On September 1, 2026, Supreme Federal Court (STF) Justice André Mendonça lifted secrecy on a 218-page Federal Police forensic report showing investigators had recovered 52 supposedly "disappearing" WhatsApp messages that Banco Master's Daniel Vorcaro sent to a contact attributed to Justice Alexandre de Moraes — five recovered directly from WhatsApp and 47 more reconstructed from matching digital artifacts, according to reporting on the report by Poder360 and CNN Brasil. The headlines have framed this as proof that WhatsApp's encryption can be defeated. It isn't. The distinction matters for how Brazil — and every government watching this case — thinks about encryption policy going forward.
How the messages actually surfaced
Vorcaro used WhatsApp's visualização única (view-once) feature, which is supposed to delete a message after it's opened. But instead of typing directly into WhatsApp, he drafted text in his iPhone's Notes app, took a screenshot, and sent the image as a view-once message — then deleted the note. That workaround left a trail: each screenshot generated a temporary PDF file that WhatsApp's transport encryption never touched, because it never left the device as a message. Federal Police used Cellebrite, the Israeli forensic firm's tool, to bypass the passcode on the seized iPhone 17 Pro, then ran the extracted data through IPED (Indexador e Processador de Evidências Digitais) — the PF's own open-source indexing tool, built after Operation Lava Jato and hosted on the agency's official portal. IPED matched timestamps across Notes, screenshots, and WhatsApp send logs to reconstruct the pattern.
That is device forensics on hardware seized under a warrant — not a backdoor into WhatsApp's Signal-protocol encryption. Meta was never asked to decrypt anything, and no vulnerability was introduced into the app that any other user relies on.
The case behind the phone
Vorcaro was arrested at a Rio airport on November 17, 2025, attempting to fly to Malta by private jet; the Central Bank ordered the extrajudicial liquidation of Banco Master the next day. The collapse left roughly R$51.8 billion — the largest hole in the fund's history — for Brazil's deposit-guarantee fund (FGC) to cover, according to Poder360, which also runs Operation Compliance Zero, a federal fraud and money-laundering probe. The FGC's own guarantee-payment page confirms Master, Master de Investimento and Letsbank were consolidated into one conglomerate for the R$250,000-per-depositor coverage cap. Given the scale of that fraud and Vorcaro's attempted flight, a court-authorized forensic search of his phone is a proportionate step — not an outlier.
Steelmanning the alarm
The strongest objection isn't really about encryption; it's about what these messages allegedly show. Vorcaro was communicating, via a channel designed to leave no trace, with someone attributed to the justice overseeing scrutiny of his bank. If genuine, the public interest in surfacing that contact is obvious, and critics who say ephemeral-messaging features shouldn't shield a justice's undisclosed contacts with a fraud suspect have a fair point. Forensic tools that can reconstruct deleted communications on a lawfully seized device are a legitimate check on exactly that kind of concealment.
The recovery method also cuts the other way: it validates, rather than undermines, the position Justices Rosa Weber and Edson Fachin previewed in their 2020 votes on ADI 5527 and ADPF 403 — that end-to-end encryption is essential to privacy and security and that Brazil's Marco Civil da Internet cannot be read to force platforms to build in access (ip.rec.br).
That case has sat unresolved for six years — paused by a vista request from Moraes himself in 2020 and returned to the docket only in 2023, per the same analysis — leaving Brazil without a settled doctrine distinguishing warranted device forensics from platform-level decryption mandates. The Vorcaro episode is exactly the fact pattern the STF needs to finally rule on: it shows encryption held at the transport layer while a targeted, warrant-backed search of a suspect's own hardware still produced results. Policymakers elsewhere — including EU lawmakers debating mandatory client-side scanning — should note that Brazil got useful evidence without weakening WhatsApp's protocol for two billion users worldwide.
The part getting less attention
What should worry observers isn't the forensics — it's the secrecy fight it triggered inside the court itself. Moraes says the plenary still lacks access to 18 petitions and 180 documents across 13 related proceedings; Mendonça says he has released everything legally permissible before a scheduled full-court vote. A justice who is both a subject of the leaked messages and the one demanding fuller access to the phone dump that produced them is an awkward look for institutional impartiality, regardless of the merits. Brazil's broader intermediary-liability overhaul, already flagged by EFF for its potential to incentivize enforcement overreach (EFF), makes procedural clarity — about forensics, about court secrecy, about the limits on both — more urgent, not less.
Encryption survived this case. Institutional transparency is the open question.