A New Standard for WhatsApp Security
Meta has officially launched a suite of significant security upgrades for WhatsApp, signaling a major move to harden the platform against increasingly sophisticated account takeover tactics. The updates center on replacing legacy security features with more resilient, modern alternatives.
The changes arrive as billions of users rely on the app for sensitive communications, making it an attractive target for bad actors. By upgrading two-step verification and expanding passkey functionality, Meta is looking to drastically reduce the risk of unauthorized access.

Goodbye, Six-Digit PINs
For years, WhatsApp users have relied on a standard six-digit PIN as their secondary layer of security. However, Meta is now allowing users to upgrade this to a full, alphanumeric password. This new implementation allows for longer, complex strings including special characters, making brute-force attacks significantly more difficult.
Multi-Passkey Support and Unknown Callers
Passkeys—which allow users to sign in via biometric methods like Face ID or fingerprint—have already seen massive adoption, with over one billion users currently utilizing the technology. To further improve user experience, WhatsApp now allows multiple passkeys to be stored on a single account.
- Cross-platform support: Easily manage access if you switch between iOS and Android.
- Improved security: Removes reliance on phishable password/username combinations.
- Enhanced privacy: New context indicators for calls from unknown numbers to help identify potential scams.
Passkeys remove the need to rely on username and password combinations, which are ordinarily susceptible to phishing attacks. Passkey logins make it harder for bad actors to remotely access your accounts.
— TechCrunch