WhatsApp Vulnerability Discovered That Could Allow Attackers to Suspend Your Account Remotely

WhatsApp has suggested that users could avoid the problem by providing their email address with the two-step verification.

Advertisement
By Jagmeet Singh | Updated: 13 April 2021 11:47 IST
Highlights
  • WhatsApp appears to have two fundamental weaknesses
  • Attackers can block re-registration by simply using your phone number
  • WhatsApp support team deactivates account upon receiving an email

WhatsApp users are at risk even if they’ve enabled two-factor authentication (2FA) on their accounts

Photo Credit: Reuters

WhatsApp is found to have a vulnerability that can allow an attacker to suspend your account remotely using your phone number. The flaw that has now been found by security researchers appears to have existed on the instant messaging app for quite some time now — due to fundamental weaknesses. A large number of WhatsApp users are said to be at risk as a remote attacker can deactivate WhatsApp on your phone and then restrict you from activating it back. The vulnerability can be exploited even if you've enabled two-factor authentication (2FA) for your WhatsApp account.

Security researchers Luis Márquez Carpintero and Ernesto Canales Pereña have discovered the flaw that can allow attackers to remotely suspend your WhatsApp account. As first reported by Forbes, the researchers found that the flaw exists on the instant messaging app due to two fundamental weaknesses.

Advertisement

The first weakness allows the attacker to enter your phone number on WhatsApp installed on their phones. This will, of course, not give access to your WhatsApp account unless the attacker obtains the six-digit registration code you'll get on your phone. Multiple failed attempts to sign in using your phone number will also block code entries on WhatsApp installed on the attacker's phone for 12 hours.

However, while the attacker won't be able to repeat the sign in process with your phone number, they will be able to contact WhatsApp support to deactivate your phone number from the app. What they need is a new email address and a simple email stating that the phone has been stolen or lost. In response to that email, WhatsApp will ask for a confirmation that the attacker will quickly provide from their end.

Advertisement

This will deactivate your WhatsApp account, meaning that you'll no longer be able to access the instant messaging app on your phone. You won't be able to avoid that deactivation by using 2FA on your WhatsApp account as the account has apparently been deactivated through the email sent by the attacker.

In a regular deactivation case, you can activate your WhatsApp account back by verifying your phone number. This is, however, not possible if the attacker has already locked the verification process for 12 hours by making multiple failed attempts to sign in to your WhatsApp account. This means that you'll also be restricted from getting a new registration code on your phone number for 12 hours. The attacker can also repeat the process of failed sign-in attempts to restrict your account for another 12 hours when the first one expires.

Advertisement

This highlights that WhatsApp will treat your phone the same way it is treating the attacker's one and will block sign in access. You'll only have the option to get your WhatsApp account back by contacting the messaging app over email.

A WhatsApp spokesperson told Gadgets 360 that users could avoid the problem of getting their accounts deactivated by attackers using the newly discovered flaw by registering their email address to their account via two-step verification.

Advertisement

“Providing an email address with your two-step verification helps our customer service team assist people should they ever encounter this unlikely problem. The circumstances identified by this researcher would violate our terms of service and we encourage anyone who needs help to email our support team so we can investigate,” the spokesperson said.

However, WhatsApp has not provided any details on whether it is fixing the vulnerability to avoid its adverse effect on the masses.

It is currently unclear whether an attacker has exploited the vulnerability in the wild. However, considering the fact that the details about the flaw are now in the public, it could easily be leveraged to restrict anyone from using their WhatsApp — at least for a few hours.

WhatsApp has a massive user base of more than two billion users worldwide, with over 400 million users in India alone. Most of the users aren't likely to have their email addresses registered with their accounts at this moment. Therefore, the scope of the reported vulnerability is quite wide.


Does WhatsApp's new privacy policy spell the end for your privacy? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. New OTT Releases This Week: Musafir Cafe, Adarsh Baal Vidyalaya, and More
  2. Poco X8 Surfaces in New Regulatory Certifications
  3. Planning to Buy an iPhone 17? Apple Could Hike India Prices Soon
  4. Android 17 Makes Switching From iPhone Easier With Expanded Data Transfer Support
  5. Samsung Galaxy Unpacked July 2026 Event Roundup: Everything That Was Announced
  6. Poco F9 Ultra, Poco F9 Pro Spotted on Multiple Certification Sites Ahead of Launch
  7. Xiaomi Power Bank 5i 20000 67W With Built-In USB Type-C Cable Launched in India
  8. Here's When the OnePlus N6x Will Launch in India: See Expected Specs
  9. Boat Nirvana Eutopia 2 ANC Launched in India With Up to 80 Hours of Battery Life
  10. Google Now Lets You Sign in to Your Account With a Selfie Video
  1. Google Introduces Selfie Video Sign-In for Account Recovery
  2. Boat Nirvana Eutopia 2 ANC Launched in India With 45dB Hybrid ANC, Up to 80 Hours of Battery Life: Price, Features
  3. WhatsApp Could Replace Two-Step Verification PIN With a Stronger Password
  4. Oppo Find X10 Series Spotted Alongside iPhone 17 Pro in New Leak
  5. Microsoft Launches Xbox Backward Compatibility on PC With Four Original Xbox Games: Check System Requirements
  6. Vivo S2 Leak Reveals Expected Price and Storage Options Ahead of Rumoured India Launch
  7. New Redmi Note India Launch Appears Imminent After Official Teaser Goes Live; Could be Redmi Note 17
  8. Poco F9 Ultra, Poco F9 Pro Spotted on Multiple Certification Sites Ahead of Launch
  9. Google Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL Design, Colourways Reportedly Leak via Renders Ahead of Launch
  10. Xiaomi Power Bank 5i 20000 67W With Built-In USB Type-C Cable Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.