WhatsApp bolsters account protection with alphanumeric PINs and multi-passkey support
WhatsApp is upgrading its two-step verification to allow longer alphanumeric passwords with special characters, replacing the previous six-digit PIN option. Users can now register multiple passkeys on their account, which is useful for those switching between iOS and Android devices. Additionally, Android users will see more context about calls from unknown numbers, such as country of origin and shared groups.
The shift from six-digit PINs to alphanumeric passwords with special characters addresses a known weakness in two-step verification, as short numeric codes are more vulnerable to brute-force attacks. Passkeys, which WhatsApp first introduced in 2024, rely on biometric authentication like Face ID or fingerprints rather than traditional passwords, making remote account compromise significantly more difficult since attackers would need physical device access. The multi-passkey capability specifically accommodates users who alternate between Apple and Android devices, eliminating friction when switching platforms.
These security upgrades arrive alongside other recent WhatsApp changes, including username support launched in late June, which lets users share profiles without exposing phone numbers, and the WhatsApp Plus subscription tier introduced in May alongside similar offerings for Instagram and Facebook. The broader messaging app landscape, including competitors like Signal and Telegram, has been prioritizing accessible security features as phishing attempts grow more sophisticated.
These updates could meaningfully reduce account takeover incidents for WhatsApp's billions of users, particularly those vulnerable to phishing scams that exploit weak verification methods. The alphanumeric PIN option and multi-passkey support may especially benefit journalists, activists, and business users who face heightened targeting risks. Call context features could help Android users avoid social engineering schemes from unknown numbers. However, adoption depends on users actively enabling these protections, and those who skip the stronger options may remain exposed to evolving threats.