> WhatsApp multi-device uses a client-fanout approach, where the WhatsApp client sending the message encrypts and transmits it N number of times to N number of different devices — those in the sender and receiver’s device lists.
https://engineering.fb.com/2021/07/14/security/whatsapp-mult...
Presumably this means that the device knows how many devices it will be send to.
Like putting a screen door on a submarine.
So no, not their servers.
As another commenter noted, they just generate another key and when someone sends you a message they have to encrypt the same message twice (one for each key).
(I don't use WhatsApp so I don't know if they do the same.)
edit: Maybe I'm missing something in how the web device is provisioned (maybe treating it like a group chat with multiple keys?), but I don't see how it could decrypt messages intended for my phone without just getting a copy of the key
edit: Is there documentation somewhere? Makes no sense to me that my friend is encrypting with the same public key (before, during, and after whatsapp-web is provisioned), but somehow it is decrypted on a new device with a different key