Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern digital communication relies heavily on end-to-end encryption (E2EE) to secure data in transit, ensuring that messages can only be read by the sender and the intended recipient. Protocols utilized by dominant platforms such as WhatsApp, Signal, and Telegram mathematically protect message content from interception by telecommunication providers, hackers, and government agencies alike. However, the convenience of modern software design has introduced an alternative vector for surveillance. By allowing users to link desktop computers, tablets, and secondary browsers to a primary mobile account, these applications create persistent secondary sessions. Recent investigative findings reveal that law enforcement agencies—specifically within Germany—are systematically exploiting these companion device linking mechanisms to read communications without ever needing to break underlying encryption algorithms.
The Mechanics of Companion Device Exploitation
End-to-end encryption guarantees that data intercepted while traveling across the internet appears as unreadable ciphertext. Traditional wiretapping methods, which involve capturing data packets at the network or carrier level, are rendered useless against protocols like the Signal Protocol or WhatsApp’s implementation of it. Recognizing this barrier, law enforcement agencies have shifted their tactical focus from data in transit to endpoint compromise.
Companion device linking features are designed for user convenience, allowing individuals to mirror their mobile messaging environment onto desktop computers. To establish this connection, the primary smartphone must scan a QR code displayed on the desktop application or approve the pairing request via a cryptographic handshake.
Rather than attempting brute-force attacks against cryptographic keys, investigators circumvent the encryption by lawfully or covertly co-opting the authentication process itself. According to reports originating from German investigative outlets such as Netzpolitik, the German Customs Office (Zollkriminalamt) and various police units have successfully deployed police-controlled computers as linked desktop clients on suspects’ accounts.
Once a secondary session is legitimately established from the perspective of the messaging servers, messages sent to and from the account are automatically mirrored to the investigator’s terminal in real time. Because the police-controlled device is recognized by the network as an authorized extension of the user’s account, it receives decrypted message payloads directly from the application infrastructure, completely bypassing the need to crack the underlying encryption keys.
Chronology and Investigative Origins
The public disclosure of these techniques stems from a combination of freedom of information requests, leaked administrative documents, and parliamentary inquiries in Germany. The timeline of events illustrating the operational deployment of messenger surveillance highlights a concerted shift toward endpoint exploitation over the past several years.
Initial reports regarding state-level surveillance of encrypted messaging apps primarily focused on government-acquired malware, often referred to colloquially as federal trojans or state trojans (Staatstrojaner). These sophisticated spyware packages were designed to covertly install themselves on a target’s smartphone, logging keystrokes, capturing screenshots, and extracting data before encryption occurred. However, the legal hurdles, technical complexity, and high financial costs associated with developing and maintaining bespoke spyware prompted intelligence and law enforcement agencies to seek simpler, more reliable alternatives.
By approximately 2024, digital rights organizations and investigative journalists in Europe began noticing a distinct uptick in references to "messenger monitoring" (Messenger-Überwachung) within procurement documents and internal guidelines of German federal and state law enforcement agencies. These documents indicated that instead of relying exclusively on expensive, zero-day malware exploits, authorities were increasingly utilizing standard procedural workflows provided by the messaging apps themselves.
In early 2026, detailed reporting by Netzpolitik brought these practices into sharp focus. The investigative reports revealed specific instances where the German Customs Office utilized device-linking protocols to monitor suspects. Rather than utilizing covert remote access software, law enforcement agencies discovered that they could achieve identical surveillance outcomes by physically or digitally seizing control of the initial device-linking authentication window.
Methods of Unauthorized Authorization
A critical element of this surveillance methodology is that it cannot occur purely through remote network manipulation without some form of interaction or credential acquisition. Because applications like WhatsApp and Signal require explicit user verification to link a new desktop client, law enforcement officers must overcome this security gate. Investigations have identified three primary pathways through which police achieve this authorization:
-
Physical Access: During routine traffic stops, border crossings, or pre-dawn execution of search warrants, officers temporarily gain physical custody of an unlocked or partially accessible smartphone. In the brief window before the device is secured or wiped, officers can open the messaging application, navigate to the linked devices menu, scan a prepared QR code from a police-controlled laptop, and immediately establish a persistent desktop session.
-
State-Sanctioned Phishing: In scenarios where physical access is impractical, authorities have turned to targeted phishing campaigns. By deploying customized, state-backed infrastructure, investigators send deceptive messages or links designed to trick the target into revealing multi-factor authentication credentials or granting remote permissions that facilitate the device-linking process.
-
Interception of Verification Codes via Telecommunication Surveillance: Many messaging applications require an SMS-based verification code when registering an account on a new device or re-authenticating an existing one. By leveraging existing legal frameworks for telecommunications interception—often used in conjunction with mobile network operators—police can capture incoming SMS verification codes in transit, allowing them to complete the desktop registration process without the user’s active participation.
Supporting Data and Technical Context
The scale of encrypted messaging usage globally underscores the significance of these vulnerabilities. WhatsApp boasts over two billion active monthly users worldwide, while Signal is utilized by tens of millions of individuals, including journalists, activists, government officials, and privacy-conscious citizens. The reliance on these platforms as digital safe havens assumes that communication privacy is absolute.
However, the architecture of multi-device syncing fundamentally alters the trust model of end-to-end encryption. In a traditional single-device E2EE environment, the cryptographic boundary is drawn strictly around the hardware device holding the private keys. When multi-device support was introduced—historically a major engineering challenge because traditional E2EE requires keys to be tied to a single client—developers implemented various forms of client-to-client key distribution.
For instance, when a user links a desktop app in Signal, the primary mobile device encrypts the user’s message history and local state, and then securely transmits it over a pairwise encrypted session to the new desktop client. From the perspective of the application server, the secondary device is treated as an authenticated endpoint belonging to the same identity. Because the application server cannot distinguish between a legitimate user sitting at a personal laptop and a law enforcement officer operating a mirrored session on a police workstation, the system dutifully synchronizes all incoming and outgoing data streams.
Official Responses and Institutional Perspectives
The revelations surrounding the exploitation of companion device linking have generated significant debate among legal scholars, privacy advocates, and law enforcement representatives across Europe.
Law enforcement agencies, defending the practice, argue that modern investigative techniques must evolve in tandem with technological advancements. Representatives from federal investigative bodies maintain that organized crime, terrorism, and transnational smuggling operations increasingly rely on secure messaging applications to coordinate illicit activities. From the perspective of prosecutors and police administrators, utilizing built-in application features to maintain lawful intercept capabilities represents a pragmatic and legally grounded approach to combating serious crime, provided that such operations are authorized by judicial warrants.
Conversely, civil liberties organizations and digital rights groups have sharply criticized the practice, characterizing it as a subversion of the foundational promises made by software developers. Critics emphasize that while the mathematics of end-to-end encryption remain unbroken, the security value of that encryption is effectively neutralized if the endpoint itself is quietly compromised. Furthermore, privacy advocates argue that relying on physical access or SMS interception to bypass user consent erodes public trust in digital security mechanisms.
Software developers and platform architects face mounting pressure to address these vulnerabilities. While applications have implemented safety numbers, cryptographic fingerprints, and notification banners designed to alert users when a new key is added or a device is linked, these warnings often go unnoticed by the average user, who may not understand the security implications of an unfamiliar device appearing in their account settings.
Broader Impact and Security Implications
The implications of law enforcement agencies utilizing companion device linking extend far beyond the borders of Germany, raising critical questions regarding the future of global digital privacy and regulatory oversight.
As democratic governments increasingly seek ways to maintain investigative oversight over encrypted communications—balancing public safety against the constitutional right to privacy—the debate over endpoint security has intensified. Legislative frameworks such as the European Union’s proposed regulations on child sexual abuse material (CSAM) detection, alongside ongoing legal challenges regarding client-side scanning and exceptional access, highlight a persistent tension between state authorities and the technology sector.
For the end user, the reliance on multi-device synchronization introduces a permanent security trade-off: the convenience of seamless cross-platform messaging inherently expands the attack surface of private accounts. Cybersecurity experts emphasize that protecting modern communications requires a holistic approach that encompasses not only strong cryptographic protocols in transit, but also rigorous endpoint hygiene.
To mitigate these specific risks, privacy advocates and security researchers are calling for architectural enhancements across all major messaging platforms. Chief among these recommendations is the implementation of more prominent, transparent, and difficult-to-ignore user interfaces that display all currently connected devices in real time. If applications provide immediate, unambiguous visual notifications whenever a secondary session attempts to handshake or synchronize, users would be far more likely to detect unauthorized access before investigators can extract meaningful intelligence.
Additionally, industry experts advocate for stricter re-authentication protocols, mandatory biometric checks before approving new device links, and enhanced anomaly detection algorithms capable of identifying unusual geographic or hardware pairing patterns. Until such safeguards become standard industry practice, the exploitation of companion device linking will remain a potent tool for investigative agencies, demonstrating that the weakest link in encrypted communication is frequently not the cryptography itself, but the human and physical interface through which it is accessed.







