Messaging giant WhatsApp has around three billion users in more than 180 countries. Researchers say they were able to identify around 3.5 billion registered WhatsApp accounts thanks to a flaw in the software. That higher number is possible because WhatsAppโs API returns all accounts registered to phone numbers, including inactive, recycled, or abandoned ones, not just active users.
If youโre going to message a WhatsApp user, first you need to be sure that they have an account with the service. WhatsApp lets apps do that by sending a personโs phone number to an application programming interface (API). The API checks whether each number is registered with WhatsApp and returns basic public information.
WhatsAppโs API will tell any program that asks it if a phone number has a WhatsApp account registered to it, because thatโs how it identifies its users. But this is only supposed to process small numbers of requests at a time.
In theory, WhatsApp should limit how many of these lookups you can do in a short period, to stop abuse. In practice, researchers at the University of Vienna and security lab SBA Research found that those โintended limitsโ were easy to blow past.
They generated billions of phone numbers matching valid formats in 245 countries and fired them at WhatsAppโs servers. The contact discovery API replied quickly enough for them to query more than 100 million numbers per hour and confirm over 3.5 billion active accounts.
The team sent around 7,000 queries per second from a single source IP address. That volume of traffic should raise the eyebrows of any decent IT administrator, yet WhatsApp didnโt block the IP or the test accounts, and the researchers say they experienced no effective rate-limiting:
โTo our surprise, neither our IP address nor our accounts have been blocked by WhatsApp. Moreover, we did not experience any prohibitive rate-limiting.โ
Data-palooza at WhatsApp
The data exposed goes…
