal device, without handing over the keys to the private data of billions of users around the world.





