WhatsApp is making it harder for attackers to take over accounts. The messaging platform has announced several security updates, including support for multiple passkeys on one account, stronger two-step verification passwords, and more information about unknown callers on Android.
The changes come as WhatsApp says more than one billion people are now using passkeys to authenticate their accounts. The company is now expanding how passkeys work, particularly for people who use WhatsApp across multiple devices and platforms.
Passkeys are becoming a more practical alternative to SMS-based verification, and WhatsApp is now making them more flexible.
Previously, users could set up a passkey for their WhatsApp account and use device-based authentication such as a fingerprint, Face ID or the device’s screen lock to verify their identity. The new update allows users to add multiple passkeys to the same WhatsApp account.
This is useful for people who switch between devices or use phones running different operating systems. For example, someone with both an iPhone and an Android phone can set up passkeys for both devices instead of relying on a single authentication method.
Passkeys also remove the need to receive a one-time SMS code every time authentication is required. Since authentication happens through the device, biometric information itself is not shared with WhatsApp.
Users can manage their passkeys by going to Settings > Account > Passkeys in WhatsApp.
WhatsApp is also changing how its two-step verification works. Until now, WhatsApp’s two-step verification relied on a six-digit PIN. That provided an additional layer of protection beyond the standard phone number verification, but the format also limited the complexity of the password users could choose.
The new system allows users to create alphanumeric passwords with special characters. That gives users the option to create much stronger credentials instead of relying on a six-digit number. A longer password with a mix of letters, numbers and special characters is much harder to guess through brute-force attempts.
This is useful because account takeovers do not always require an attacker to completely bypass WhatsApp’s security. If an attacker manages to obtain or intercept an initial verification code, the two-step verification password can become another important barrier between the attacker and the account.
WhatsApp is therefore giving users a stronger second layer of protection.
The third update focuses on something that has become increasingly common on messaging platforms: unwanted calls from unknown numbers.
WhatsApp is adding more context when an unsaved contact calls an Android user. Before answering the call, users will be able to see information such as the country code associated with the number and any mutual groups shared with the caller.
That may sound like a small change, but it can be useful when dealing with suspicious calls.
For example, receiving a WhatsApp call from an international number you do not recognise is already a reason to be cautious. If WhatsApp can also show that you have no mutual groups with the caller, users have more information to decide whether the call is worth answering.
The feature does not automatically identify a caller as a scammer. Instead, WhatsApp is giving users additional context before they decide whether to answer.
WhatsApp says more than one billion users have already adopted passkeys. It shows that the technology is moving beyond early adopters. Allowing multiple passkeys could make the system more useful for people who regularly use more than one phone. Instead of treating passkeys as a single replacement for SMS verification, WhatsApp is turning them into a flexible authentication layer that can follow users across their devices.
All of these features work alongside WhatsApp’s existing end-to-end encryption, which protects personal messages and calls.






