Deleted WhatsApp messages leave behind forensic artifacts that could be reconstructed by someone with access to your device or iCloud backups
Sorry, folks, while experts are saying the encryption checks out in WhatsApp, it looks like the latest version of the app tested leaves forensic trace …
Context & Ripple Effects
Jonathan Zdziarski's forensic teardown found that WhatsApp's end-to-end encryption holds up in transit, but 'deleted' messages survive as recoverable artifacts in the app's database and in iCloud backups — so anyone with device or backup access can reconstruct conversations the sender believed were gone. The finding reframed the threat model: the pipe was encrypted, the endpoints and Apple's backup store were not.
That gap became the throughline for the next decade of coverage. WhatsApp responded by rolling out end-to-end encryption for chat history backups in iCloud and Google Drive, first tested on Android, and later extended it with passkey-encrypted backups letting users bind stored history to biometrics or a code. By 2026, that accumulated reverse-engineering record was being cited to undercut a class action's claim that Meta can read user chats.
First-order effects
- Users who delete messages get false assurance: forensic examiners, thieves, or anyone holding an unlocked device or iCloud credentials can reconstruct 'deleted' chats without breaking WhatsApp's encryption.
- Law enforcement gains a documented path around E2EE that requires no crypto break — just physical access or a backup subpoena.
Second-order effects
- WhatsApp is pushed to close the backup hole itself, culminating in its e2e-encrypted backup rollout across iCloud and Google Drive and later passkey-based key custody — shifting protection from Apple's servers to keys only the user holds.
- Apple's iCloud sits exposed as the weakest link in otherwise-encrypted messaging stacks, pressuring platform vendors to treat backup stores as part of the privacy surface rather than neutral infrastructure.
Third-order effects
- Once transport encryption is table stakes, the battleground moves to data at rest: user-held backup keys become the mechanism that determines whether a platform vendor — or anyone else — can read stored history, a structure WhatsApp's defenders later invoke against claims it can read chats.
- Forensic researchers like Zdziarski become load-bearing infrastructure for both privacy engineering and litigation, since their reverse engineering defines what platforms actually can and cannot access.
The trend: Messaging security is migrating from encrypting messages in transit to encrypting everything at rest — devices, databases, and cloud backups — under keys held by users rather than platforms.