Skip to content

SecurityWidely confirmed7 publishers2 min readPublished Updated

WhatsApp trades a six-digit PIN for a real password, and a passkey for each platform

The two-step secret becomes a full alphanumeric password, and an account can now hold one passkey per platform. Both remain opt-in settings inside the app.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying WhatsApp trades a six-digit PIN for a real password, and a passkey for each platform
Photo: fb.com

What happened

  • Meta said on Tuesday that a WhatsApp account can now hold more than one passkey, so someone using both Android and iOS can enroll one per platform.
  • Two-step verification moves off the six-digit PIN to a full password: longer, alphanumeric, and accepting special characters.
  • WhatsApp says more than a billion people already log in with a passkey, on a service it puts at over 3 billion users in more than 180 countries.
  • Android call screens will show context on callers who are not saved contacts, including foreign numbering and shared groups.

Why it matters

  • capability Staff who carry an Android handset and an iPhone can now be passkey-authenticated on both, so the typed-code fallback no longer has a convenience argument behind it.
  • constraint Every one of these controls lives in a consumer settings menu, so a security team can lift its assumed baseline only for people it persuades, not for accounts it administers.
  • exposure Most WhatsApp accounts an organisation deals with still have no passkey, which keeps the stolen one-time code the working route into supplier, contractor and customer conversations.
  • contradiction BleepingComputer lists the Android caller context as country and shared groups; The Hacker News adds whether the caller is already a contact, an odd field on a screen defined by the caller not...

A six-digit PIN has exactly one million possible values [18]. WhatsApp's pitch for replacing it is guessing resistance: longer, alphanumeric, special characters permitted, with a nudge that anyone still using "123456" should move [4][5]. Take a six-character password over case-sensitive letters and digits and the space becomes about 56.8 billion values, roughly 56,800 times the PIN, before a single special character is counted [19]. None of the four accounts of the announcement mentions a minimum length or a complexity rule [17], so the ceiling has moved further than the floor.

The reason this is more than a settings tweak is the shape of a WhatsApp takeover. Accounts are closely tied to phone numbers, which makes the one-time verification code the thing worth stealing, whether lifted directly or talked out of the victim, according to CyberInsider [14]. The two-step secret is the hop after that, and until now it was six digits [4]. WhatsApp says two-step verification exists precisely to hold when someone already has the one-time passcode [6]. Passkeys avoid that path: authentication runs against the device fingerprint, Face ID or screen lock, with no separate code or PIN to type [13].

The multi-passkey change looks minor and is not. CyberInsider describes the account as previously supporting a single passkey [12], so anyone carrying an Android handset and an iPhone had one enrolled platform and a typed-code fallback on the other. Two enrollments remove the reason to keep the fallback warm. What no version of the announcement says is that the one-time code route has been retired [21], which means the phishing-resistant method is additive rather than exclusive, and the weakest enabled path still sets the account's real strength.

Most of what shipped this year aims at the user rather than the credential: Strict Account Settings in January for high-risk people such as journalists and public figures [9], warnings in March on device-linking requests that may be fraudulent [10], and an optional Scam Alert beta this month running a local machine learning model [11], alongside the new caller context on Android [7]. Those are all interventions at the moment of attack. Passkeys change what an attacker has to hold. The vendor report promoted under BleepingComputer's own coverage makes the matching point from the defender's side: across 338 million simulations in production environments, prevention falls off sharply once an intruder is using valid credentials [16]. Making valid credentials harder to obtain is the part of that curve a messaging app can touch.

What to watch

  • Whether WhatsApp publishes a minimum length or complexity rule for the new two-step password, or accepts whatever a user types.
  • Whether the non-contact caller context reaches iOS, and how long the Android-only gap lasts.
  • Whether Scam Alert leaves limited beta, and what the on-device model actually flags.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence68
Adoption35
Hype gap+10
Incentives40
Confidence72

Perspective Coverage

7 publishers
Builder
Builder 33%
Operator
Operator 55%
Investor
Investor 12%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Meta announced on Tuesday a set of WhatsApp account security features, including support for adding multiple passkeys to a single account, aimed at users with both iOS and Android devices signing in with the phishing-resistant method.

  2. [2]

    Users can manage or add passkeys by navigating to Settings > Account > Passkeys.

  3. [3]

    WhatsApp says more than 1 billion people already use a passkey to log into WhatsApp.

Sources

7 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    2 articles · August 25, 2026

    WhatsApp adds stronger two-step verification, multiple passkeys
  2. cyberinsider.com

    1 article · August 25, 2026

    WhatsApp adds multiple passkeys and stronger two-step verification | CyberInsider
  3. helpnetsecurity.com

    2 articles · August 26, 2026

    Meta adds three new features to keep WhatsApp accounts secure
  4. scworld.com

    1 article · August 26, 2026

    WhatsApp enhances account security with passkeys and stronger verification
  5. securityaffairs.com

    1 article · August 26, 2026

    WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
  6. securityweek.com

    1 article · August 25, 2026

    WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
  7. thehackernews.com

    1 article · August 25, 2026

    WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories