WhatsApp says more than one billion people now use passkeys to protect their accounts, as the messaging service introduces support for multiple passkeys and upgrades other account-security features.
The Meta-owned service is also replacing its six-digit two-step verification PIN with a longer password option. Android users will receive additional context before answering calls from numbers that are not saved in their contacts.
Multiple passkeys for one account
A passkey lets a user verify access to WhatsApp with the same method used to unlock a device, such as a fingerprint, facial recognition or screen-lock code. WhatsApp first introduced passkey support as an alternative to authentication codes and PINs.
In its August 25 announcement, WhatsApp said users can now add more than one passkey to an account. The change is intended for people who use the service across Android and iOS devices.
Passkeys are based on FIDO authentication standards and use public-key cryptography. The FIDO Alliance explains that the credential is tied to the relevant account and can be stored on a phone, computer or hardware security key. Because the user does not type a shared password into a site or app, passkeys are designed to resist phishing and credential theft.
WhatsApp’s one-billion figure is a company-reported adoption milestone. The company did not provide a regional breakdown, the number of active passkey authentications, or the share of its total users that has configured the feature.
Stronger two-step verification
WhatsApp is also changing the additional credential used for two-step verification. Instead of limiting users to a six-digit PIN, the service now supports a longer alphanumeric password that can include special characters.
The feature adds a separate protection layer intended to make account takeover harder even when an attacker obtains a one-time code. Users still need to choose a unique credential and keep recovery information secure.
On Android, WhatsApp will show more information when a call comes from someone outside the user’s contacts. The context can include whether the number is registered in another country and whether the caller shares any groups with the recipient.
The caller-context feature does not determine that a call is fraudulent. It gives recipients more information before they decide whether to answer, particularly when an unfamiliar caller is attempting to create urgency.
The changes arrive as messaging services face sustained pressure to limit impersonation, social engineering and account-takeover scams. Singapore, for example, has placed WhatsApp and several other communications platforms under new online-crime codes that require additional anti-scam measures.
WhatsApp said passkeys can be managed under Settings, Account and Passkeys. Availability may vary by operating system, app version and rollout stage, so users may not see every option immediately.
Singapore police disrupt 30,000 Apple iMessage accounts as scam losses hit $1.7M

