WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into the messaging app, marking one of the largest passwordless authentication rollouts in consumer tech history.
Alongside this milestone, Meta’s flagship messaging platform is rolling out a major upgrade to two-step verification, replacing the long-standing six-digit PIN with a full alphanumeric password, and adding new caller-context features designed to help users spot scams before they even pick up the phone.
Passkeys let WhatsApp users authenticate using their device’s fingerprint sensor, Face ID, or screen lock code instead of typing in a numeric code or PIN.
Since the feature relies on cryptographic keys tied to the device rather than a shared secret transmitted over a network, it is inherently more resistant to phishing, credential stuffing, and SIM-swap-style takeover attempts than legacy verification codes.
WhatsApp says the technology has now crossed the 1 billion user mark, and the company is expanding support so that people who split their usage between an Android phone and an iPhone can register multiple passkeys on a single account.
The feature is accessible under Settings> Account> Passkeys, where users can add a new key or review existing ones tied to their device’s password manager.
The more consequential change targets two-step verification, the secondary layer of protection that has traditionally required a six-digit PIN even after a one-time SMS passcode has been entered.
WhatsApp is now letting users replace that PIN with a genuine password: longer, alphanumeric, and capable of including special characters, which meaningfully raises the difficulty of brute-force and credential-guessing attacks.
According to WhatsApp’s own security requirements outlined in the WhatsApp security announcement, a new password must be at least 8 characters long and include at least one letter and one number, with the option to strengthen it further by including symbols.
This matters because six-digit PINs, while better than nothing, offer a comparatively small keyspace and are frequently reused across services or set to easily guessable sequences like “123456.”
Security researchers have long flagged short numeric codes as a weak link in account-recovery and secondary-authentication flows, since automated guessing or social-engineering attacks can bypass them faster than a properly constructed password.
WhatsApp’s own messaging around the rollout explicitly nods to this risk, noting that anyone still relying on a simple numeric PIN should treat the update as a prompt to upgrade.
Independent reporting indicates the account password feature was first spotted in Android beta builds as early as July 2026, developed under the codename “dedicated account password system,” before receiving confirmation of a wider rollout this week.
| Security Feature | Previous Implementation | Upgraded Standard |
| Primary Login Method | SMS Verification Codes | Biometric & Device-Bound Passkeys |
| Two-Step Verification | 6-Digit Numeric PIN | Alphanumeric Password (8+ Characters) |
| Cross-Platform Support | Single Ecosystem Key | Multi-Device Key Registration |
| Inbound Call Security | Unverified Caller Display | Contextual Indicators (Country & Shared Groups) |
WhatsApp is also rolling out a lower-profile but practical anti-fraud measure for Android users, expanding ongoing efforts to improve messaging anti-scam tools.
When a call arrives from a number not saved as a contact, the incoming call screen now surfaces additional context, including whether the number is from a different country and whether the caller shares any groups with the recipient.
Since many scam and vishing operations rely on urgency and unfamiliarity to pressure victims into answering or acting quickly, this added friction gives users a moment to evaluate legitimacy before engaging.
Account takeover remains one of the most common entry points for messaging-platform abuse, from SIM-swap fraud to social-engineering scams that hijack a victim’s contact list.
By combining passwordless authentication at scale, a stronger secondary password requirement, and contextual caller information, WhatsApp is tightening multiple layers of its security stack simultaneously rather than relying on any single control.
Users who have not yet enabled two-step verification or are still using a legacy PIN should treat this rollout as a timely reminder to review their account security settings.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…
AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…
A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…
ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is…