WhatsApp Adds Passkey Support for 1 Billion Users, Bolstering Two-Step Verification
Key Takeaways WhatsApp has significantly enhanced account security for over a billion users by expanding passkey support. The platform is upgrading its two-step verification from a six-digit PIN to a...
Key Takeaways
- WhatsApp has significantly enhanced account security for over a billion users by expanding passkey support.
- The platform is upgrading its two-step verification from a six-digit PIN to a stronger, alphanumeric password.
- New anti-scam features are being introduced for Android users, providing additional context for unknown incoming calls.
- These updates aim to bolster defenses against phishing, SIM-swap attacks, and social engineering fraud.
WhatsApp Fortifies Account Security with Passkeys for Over a Billion Users and Enhanced Two-Step Verification
WhatsApp, the Meta-owned messaging giant, has announced a substantial upgrade to its account security features, confirming that over one billion users now utilize passkeys for authentication. This rollout represents one of the most extensive implementations of passwordless authentication in the consumer technology sector to date.
Table Of Content
In parallel with this milestone, the platform is introducing a significant enhancement to its two-step verification process, replacing the traditional six-digit PIN with a robust alphanumeric password. Additionally, new caller-context features are being deployed to help users identify potential scams before responding to unknown calls.
Passkeys Reach Critical Mass
Passkeys enable WhatsApp users to authenticate their accounts using their device’s built-in biometric sensors, such as fingerprint or Face ID, or by entering their device’s screen lock code. This method eliminates the need for users to type in a numeric code or PIN, streamlining the login process while significantly boosting security.
The inherent cryptographic nature of passkeys, which are tied directly to a user’s device rather than relying on shared secrets transmitted over networks, makes them considerably more resilient to common attack vectors. These include phishing attempts, credential stuffing attacks, and SIM-swap fraud, which often target legacy verification codes.
WhatsApp reports that passkey adoption has now surpassed the one billion user mark. The company is also expanding support for this feature, allowing users who operate across both Android and iOS devices to register multiple passkeys to a single account. Users can manage their passkeys by navigating to Settings > Account > Passkeys, where they can add new keys or review existing ones linked to their device’s password manager.
Upgrading Two-Step Verification to Alphanumeric Passwords
Perhaps the most impactful change for overall account security involves the two-step verification (2SV) system. Previously, 2SV on WhatsApp required a six-digit PIN after the initial SMS one-time passcode. WhatsApp is now allowing users to replace this PIN with a full-fledged alphanumeric password, capable of including special characters.
This upgrade dramatically increases the complexity of the secondary authentication layer, making brute-force and credential-guessing attacks far more difficult. According to the WhatsApp security announcement, new passwords must be a minimum of eight characters long and include at least one letter and one number, with an option to further strengthen them using symbols.
The move addresses a long-standing vulnerability associated with short numeric PINs. While better than no protection, six-digit PINs offer a comparatively small “keyspace” and are frequently chosen as easily guessable sequences like “123456” or reused across multiple services. Cybersecurity researchers have consistently highlighted such short numeric codes as a weak point in account recovery and secondary authentication flows, as they can often be bypassed through automated guessing or social engineering tactics more quickly than a properly constructed password.
WhatsApp’s communication surrounding this rollout explicitly acknowledges this risk, urging users still relying on simple numeric PINs to upgrade their security settings. Independent reports suggest that this account password feature was initially observed in Android beta builds as early as July 2026, under the codename “dedicated account password system,” before its confirmed wider release this week.
| Security Feature | Previous Implementation | Upgraded Standard |
| Primary Login Method | SMS Verification Codes | Biometric & Device-Bound Passkeys |
| Two-Step Verification | 6-Digit Numeric PIN | Alphanumeric Password (8+ Characters) |
| Cross-Platform Support | Single Ecosystem Key | Multi-Device Key Registration |
| Inbound Call Security | Unverified Caller Display | Contextual Indicators (Country & Shared Groups) |
New Anti-Scam Measures for Inbound Calls
WhatsApp is also rolling out a practical, albeit lower-profile, anti-fraud measure specifically for Android users, building on its ongoing efforts to combat messaging scams. When a call originates from a number not saved in a user’s contacts, the incoming call screen will now display additional contextual information. This includes details such as whether the number is from a different country and if the caller shares any common groups with the recipient.
Many scam and vishing operations exploit urgency and unfamiliarity to pressure victims into answering or acting impulsively. This added contextual friction provides users with a crucial moment to assess the legitimacy of an incoming call before engaging, potentially preventing them from falling victim to fraud.
Account takeover remains one of the most prevalent entry points for various forms of abuse on messaging platforms, ranging from SIM-swap fraud to social engineering scams that hijack a victim’s contact list. By simultaneously integrating scaled passwordless authentication, a more robust secondary password requirement, and intelligent contextual caller information, WhatsApp is reinforcing multiple layers of its security architecture, rather than relying on a single control.
What You Should Do
- Enable Passkeys: Navigate to Settings > Account > Passkeys and set up a passkey for your WhatsApp account using your device’s biometric or screen lock authentication.
- Upgrade Two-Step Verification: If you are still using a six-digit PIN for two-step verification, update it to a strong, alphanumeric password (at least 8 characters, including letters, numbers, and ideally symbols).
- Review Account Security: Regularly check your WhatsApp security settings to ensure all available protections are enabled and up-to-date.
- Exercise Caution with Unknown Calls: Pay attention to the new caller context information for unknown numbers on Android and always be wary of unsolicited calls, especially those demanding immediate action or personal information.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.