comscore

How 3.5 Billion WhatsApp Accounts Could Be at Risk: A recent research exposes a major flaw in the Meta app 

A team of Austrian researchers has revealed that anyone could quietly map the phone numbers of nearly all WhatsApp users worldwide, using nothing more than automated contact discovery through WhatsApp Web.

Published By: Madhav Malhotra | Published: Nov 23, 2025, 12:50 PM (IST)

  • whatsapp
  • twitter
  • facebook
  • whatsapp
  • twitter
  • facebook

Whatsapp is one of the most commonly used communication apps. But, its biggest strength of being a simple phone number based communication might also be its major privacy weakness. 

A team of researchers at the University of Vienna explained that they were able to build a massive database containing phone numbers linked to all 3.5 billion WhatsApp accounts. Their findings were shocking and showed just how much publicly visible information could be pulled at a major scale. 

The process mimicked everyday WhatsApp behavior. When you add a number, WhatsApp checks if it’s linked to an account and then displays the user’s profile picture and text. The researchers simply automated this process using WhatsApp Web. Their automated system was powerful enough to test almost 100 million phone numbers per hour, making it possible to map the entire user base in a relatively short time.

The surprising part is that Meta was warned about this exact vulnerability back in 2017 and yet no strict protections were introduced for years. It wasn’t until the researchers disclosed their new findings in April 2025 that Meta stepped up.

Meta’s Response

Meta responded to this by introducing rate-limiting measures and anti-scraping protections. The company also credited the researchers and stated that no non-public information was at risk. Still, this could be a big issue and a concern for millions of users, since WhatsApp is their primary communication app.

Even though the issue is now patched, the incident is a reminder to all the users that they should regularly check their privacy settings. The best step users can take is to keep their profile photo and about text visible only to contacts, which can significantly reduce exposure.