You get a WhatsApp message from a real friend, someone you've known for years. It asks you to click a link and vote for their kid in a dance contest, or their dog in a photo contest, or their school in some fundraiser. Nothing about it screams scam — it's not asking for your bank password, and it's coming from a contact you trust, in a thread you've had for years.
That's exactly the point. Security researchers at Malwarebytes documented this pattern in early August 2026: the message doesn't come from a spoofed number. It comes from your friend's actual, hijacked WhatsApp account. The attacker isn't impersonating them — they're inside their account, sending as them, to everyone in their contact list, including you.
How the account gets taken over without a password
WhatsApp lets one account stay logged into up to four extra devices at once — your phone, plus WhatsApp Web on a browser, a desktop app, and so on — through a feature called linked devices. Linking a new device normally means opening WhatsApp on your phone, going to Settings, and scanning a QR code shown on the new device. No password needed, because your phone is already logged in and vouching for the new session.
The scam hijacks that flow instead of the login itself. The victim clicks a link — sometimes on the real wa.me domain — that walks them through what looks like "WhatsApp Web setup," or tells them to type a code into their own linked-devices screen. Following those steps does exactly one thing: it approves the attacker's device as a new linked session on the victim's account. From that point on, the attacker can read and send messages as if they were the account owner, on a device the victim never sees.
This is why it doesn't trip any of the alarms people are trained to watch for. There's no password change, so no "your password was changed" email. There's no failed login attempt, so no security alert. The account owner's own phone still works completely normally. The only trace is one extra, unfamiliar entry sitting quietly in the linked-devices list — and almost nobody checks that list unless they know to look.
Check your own linked devices right now
Do this whether or not you've received one of these messages, since it takes under two minutes and costs nothing:
- On iPhone or Android: Open WhatsApp → tap Settings (or the three-dot menu on Android) → Linked Devices.
- Review every entry. Each one shows a device type (Chrome, Windows, Mac, another phone) and when it was last active. If you only ever use WhatsApp on your own phone, this list should be empty. If you do use WhatsApp Web on a home or work computer, you should recognize every single entry.
- Anything you don't recognize — remove it immediately. Tap the device, then "Log out," or use "Log out from all devices" if you're not sure which entry is the problem. This instantly cuts off the attacker's access; it doesn't require changing your password or phone number.
Then lock the door behind you
Removing the rogue device stops the immediate access, but it doesn't stop someone from linking a new one the same way. Two follow-up steps matter:
- Turn on two-step verification. Settings → Account → Two-step verification → Enable. This adds a 6-digit PIN that's required for certain sensitive actions and makes it harder for someone to re-establish control even if they trick you again.
- Never enter a code into your own WhatsApp settings because a message told you to. That's the actual mechanism of this scam. Legitimate device linking always starts with you opening WhatsApp Web or Desktop yourself and scanning a QR code with your phone's camera — it is never initiated by typing a code that arrived in a chat, text, or link. If any page asks you to do that, close it.
If the message came from a friend, not from you
Don't click the link, and don't send money if the conversation escalates into a request for one — that's frequently the next step once the attacker has access, since a message asking for emergency cash from a real friend's account is far more convincing than the same message from a stranger. Instead, contact that friend through a different channel entirely — a phone call, a text, an email, anything that isn't the WhatsApp thread itself, since that thread may not actually be them. Tell them what you received and suggest they check their own linked-devices list. If it turns out their account was compromised, they should also warn their other contacts the same way, since the attacker's whole strategy depends on the message looking exactly as trustworthy as it is right now.
None of this requires antivirus software, a password manager, or any tool beyond WhatsApp's own settings menu. It requires knowing that "linked devices" is a list worth checking — and that a favor request from someone real is not proof the request actually came from them.