Key takeaway

Never scan a WhatsApp device-linking QR code or share a linking code simply because someone asks you to. WhatsApp's new warnings can flag suspicious attempts, but users should still regularly check Linked Devices and remove anything they do not recognise.

WhatsApp Is Making Suspicious Account Linking Harder — Here’s Why It Matters

A new security warning targets a clever scam that can give criminals access to your WhatsApp through a linked device without stealing your phone.

WhatsApp has introduced a new security measure designed to make one increasingly dangerous account takeover trick harder to pull off. The company is now warning users when its systems detect signs that a device-linking request may be suspicious. The feature was announced by Meta in March 2026 as part of a wider effort to combat online scams.

It sounds like a small change. But considering how much personal and business communication now takes place through WhatsApp, it could prevent a particularly convincing type of scam.

First, What Is a Linked Device? WhatsApp allows you to connect your account to other devices, such as a computer, tablet or another supported device. Once linked, those devices can independently access WhatsApp while your messages and calls remain protected by end-to-end encryption. WhatsApp also transfers a protected copy of recent message history when a new device is linked. Normally, this is extremely convenient. You can respond to customers from a computer, continue conversations on another device or use WhatsApp without constantly reaching for your main phone. The problem begins when the device being linked doesn't belong to you.

How the Scam Works Unlike traditional account theft, the criminal may not need to steal your smartphone or even know your WhatsApp password. Instead, the attacker attempts to convince you to authorise their device. Meta says scammers may ask victims to provide their phone number and then share a device-linking code. Another tactic involves convincing someone to scan a QR code under false pretences. If successful, that QR code can link the scammer's device to the victim's WhatsApp account.

The excuse could be almost anything:

  • “Scan this code to vote for me.”
  • “Confirm your business account here.”
  • “Your WhatsApp needs verification.”
  • “Scan this QR code to receive your prize.”

The victim thinks they are completing an ordinary online action. In reality, they may be authorising another device to access their WhatsApp.

What WhatsApp Is Changing WhatsApp's new defence adds another moment of friction before suspicious linking is completed. According to Meta, when behavioural signals indicate that a linking request may be suspicious, WhatsApp can now display a warning telling the user where the request is coming from and that it could be a scam.

That warning matters because many successful scams rely on speed. The criminal wants the victim to scan the QR code or enter the linking code before stopping to ask:

  • “Why does this website need access to my WhatsApp account?”

A prominent security warning creates an opportunity to reconsider. Why This Matters for WhatsApp Users in Africa. For many users, compromising WhatsApp can mean far more than gaining access to casual conversations.

WhatsApp accounts may be connected to: - * Family and friends - * Customers and suppliers - * School groups - * Workplace conversations - * Business contacts - * Community groups

An attacker who successfully links an unauthorised device could potentially exploit the trust attached to your identity. For example, contacts may receive messages appearing to come from someone they already know. That is what makes account compromise particularly dangerous: the scammer may inherit the victim's credibility.

A message asking for urgent financial assistance is far more convincing when it appears inside an existing conversation with someone you trust.

The New Warning Is Helpful, but It Cannot Replace Caution The important phrase in Meta's announcement is when behavioural signals suggest the linking request may be suspicious. That means users should not assume every dangerous attempt will automatically trigger a warning. If WhatsApp displays no alert, that does not make an unexpected QR code or device-linking request legitimate. Treat any unsolicited request to link your WhatsApp account with caution. Never Share a Device-Linking Code

A device linking code should be treated much like an authentication credential. If another person asks you to send them a code appearing inside WhatsApp so they can “verify” something, stop and examine what the code is actually for. WhatsApp supports linking devices through QR codes and through a phone number linking process.

Those processes exist to connect your account to a device you intend to use. They are not ordinary verification codes that should be handed to strangers.

Check Your Linked Devices One of the easiest security checks you can perform takes less than a minute. - Open WhatsApp and go to Linked Devices. - Review everything connected to your account.

WhatsApp recommends checking linked devices regularly, and users can log out devices they do not recognise.

If you see: - * A computer you do not recognise - * A browser you never connected - * A device from an unfamiliar location - * An old device you no longer use remove it.

Do not assume that because WhatsApp still works normally on your phone, nobody else has access through another linked device. Enable Two-Step Verification Too Device-linking warnings should form part of a wider security routine. WhatsApp also provides two-step verification, which allows users to protect their accounts with an additional PIN. Its security guidance recommends using the feature alongside regularly reviewing linked devices. No single security feature can stop every form of social engineering. The strongest protection comes from combining technical safeguards with scepticism about unexpected requests.

A Simple Rule for QR Codes QR codes feel harmless because they are everywhere from restaurant menus to payments and event tickets. But scanning one can initiate an action you may not fully understand.

Before scanning a QR code involving WhatsApp, ask: - Who sent this? - Why do they need me to scan it? - Is WhatsApp telling me that I am linking a device? - Do I personally own or control the device being linked?

If the final answer is no, do not proceed.

TechView Africa Verdict WhatsApp's new suspicious device-linking warning addresses an important weakness exploited by social-engineering scams, victims can sometimes be persuaded to authorise the attack themselves. By warning users when a linking attempt shows suspicious behavioural signals, WhatsApp is adding a useful barrier between the scammer and the account. But the best defence remains understanding what device linking actually does.

If someone asks you to scan a QR code, send a linking code or “verify” WhatsApp through an unfamiliar website, do not proceed simply because the request looks professional. Your WhatsApp account should only be linked to devices you recognise and control.

Frequently asked questions

Does scanning any WhatsApp QR code steal an account?

No. QR codes can have legitimate uses. The danger is approving a linking action you did not start or understand.

What if I see a device I do not recognise?

Log it out immediately, enable two-step verification and review recent messages and account changes.

Can WhatsApp support ask for my six-digit code?

You should never share a registration or verification code with another person.

Sources & verification notes

Meta Newsroom & WhatsApp Help Center.

Found an error, outdated step or safety concern? Contact the desk.