"We pay $10–20 a day - just add people to a chat from a number list" - sounds like easy side income, but ends in a permanent ban on your own account. Scheme organizers stay clean; the person who performed the action pays. This article explains why liability always lands on the executor account, and separately - what actually happened with the
wa.me/settingslink that crashed the app in 2023.
After reading you'll recognize the "paid admin work" scheme from the first message and know what the old settings-link vulnerability really did versus what was invented after the fact.
The scheme usually arrives via Telegram or acquaintances: join someone else's chat and add people from a ready number list for fixed daily pay. Wording is deliberately harmless - "administration," "moderation," "working with a database."
The detail victims miss: they want you to add people from your personal WhatsApp account, not the organizer's number. That's not accidental - it's the whole point.
WhatsApp logic is simple: sanctions hit the account that physically performed the action - tapped "Add participant." Not the group admin, not the chat creator, not whoever sent the number list.
When people added without consent mass-tap "Report and exit," the executor number takes the hit. Organizers use other people's accounts as consumables - they last exactly until the first complaint wave.
A user gets a Telegram offer: join a specified chat and add people from a list, $10–20 per day. They do about 40 adds - and their WhatsApp account gets a permanent ban. Organizers vanish, having gotten the target inviting while keeping their own "organizer numbers" untouched.
Not an isolated case - characteristic mechanics: the larger and colder the list people are added from, the faster the block arrives.
Mass group adds are noticeably more dangerous than regular messaging - each add without consent is a potential report, not just an unread message.
Officially, one WhatsApp group can hold up to 1024 members - no technical ceiling here. But that's a group limit, not a safe action volume for one number.
Practitioners use far more modest figures: for an unwarmed number with no history - no more than 10–20 adds per day, and even that's no guarantee. Aggressive inviting to a cold list can trigger permanent ban within 15–30 minutes of starting. Meta publishes no official thresholds - practitioner observation only, not documented rules.
The colder the recipient list, the shorter the adding account's lifespan.
Misconception: "wa.me/settings breaks the app, reinstall required" - sounds like a universal vulnerability, current on any device.
Clarification: a specific vulnerability in certain Android app versions, documented May 2023 (notably build 2.23.10.77). Cause - client code mishandling an empty path after /settings, crashing when trying to render such a message in chat. Meta patched it in later updates - current app versions don't reproduce the issue.
Separate myth - reinstall. You could restore without uninstalling: open the problem chat via WhatsApp Web or Desktop (bug affected mobile Android client only) and delete the message with "Delete for me" or "Delete for everyone." Mobile app then worked normally. General wa.me link format is covered in a separate article - here it's one specific path bug, not any wa.me link.
At a company CRM connected to WhatsApp via automation, scammers sent the text wa.me/settings. When a support agent opened that chat on an old Android work phone, the app loop-crashed, paralyzing the shift until someone deleted the message via web.
Shows that even a patch-closed vulnerability still works where the client isn't updated - common on corporate or long-untouched devices.
Several forum-confident claims lack official confirmation:
Treat these as uncertainty zones, not decision facts.
Be wary if a WhatsApp "side job" offer includes any of:
Any "work" through your WA account for third parties you can't verify or control is potential fraud - the number owner pays, not the client.
If you or your team were offered group-add side work - check whether it ran on company work numbers, and update WhatsApp on all corporate devices to current version.
Practical rule:
WhatsApp always holds the account that performed the action responsible - the scheme client risks someone else's number, not their own.