WhatsApp is rolling out stronger account security with longer two-step verification passwords, multiple passkeys and more information about unknown callers.
WhatsApp is making a significant change to the way billions of people protect their accounts.
The messaging platform announced Tuesday that it is upgrading its traditional six-digit two-step verification PIN, expanding passkey support and giving Android users more information when an unknown person calls them.
The changes are designed to make account takeovers and social-engineering scams harder, while giving users more control over how they authenticate themselves.
The announcement comes as messaging accounts have become increasingly valuable targets for scammers. A compromised WhatsApp account can provide access not only to private conversations, but also to contacts, shared media and potentially sensitive information exchanged through the platform.
WhatsApp says more than one billion people already use passkeys to access their accounts, making the technology a significant part of its security strategy.
Six Digits Are No Longer Enough

One of the most visible changes concerns WhatsApp’s two-step verification system.
Previously, users who enabled the feature relied on a six-digit PIN as an additional layer of protection. The PIN is separate from the one-time registration code sent when a phone number is registered with WhatsApp.
Now, WhatsApp is allowing users to replace that six-digit PIN with a full password.
The new password can be longer and include letters, numbers and special characters, making it substantially more difficult to guess than a short numerical combination.
The purpose of two-step verification remains the same: even if an attacker manages to obtain a user’s one-time verification code, the additional password can prevent them from successfully taking control of the account.
Meta says the change is intended to make the extra security layer harder to compromise.
For users who have been relying on simple PINs, the upgrade is particularly relevant.
A six-digit code has only one million possible combinations. A properly chosen longer password provides a much larger search space and can be considerably harder to guess.
But the security benefit ultimately depends on the password users choose.
A long password that is reused across other services is still a security risk.
WhatsApp Expands Passkeys
The second major change involves passkeys, which allow users to authenticate using their device’s built-in security features rather than manually entering passwords or verification codes.
Depending on the device, that can mean using a fingerprint, Face ID or the device’s screen-lock mechanism.
Passkeys are designed to be resistant to traditional phishing attacks because there is no conventional password for a scammer to trick a user into revealing.
WhatsApp says more than one billion users have already set up a passkey.
The company is now allowing users to add multiple passkeys to the same WhatsApp account.
That could be especially useful for people who regularly use more than one device or switch between Android and iOS. A user can have separate passkeys associated with different devices rather than relying on a single authentication method.
WhatsApp says users can manage the feature under Settings > Account > Passkeys.
The move also reflects a broader shift across the technology industry.
Apple, Google, Microsoft and other major companies have been pushing passkeys as an alternative to traditional passwords.
WhatsApp’s scale makes its adoption particularly significant.
Why Passkeys Matter
Passwords have always had a fundamental weakness: people can give them away.
A phishing message can convince someone to enter a password on a fake website. A scammer can ask for a verification code over the phone. Passwords can also be reused, leaked or stored insecurely.
Passkeys work differently.
The private cryptographic key remains associated with the user’s device and is protected by the device’s authentication system.
The user does not normally need to type the underlying credential into a website or tell it to another person.
That makes the technology much harder to exploit through conventional phishing.
However, passkeys do not make an account completely immune to attack.
If an attacker gains control of a user’s device or successfully compromises another part of the account-recovery process, security risks can remain.
The important point is that passkeys eliminate one of the most common weaknesses in traditional authentication: the need to transmit or remember a password.
More Information About Unknown Callers
WhatsApp is also adding another security feature, this time aimed at scams that begin with a phone call.
On Android, users will receive additional context when someone who is not saved in their contacts calls them.
The information can include whether the caller’s number is associated with another country and whether the caller shares any WhatsApp groups with the recipient.
The goal is straightforward.
Instead of receiving an unexpected call with almost no information, users will have additional clues that may help them decide whether answering makes sense.
WhatsApp says scammers often rely on urgency to pressure people into responding quickly. Providing more information before the call is answered gives users an opportunity to pause and assess the situation.
The feature is currently being introduced for Android users.
A Response to a Bigger Problem
These changes are arriving as account-takeover scams continue to evolve.
Attackers do not necessarily need to break WhatsApp’s encryption to compromise an account.
In many cases, the easier target is the user.
A scammer may pretend to be a friend, family member, company employee or technical-support representative.
They may then ask the victim to provide a verification code or approve an authentication request.
This type of social engineering can be surprisingly effective because it attacks human trust rather than the underlying encryption technology.
That is why stronger authentication alone is not enough.
Users still need to recognize suspicious messages and calls.
WhatsApp’s new features are designed to create additional barriers when those attacks occur.
What Users Should Do
For WhatsApp users, the announcement provides a good reason to review account security settings.
First, users who have not enabled two-step verification should consider doing so.
Those who already use it should consider replacing a weak six-digit PIN with a stronger password if the option is available on their account.
Users should also consider enabling a passkey where supported.
And perhaps most importantly, nobody should share a WhatsApp verification code or security credential with another person — even if the request appears to come from someone they know.
A legitimate friend or company representative should not need the user’s private authentication code.
This Is Bigger Than WhatsApp
WhatsApp’s changes are part of a much broader transformation in digital security.
The technology industry is gradually moving away from passwords and toward authentication methods based on cryptographic keys, biometrics and trusted devices.
At the same time, messaging platforms are adding more context to interactions because scammers increasingly use social engineering rather than sophisticated technical exploits.
For a service with more than three billion users, even relatively small improvements can have enormous consequences at global scale.
A stronger authentication system can potentially prevent millions of account-takeover attempts.
Better caller information can help users recognize suspicious contacts before they engage.
And multiple passkeys can make secure authentication more practical for people who use several devices.
WhatsApp’s latest security update is not a single feature.
It is a broader attempt to strengthen several points where users can become vulnerable.
The company is replacing its traditional six-digit two-step verification PIN with stronger password options, allowing multiple passkeys and giving Android users additional information about calls from unknown numbers.
Truth Mode: none of these features makes WhatsApp impossible to hack, and no security system can completely eliminate social engineering.
What they do is raise the difficulty for attackers.
The most important change may ultimately be the growth of passkeys.
With more than one billion WhatsApp users already using them, passkeys are moving beyond an experimental replacement for passwords and becoming a mainstream authentication method.
For WhatsApp users, the message is simple:
Security is no longer just about protecting your chats. It is also about protecting the identity that gives you access to them.
And as scammers become better at manipulating people, stronger authentication may become one of the most important defenses between a user and a stolen account.