Is WhatsApp View Once actually safe?
It has been broken four times in eighteen months. Meta declined to fix the fourth, and its reasoning tells you exactly what the feature is for.
Short answer: View Once is a courtesy, not a control. It stops an honest person casually keeping a photo. It does not stop anyone who wants to keep it. Researchers have bypassed it four separate times since September 2024, and in March 2026 Meta declined to fix the most recent one. It also does not work for documents or text at all — so the contract you sent on WhatsApp had no protection of any kind.
Why it breaks, in one sentence
View Once is a flag on a message, honoured by the app. The media is delivered to the recipient's device like any other message; the official WhatsApp client simply agrees to show it once and then delete it. Nothing forces that agreement. Any client that ignores the flag keeps the file.
That is the whole vulnerability, and it is structural rather than a bug. It is why the same weakness keeps returning after each fix.
The four bypasses
All four were found by Tal Be'ery, CTO of the wallet company Zengo.
| When | What |
|---|---|
| Sept 2024 | Unofficial clients built on the Baileys web API ignore the flag entirely. Also achievable with a browser extension on WhatsApp Web, which made it point-and-click for non-technical users. Reported as exploited in the wild. |
| Mid-Sept 2024 | Meta issues a partial fix. It does not work. |
| Nov 2024 | A server-side fix lands, reported in December. |
| Feb–Mar 2026 | A fourth bypass is disclosed on 16 February. Meta rejects the report on 10 March and will not patch it. |
Sources: The Register, TechCrunch, SecurityWeek.
Meta's position, which is the most useful part
Meta's answer is not a denial. It is a redefinition, and it is worth reading carefully:
View Once is "an additional privacy layer" for trusted contacts — not "a forensic-grade data deletion tool".
That is honest, and technically it is correct. A recipient who wants the content can always photograph the screen with another phone, so no amount of engineering makes the feature absolute. Meta is declining to promise something it cannot deliver.
The fair criticism is narrower: the name promises more than the feature intends. "View Once" sounds like a guarantee. Meta means it as a nudge. Most people sending an ID over WhatsApp hear the guarantee.
The part most people miss
View Once only works on photos, videos and voice notes. It does not apply to documents, and it does not apply to text.
So if you have been sending PDF contracts, title deeds, passport scans, tenancy agreements or price lists on WhatsApp, View Once was never involved. Those files landed in the recipient's chat, in their gallery or downloads folder, and in whatever cloud backup their phone runs. They are still there. They are forwardable in two taps, forever, to anyone.
It is also phone-only. There is no View Once on WhatsApp Web for sending.
What View Once does not do
| Capability | View Once |
|---|---|
| Works on documents | No — photos, videos, voice notes only |
| Watermark | None. A leaked copy is anonymous. |
| Screenshot alert | No. Blocks on official clients, does not tell you about attempts. |
| Audit trail | "Opened" only. No time spent, no device, no repeat views. |
| Revoke after sending | No. |
| Identity binding | No. Whoever holds the phone opens it. |
| Second-phone photo | Nothing stops this — as with every product, including ours. |
Does this matter for you?
Be honest with yourself about the threat. If you are sending a photo to a friend, View Once is fine, and the four bypasses are academic. Nobody is running a modified WhatsApp client to keep your picture.
It matters when the content has commercial value to the recipient. An off-market property pack, a client list, a candidate's CV, a term sheet, an ID document. There, the person receiving it has a reason to keep it, and keeping it is trivial — no bypass required, because View Once never applied to the file in the first place.
The deeper problem with WhatsApp is not the bypasses. It is that a leak is invisible and deferred. Nobody tells you the pack was forwarded. You find out months later when a competitor somehow knew, and by then the leak has no name attached to it. The pain never connects to the cause, which is exactly why the habit never changes.
What to do instead
The fix is not a better self-destructing photo. It is attribution: making sure any copy that escapes carries the name of whoever let it escape.
Be'ery's own analysis of View Once makes the argument for you. Digital extraction differs from photographing a screen on quality, scalability, timeliness, attribution and deniability. Those last two are the ones that matter, and they are precisely what a per-viewer watermark attacks. A forwarded file is anonymous and deniable. A photograph of a screen with someone's name and phone number across it is neither.
So: send a link, not a file. Watermark it with the viewer's own identity. Give it an expiry. Log who opened it. Accept that you cannot stop a camera, and make the camera shot worthless and traceable instead.
For the wider question of whether any product can stop screen capture, see our honest answer on screenshot protection. Short version: no, and be suspicious of anyone who says otherwise.
Common questions
Can someone save a WhatsApp View Once photo?
Yes. Researchers have demonstrated four separate bypasses since September 2024. The view-once flag is enforced by the client, not the server, so any unofficial client or browser extension can ignore it and keep the media. Meta fixed some of these; as of March 2026 it declined to fix the fourth.
Does WhatsApp tell you if someone screenshots a View Once message?
No. WhatsApp blocks screenshots of View Once media on its official clients, but it does not notify the sender of an attempt, and the block does not apply to unofficial clients or to someone photographing the screen with a second phone.
Is WhatsApp View Once safe for sending contracts or ID documents?
It is not designed for it. View Once does not work for documents or text at all, only photos, videos and voice notes, so a PDF contract sent on WhatsApp has no protection whatsoever. Meta describes View Once as an additional privacy layer for trusted contacts, not a forensic-grade data deletion tool. There is no watermark, no identity binding and no audit trail.
Why has Meta not fixed the WhatsApp View Once bypass?
Meta rejected the fourth bypass report in March 2026. Its position is that View Once is an additional privacy layer for people you trust, not a guarantee, and that a determined recipient can always photograph the screen with another device. That reasoning is technically correct. The criticism is that the feature's name implies a stronger promise than Meta intends to keep.
What is a safer way to send a sensitive document than WhatsApp?
Send a protected viewing link rather than the file. A link can be watermarked with the recipient's own name and number so any leaked copy identifies its source, can expire or burn after one view, can be revoked, and produces an audit trail of who opened it and when. Nothing stops a photograph of the screen, but attribution changes behaviour in a way a self-deleting photo does not.
Send it as a link they cannot quietly keep
Their name and number across every page. Expires when you say. Revoke it after sending. Open a live demo, no sign-up.
Watch it work