That’s one way, but.
https://thehackernews.com/2025/02/hackers-exploit-signals-li...
“… the threat actors, including one it's tracking as UNC5792, have resorted to malicious QR codes that, when scanned, will link a victim's account to an actor-controlled Signal instance.”
“ These QR codes are known to masquerade as group invites, security alerts, or legitimate device pairing instructions from the Signal website.”
Also
“ Last week, Microsoft and Volexity also revealed that multiple Russian threat actors are taking advantage of a technique called device code phishing to log into victims' accounts by targeting them via messaging apps like WhatsApp, Signal, and Microsoft Teams.”