SecurityWidely confirmed7 publishers2 min readPublished Updated
WhatsApp trades a six-digit PIN for a real password, and a passkey for each platform
The two-step secret becomes a full alphanumeric password, and an account can now hold one passkey per platform. Both remain opt-in settings inside the app.
The Watch · Security desk

What happened
- Meta said on Tuesday that a WhatsApp account can now hold more than one passkey, so someone using both Android and iOS can enroll one per platform.
- Two-step verification moves off the six-digit PIN to a full password: longer, alphanumeric, and accepting special characters.
- WhatsApp says more than a billion people already log in with a passkey, on a service it puts at over 3 billion users in more than 180 countries.
- Android call screens will show context on callers who are not saved contacts, including foreign numbering and shared groups.
Why it matters
- capability Staff who carry an Android handset and an iPhone can now be passkey-authenticated on both, so the typed-code fallback no longer has a convenience argument behind it.
- constraint Every one of these controls lives in a consumer settings menu, so a security team can lift its assumed baseline only for people it persuades, not for accounts it administers.
- exposure Most WhatsApp accounts an organisation deals with still have no passkey, which keeps the stolen one-time code the working route into supplier, contractor and customer conversations.
- contradiction BleepingComputer lists the Android caller context as country and shared groups; The Hacker News adds whether the caller is already a contact, an odd field on a screen defined by the caller not...
A six-digit PIN has exactly one million possible values [18]. WhatsApp's pitch for replacing it is guessing resistance: longer, alphanumeric, special characters permitted, with a nudge that anyone still using "123456" should move [4][5]. Take a six-character password over case-sensitive letters and digits and the space becomes about 56.8 billion values, roughly 56,800 times the PIN, before a single special character is counted [19]. None of the four accounts of the announcement mentions a minimum length or a complexity rule [17], so the ceiling has moved further than the floor.
The reason this is more than a settings tweak is the shape of a WhatsApp takeover. Accounts are closely tied to phone numbers, which makes the one-time verification code the thing worth stealing, whether lifted directly or talked out of the victim, according to CyberInsider [14]. The two-step secret is the hop after that, and until now it was six digits [4]. WhatsApp says two-step verification exists precisely to hold when someone already has the one-time passcode [6]. Passkeys avoid that path: authentication runs against the device fingerprint, Face ID or screen lock, with no separate code or PIN to type [13].
The multi-passkey change looks minor and is not. CyberInsider describes the account as previously supporting a single passkey [12], so anyone carrying an Android handset and an iPhone had one enrolled platform and a typed-code fallback on the other. Two enrollments remove the reason to keep the fallback warm. What no version of the announcement says is that the one-time code route has been retired [21], which means the phishing-resistant method is additive rather than exclusive, and the weakest enabled path still sets the account's real strength.
Most of what shipped this year aims at the user rather than the credential: Strict Account Settings in January for high-risk people such as journalists and public figures [9], warnings in March on device-linking requests that may be fraudulent [10], and an optional Scam Alert beta this month running a local machine learning model [11], alongside the new caller context on Android [7]. Those are all interventions at the moment of attack. Passkeys change what an attacker has to hold. The vendor report promoted under BleepingComputer's own coverage makes the matching point from the defender's side: across 338 million simulations in production environments, prevention falls off sharply once an intruder is using valid credentials [16]. Making valid credentials harder to obtain is the part of that curve a messaging app can touch.
What to watch
- Whether WhatsApp publishes a minimum length or complexity rule for the new two-step password, or accepts whatever a user types.
- Whether the non-contact caller context reaches iOS, and how long the Android-only gap lasts.
- Whether Scam Alert leaves limited beta, and what the on-device model actually flags.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence68
- Adoption35
- Hype gap+10
- Incentives40
- Confidence72
Perspective Coverage
7 publishers- Builder
- Builder 33%
- Operator
- Operator 55%
- Investor
- Investor 12%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Meta announced on Tuesday a set of WhatsApp account security features, including support for adding multiple passkeys to a single account, aimed at users with both iOS and Android devices signing in with the phishing-resistant method.
ReportedSupportedSource: The Hacker News5 sources— create a free account to open themView cited source - [2]
Users can manage or add passkeys by navigating to Settings > Account > Passkeys.
- [3]
WhatsApp says more than 1 billion people already use a passkey to log into WhatsApp.
- [4]
WhatsApp said: "Until now it was a six-digit PIN, we've now upgraded it to a full password: longer, alphanumeric, and even with special ch@racters to make it harder to guess."
- [5]
WhatsApp said: "If you've been using '123456,' this is your sign to upgrade."
- [6]
WhatsApp said two-step verification is an extra protection layer that helps prevent someone taking over an account even if they get hold of the user's one-time passcode.
- [7]
On Android, WhatsApp will now show more information about a non-contact caller, such as whether the number is from a different country and whether the parties share any groups.
- [8]
The Hacker News reports the extra call context will include where the call originates, whether the person calling is already on the contact list, and whether both parties are in any common groups.
ReportedSupportedSource: The Hacker News4 sources— create a free account to open themView cited source - [9]
In January, WhatsApp began rolling out Strict Account Settings, an Apple Lockdown-style feature for high-risk individuals such as journalists and public figures, including against spyware attacks.
- [10]
In March, Meta announced WhatsApp would warn users when a device-linking request may be fraudulent, a tactic used to hijack accounts by tricking users into sharing a linking code or scanning a malicious QR code.
- [11]
Earlier this month WhatsApp introduced an optional Scam Alert feature in limited beta, using a local machine learning model to warn users they are being targeted by scammers.
- [12]
CyberInsider describes the main passkey change as support for adding more than one passkey to the same WhatsApp account, particularly for people using both Android and iOS.
- [13]
Passkeys let WhatsApp users verify identity using the method already protecting their device, such as fingerprint, Face ID or screen-lock code, removing the need to enter a separate verification code or PIN.
- [14]
Because WhatsApp accounts are closely tied to phone numbers, stronger authentication can help limit account takeover attempts involving stolen verification codes or other social engineering techniques.
- [15]
According to WhatsApp, more than 3 billion people in over 180 countries use the messaging service.
- [16]
A Blue Report 2026 promotion carried with BleepingComputer's coverage states that overall prevention scores can hide what happens after initial access, that prevention drops sharply once attackers are using valid credentials, and that the report measures defenses technique by technique across 338 million simulations run in customer production environments.
ReportedSupportedSource: Blue Report 2026 promotional copy on BleepingComputer2 sources— create a free account to open themView cited source - [17]
None of the four supplied accounts of the announcement states a minimum length or complexity requirement for the new two-step verification password.
- [18]
A six-digit numeric PIN has 1,000,000 possible values.
- [19]
A six-character password drawn from case-sensitive letters and digits has 56,800,235,584 possible values, about 56,800 times the six-digit PIN space, excluding special characters.
- [20]
The 1 billion accounts with a passkey represent under a third of WhatsApp's stated user base of more than 3 billion, leaving most accounts without one.
- [21]
None of the four supplied accounts states that the one-time verification code login path has been retired.
Sources
7 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comWhatsApp adds stronger two-step verification, multiple passkeys
2 articles · August 25, 2026
- cyberinsider.comWhatsApp adds multiple passkeys and stronger two-step verification | CyberInsider
1 article · August 25, 2026
- helpnetsecurity.comMeta adds three new features to keep WhatsApp accounts secure
2 articles · August 26, 2026
- scworld.comWhatsApp enhances account security with passkeys and stronger verification
1 article · August 26, 2026
- securityaffairs.comWhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
1 article · August 26, 2026
- securityweek.comWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
1 article · August 25, 2026
- thehackernews.comWhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.