https://thehackernews.com/2017/01/whatsapp-encryption-backdo...
In short, their implementation allows to change the encryption keys of users without their consent to arbitrary, known keys. The protocol won't re-encrypt sent messages, but there is nothing in the protocol forcing the app to show a notification that your encryption key has changed, which amounts to a man-in-the-middle attack. Any subsequent messages sent or received using that encryption key will be exposed to the attacker.
Encryption keys are managed on servers controlled by WhatsApp.