Security1 distinct publisher2 min readPublished
The August 25 milestone lands against FIDO's count of 5 billion passkeys in circulation. But the stronger two-step verification shipped alongside it is opt-in, so every account that skips it keeps a guessable numeric second step.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
A passkey never gets typed. It sits on the device or in its credential manager and is released by fingerprint, face, or screen-lock code, so a spoofed login page has nothing to collect and there is no SMS code for a caller to talk someone into reading out [6]. Malwarebytes adds a delivery argument: in regions where SMS one-time codes arrive late or not at all, the passkey is the more reliable route, which the writeup offers as an explanation for how the count reached a billion so quickly [7].
Set the billion against FIDO's five billion and you get one in five, or 20 percent [14]. Treat that as a rough scale marker rather than a share. FIDO is counting credentials [2]; WhatsApp is counting people who log back in [1]; and WhatsApp now issues more than one passkey per account, so a user with an Android phone and an iPhone registers one on each [4]. The two figures do not share a unit.
The second change is the one that touches attacker economics. A six-digit numeric PIN has 1,000,000 possible values [15], and user choice does not spread evenly across them: Malwarebytes describes PINs such as "123456" as common, weak, and reused [8]. The replacement is a longer alphanumeric password that accepts special characters [3]. Per Malwarebytes, that secret is what still stands between an account and an attacker who has already obtained the one-time code [9].
These are two independent switches, not one upgrade. Neither the passkey nor the new password format is retroactive or forced, so an account keeps its old PIN, or no passkey at all, until the user goes and changes it [10]. The guidance itself tells users to move to the new password format "when it becomes available", which reads as staged availability rather than a flag flipped for everyone [11]. An enrolled passkey therefore does not retire the PIN path behind it.
There is a dependency worth registering before anyone migrates: the recovery email is the only way to reset the two-step verification password if it is forgotten [12]. Trading six memorable digits for a long alphanumeric string moves the failure mode from guessing to lockout, and the recovery address becomes the account's soft edge.
Also in the same release, Android users get context on calls from numbers not in their contacts, including whether the number is foreign and whether any groups are shared [5]. WhatsApp published the login figure [1]. The count of accounts still sitting on a six-digit PIN, and any date for retiring the format, are not in the announcement as reported [13].
Ranked by verification strength, evidence, and original report placement.
WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app.
The FIDO Alliance estimates 5 billion passkeys are in use worldwide and that 75% of consumers have enabled one on at least one account.
WhatsApp's two-step verification is moving from a simple six-digit PIN to a longer alphanumeric password that can include special characters.
Passkey support originally launched on Android and later extended to iOS; WhatsApp now supports multiple passkeys per account, so a user with both an Android phone and an iPhone can register one on each device.
On Android, WhatsApp now shows extra context about calls from numbers not saved in contacts, including whether the number is from another country and whether any groups are shared.
Passkeys resist phishing because there is no password or SMS code to type into a fake site or hand to a scammer; the passkey is stored on the device or in its credential manager and unlocked with a fingerprint, face, or screen-lock code.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
A BLE reconnect callback is not readiness: model it as recovery or lose data quietly1 distinct publisher
build
SMS OTP as a ledger entry: one challenge, one send, and a server that owns expiry1 distinct publisher
product
Instapaper's second rewrite in 18 years is a spend signal, not a Pocket obituary1 distinct publisher
leadership
Memory at 300% ends the cheap phone: IDC cuts units 16.7% while market value keeps climbing1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party numbers, one relay
Every quantity in this story — a billion logins, 5 billion passkeys, 75% of consumers — originates with the party it flatters and reaches us through a single security vendor's blog. WhatsApp's own announcement is described but not quoted, and FIDO's estimate arrives without a methodology note. What holds up well is the product mechanics: the passkey menu path, multiple credentials per account, the recovery email as sole reset. That is checkable-in-an-afternoon detail a vendor rarely fumbles, which is why this sits mid-scale rather than at the floor.
Enormous where it is counted
A billion people signing in without a password is the largest consumer authentication datapoint anyone has put a number on, and it describes shipped behaviour, not a pilot. The gap is that adoption of the fix announced the same day is entirely unmeasured: the alphanumeric second factor lands in stages, existing PINs survive untouched, and no figure exists for how many accounts that leaves on six digits. Strong uptake of the headline feature, unknown uptake of the one that closes the hole.
Milestone framing over an opt-in floor
"One of the largest passwordless rollouts to date" is a fair reading of the number. What the framing glides past is that the weakest link is left exactly where it was: an account whose second step is 123456 keeps it until its owner goes hunting through Settings, and the replacement may not even be available yet. Setting a count of people beside a count of credentials flatters both. The security improvements are real; the sense of a problem solved is a few steps ahead of what shipped.
The advice comes with a checkout
The piece closes on Malwarebytes Mobile Security and its Scam Guard feature, and it is shaped as a to-do list — the form security writing takes when the writer sells protection. The upstream incentive runs the same direction: a billion-user milestone is a marketing asset for WhatsApp, announced on its own schedule with its own metric. None of that makes the guidance wrong, and the settings steps cost nothing to follow. It does mean the enthusiasm in this story has two owners and no disinterested party.
Plausible, single-voiced
We would bet on the product facts and hold back on the figures. One publisher, no second account, and the two numbers doing the most work are both self-reported by organisations with a stake in them. Against that, nothing in the story is contested, the mechanics are internally consistent, and the most consequential line — that old PINs simply persist — is one a vendor had no reason to volunteer.