bytevyte
bytevyte
Language
quick-beats

WhatsApp account security: passwords, passkeys, caller info

WhatsApp account security

WhatsApp is retiring the six-digit PIN that has guarded two-step verification since 2017, replacing it with full alphanumeric passwords as part of a broader WhatsApp account security push announced this week. The update, revealed by Meta on August 25, also lets users register multiple passkeys to a single account and adds extra context for incoming calls from unknown numbers on Android. All three features are rolling out gradually.

The new credential accepts letters, numbers, and special characters such as @ or $, and must contain at least eight characters including one number and one letter. Meta says the upgrade is designed to keep attackers out of an account even when they have obtained a user's one-time verification code, because the password is now a separate layer on top of that code. Two-step verification remains available on both Android and iOS.

Two-step verification has relied on a six-digit PIN since the feature arrived in early 2017, a format with only a million possible combinations. That six-digit code has been the weak point in WhatsApp account security for years. Those codes were also prone to predictable choices such as birthdays or repeating digits. Moving to an alphanumeric password with special characters expands the guessable space far beyond what a six-digit code allowed, which addresses the brute-force weakness at the heart of the old system.

The change matters most in a specific attack scenario: a user's six-digit one-time code is intercepted or phished, and the attacker still needs the second factor to take over the account. Under the old setup, that second factor was itself a short numeric code that could be guessed once the first code was known. A full password widens that gap considerably, which is the main reason the update is a substantive change rather than a cosmetic one. This is the scenario the WhatsApp account security update targets.

The flow when setting up a phone is familiar: WhatsApp sends a six-digit one-time code to verify the number, and two-step verification adds a second check on top of it. The password does not replace that code. It replaces the old PIN as the second check, so the verification step users already know stays in place while the credential behind it gets much stronger.

Multiple passkeys on one WhatsApp account

Passkey support, which reached Android in 2023 and iOS in 2024, previously allowed a single passkey per account. That limit is now gone: users can register several passkeys on the same account, a change aimed at people who run WhatsApp on both an Android phone and an iPhone. Each device can hold its own credential instead of sharing one key across platforms. The multi-passkey change is part of the same WhatsApp account security update.

Passkeys unlock with a fingerprint, Face ID, or the device's screen lock rather than a typed code, and they are considered phishing-resistant because the credential is tied to the specific app and domain requesting it. Credentials are managed under Settings > Account > Passkeys, where users can now create separate passkeys for each platform they sign in with.

WhatsApp says more than a billion people have already set up a passkey, a scale that makes the feature one of the largest real-world deployments of the technology. The progression from Android-only support in 2023 to multi-passkey accounts in 2026 shows the feature moving from early adoption into mainstream use. That covers common real-world setups, including a personal phone paired with a work phone, or an Android handset used alongside an iPhone.

Android gains context on unknown callers

On Android, calls from numbers not saved in a user's contacts now surface extra information before the call is answered, including the caller's country of origin and any WhatsApp groups the caller shares with the recipient. The caller context is the third piece of the WhatsApp account security update. WhatsApp positions the details as a way to judge whether an unfamiliar call is worth picking up, particularly given the volume of spam and scam calls routed through messaging apps.

The caller context is Android-only for now, and Meta has not said when or whether iOS will receive the same information. The feature targets a different entry point than the other two changes: passwords and passkeys guard against credential theft, while the caller details help users recognize the social-engineering calls that often precede phishing attempts.

For users who want the protections now, the setup is straightforward: enable two-step verification and choose a password rather than a PIN, register a passkey on each device that signs into the account, and use the caller details on Android when deciding whether to answer. The password and passkeys are separate mechanisms, so either can be adopted on its own, and the caller context requires no configuration beyond keeping the app updated.

The WhatsApp account security update at a glance

The three changes address separate weak points, from guessed PINs to credential phishing to unfamiliar callers. Read together, the trio closes the most common paths into an account rather than patching a single hole. The table below summarizes the WhatsApp account security changes.

FeatureBeforeAfter
Two-step verificationSix-digit numeric PINAlphanumeric password with special characters, at least 8 characters
PasskeysOne per accountMultiple passkeys across Android and iOS
Unknown calls on AndroidNumber onlyCountry of origin and shared groups shown

The features began arriving on August 25 and are being phased in, so the password option and caller context may not appear on every device or in every region immediately. The gradual rollout means some users will see the WhatsApp account security changes before others. WhatsApp has not provided a completion date for the gradual rollout.

The timing of the WhatsApp account security changes reflects a wider shift in consumer messaging, where short numeric codes are giving way to passwords and passkeys and where caller identification is becoming a standard anti-spam tool. The practical stakes are straightforward: a hijacked account exposes private conversations and gives attackers a way to target the victim's contacts.

Why this matters

For the average user, the WhatsApp account security update means an account that survives a stolen verification code, less friction when signing in across two phones, and a better-informed decision before answering an unknown number. None of it requires new habits beyond setting a stronger password once. With more than a billion passkeys already in use, the changes effectively raise the security baseline for a messaging service used by a large share of the world's phone owners.

Sources

New Account Security Features for WhatsApp

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.