Ethereum co-founder Vitalik Buterin publicly welcomed Signal’s ongoing efforts to allow account registration without a phone number on August 7, 2026. Posting on X, Buterin called the development “very welcome,” but he also tempered his praise. He added a significant counterpoint about the limitations of this change for achieving “true anonymity” in an era increasingly shaped by artificial intelligence.
Buterin’s comments quickly drew attention, underscoring a critical shift in the broader conversation around digital privacy. This isn’t just about a messaging app; it’s about how fundamental privacy protections must evolve to counter increasingly sophisticated threats, particularly from AI-driven data correlation.
Signal tackles phone number reliance for accounts
The privacy-focused messaging application Signal has long relied on phone numbers for user registration, a practice Buterin and many other privacy advocates have criticized. This reliance links digital identities to a centralized telecommunications infrastructure. It leaves users vulnerable to issues like SIM card swaps and potential government interference.
By exploring numberless accounts, Signal aims to reduce this dependency. Buterin previously described the phone number system as “highly oligopolistic,” highlighting its inherent security and privacy weaknesses. Removing this requirement could significantly lower identity security risks, making it harder for bad actors to compromise accounts through phone-related exploits.
It also provides a stronger shield against state-level pressure. Governments often use phone number registrations to identify, ban, or restrict users based on nationality or country of origin. A move away from this model empowers users in regions with repressive regimes or heightened surveillance.
Signal has confirmed it’s actively “exploring” and “working on” allowing optional sign-ups without a phone number. However, the feature isn’t officially confirmed for full implementation. Independent tracking site AboutSignal.com, however, has reported server code commits that point to robust backend support for numberless registration.
These code changes suggest a tiered approach. Accounts registered without a phone number would operate differently from those linked to one. It appears users won’t be able to add a number later or strip one from an existing account; the option would be limited to new sign-ups. This distinction is crucial for maintaining platform integrity.
Signal’s Chief Technology Officer, Ehren Kret, addressed the challenges in a March 2026 video from the FUTO Don’t Be Evil conference, published in July 2026. Kret noted that the primary hurdle is preventing spam and abuse without the barrier that phone numbers currently provide.
“We gotta figure out some way to induce a cost for signing up without a phone number,” Kret said, indicating that Signal is seeking alternative authentication methods.
Technical steps toward numberless accounts
The GitHub commits highlighted by AboutSignal.com offer a glimpse into Signal’s developmental progress. One commit, identified as ef2d257, states, “Don’t allow or set registration lock on accounts with no phone number.” This suggests a clear separation of account types is underway.
Another commit, 78e7e99, shows an effort to “Add utility methods for getting country/region codes for accounts that may not have phone numbers.” This indicates the system is being built to handle users whose geographical location isn’t tied to a phone number. It’s a foundational step for truly anonymous access.
Commit d7447b1, “Add support for pessimistic locking of phone-number-less accounts,” further illustrates the complexity. Signal is working on robust security mechanisms specific to these new account types. It underscores the challenges of maintaining security without traditional identifiers.
Finally, commit 29c5f8b, “Do not allow accounts without phone numbers to perform PNI key operations,” points to careful design around security protocols. These technical details show a deliberate, methodical approach. Signal aims to safeguard user integrity while removing a core identifier.
Buterin’s nuanced view on privacy and AI’s role
Buterin’s endorsement of Signal’s initiative stems from his long-standing commitment to digital privacy. He has consistently championed tools and platforms that protect user data. His support isn’t merely theoretical; he made significant donations to privacy projects last year.
In November 2025, Buterin donated 128 ETH each to Signal and SimpleX Chat. He praised both platforms for advancing open account creation and strengthening metadata privacy. This financial backing highlights his belief in the practical application of privacy technologies.
Buterin’s deeper analysis, however, reveals a growing concern: the evolving threat landscape driven by artificial intelligence. While Signal’s move improves “confidentiality,” he argues it falls short of achieving “true anonymity.” The distinction is critical for understanding the future of digital interactions.
AI’s capacity to process vast amounts of data means that metadata, such as message sending times, frequency, and recipient lists, can still be correlated. This correlation allows AI to reconstruct identities, even when direct personal identifiers are removed. Buterin contends that “pseudonymity is no longer sufficient in 2026.”
He views the “only defensible form of privacy” as “message-by-message uncorrelatability.” This means no entity outside the direct sender and recipient should be able to determine who is communicating. This is a far more stringent standard than simply removing a phone number.
Reimagining digital identity in the AI era
Buterin’s emphasis on “message-by-message uncorrelatability” effectively raises the bar for privacy in the AI age. This isn’t just an incremental improvement; it signifies a fundamental re-evaluation of what constitutes secure communication. Pseudonymity, once considered a strong privacy measure, now faces significant challenges from advanced analytical capabilities.
The implication is clear: privacy tools must adapt beyond merely obscuring direct identifiers. They need to address the subtle patterns and correlations that AI can exploit. Projects like Session and SimpleX, which incorporate mixing networks and other techniques, are already exploring these deeper forms of metadata protection. These tools aim to break the very linkages that AI seeks to establish.
Buterin has consistently pushed for robust privacy measures, even beyond messaging apps. His April 2025 essay, “Why I support privacy,” articulated his belief that concentrated data collection empowers those who hold it. He argued for resisting this concentration in the digital realm where it’s most feasible.
He’s also been a driving force behind incorporating privacy features directly into the Ethereum mainnet. His roadmap for native Ethereum privacy focuses on uncensorable private transactions, unlinkable account activity, and private blockchain reads. This parallel effort highlights a consistent vision across decentralized and centralized platforms.
For platforms like Signal, the immediate next priority, as identified by Buterin, is protection against spam and Denial-of-Service (DoS) attacks. As the phone number barrier diminishes, new mechanisms are essential to prevent malicious actors from overwhelming the system. This practical challenge often conflicts with the ideal of complete anonymity. Developers must balance these competing needs.
Buterin’s endorsement of Signal’s step, coupled with his warning, serves as a critical review of current privacy initiatives. It suggests that while progress is being made, the privacy frontier is constantly shifting. Achieving true anonymity requires continuous innovation. It also demands a proactive approach to evolving threats, especially those posed by increasingly intelligent systems.
