privacy

Hackers Can Exploit Delivery Receipts On Instant Messengers To Access User Private Data

Hackers have found a way to secretly track users on popular messaging apps like WhatsApp and Signal using delivery receipts. These “silent” receipts let attackers monitor device activity without sending visible notifications.​​

Silent Probing Mechanics

Attackers send crafted messages, such as reactions to non-existent chats or self-reactions, which trigger delivery receipts but produce no alerts on the victim’s phone.

These receipts reveal round-trip times (RTTs) that differ based on device state for instance, screen-on states yield about 1-second RTTs on iPhones, while screen-off states exceed 1 second.

High-frequency pings (sub-second intervals on WhatsApp) enable second-level tracking of online status, app foreground use (300ms RTTs), and multi-device logins, with each companion device (web/desktop) responding independently.

Hackers Exploit Messenger Receipts

No prior chat is needed; a phone number suffices for “spooky stranger” attacks on both apps.

MessengerStealth ReactionsMulti-Device TrackingStranger Access
WhatsAppYesYes (independent)Yes
SignalYesYes (independent)Yes
ThreemaNoNo (synchronized)No

​​Privacy Risks and Fixes

RTT patterns expose routines like sleep schedules (no receipts during offline), office logins (low-jitter LAN), or travel (LTE switches), even fingerprinting OS via receipt stacking.

Resource attacks drain batteries (14-18% per hour on iPhones) or inflate data (13GB/hour via 1MB reactions). Universities disclosed findings in 2024; Meta acknowledged, but no patches by late 2025 Signal ignored reports.

Users cannot turn off receipts or block silently. Developers should add noise to timings, rate limits, stricter validation, and optional receipt toggles.

Threema resists via synchronized receipts. With billions of users affected, an urgent redesign is needed for end-to-end encrypted messengers.

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Recent Posts

Burp Suite Supercharges Its Scanning Capabilities With React2Shell Vulnerability Detection

PortSwigger has leveled up Burp Suite's scanning arsenal with the latest Active Scan++ extension, version…

5 months ago

Malicious MCP Servers Enable New Prompt Injection Attack To Drain Resources

Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol…

5 months ago

Law Enforcement Detains Hackers Equipped With Specialized Flipper Hacking Tools

Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of…

5 months ago

Google Unveils 10 New Gemini-Powered AI Features For Chrome

Google has launched its most significant Chrome update ever, embedding Gemini AI across the browser…

5 months ago

CISA Alerts On Actively Exploited Buffer Overflow Flaw In D-Link Routers

Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by…

5 months ago

Over 500 Apache Tika Toolkit Instances Exposed To Critical XXE Vulnerability

Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for…

5 months ago