Skip to main content
CybersecurityHacking

WhatsApp Bolsters Sign-In Security with Multi-Device Passkey Support

Hand hovers over smartphone displaying passkey management interface on screen.

"More than 1 billion people use a passkey to log into WhatsApp," Meta said — a striking scale for a technology designed to be resistant to phishing and account takeover.

Multiple passkeys for one account across iOS and Android

Meta announced that WhatsApp now supports multiple passkeys tied to a single account so users with both iOS and Android devices can sign in using the phishing-resistant method. The company framed the change as a convenience and security improvement: multiple passkeys let a single WhatsApp account accept more than one device-authenticated credential, simplifying multi-device use without reverting to less secure authentication steps.

Users are able to manage these credentials directly in the app under Settings > Account > Passkeys, the company said.

Rollout timeline embedded in the announcement

The update builds on a multi-year rollout. WhatsApp first introduced passkeys on Android in October 2023, expanded support to iOS in early 2024, and later integrated passkeys into Facebook logins in June 2025. Meta characterized the multi-passkey capability as the next step in that progression, extending passkey sign-in flexibility across users' device ecosystems.

Two-step verification: from six-digit PINs to full passwords

WhatsApp also upgraded its two-step verification option. "Two-step verification is an extra protection layer that helps prevent someone from taking over your account, even if they get hold of your one-time passcode," WhatsApp said in a blog post shared with The Hacker News. Until now, the secondary secret was a six-digit PIN; WhatsApp said it has “upgraded it to a full password: longer, alphanumeric, and even with special ch@racters to make it harder to guess.”

The company was explicit about user behavior when urging adoption: "If you've been using '123456,' this is your sign to upgrade," WhatsApp wrote.

More context on calls for Android users to blunt scams

Separately for Android, WhatsApp said it will surface additional context on incoming calls from people who are not in a user's contacts. The extra context will include details such as where the call is originating from, whether the caller is already on the recipient's contact list, and whether both parties are members of any common groups.

WhatsApp described the change in behavioral terms: "Scammers rely on urgency – now you can take a beat with some more info before answering," the messaging app said.

What this means for technologists and security teams, end users, and scammers

  • Technologists and security teams: Multiple passkeys per account change how authentication is managed on-device and across platforms. Teams responsible for user support and account recovery will need to note the Settings > Account > Passkeys management path announced by WhatsApp and consider how multi-passkey states affect incident response and device loss scenarios.
  • End users and the general public: The shift from a six-digit PIN to a longer alphanumeric password for two-step verification raises the bar on guessable secondary secrets. WhatsApp’s explicit call to upgrade weak PINs (for example, "123456") signals the company expects users to move to stronger strings that include letters, numbers and special ch@racters.
  • Adversaries and scammers: The combination of phishing-resistant passkey sign-ins and additional call-origin context on Android reduces two common exploit avenues — credential phishing and urgency-based social-engineering calls — by removing obvious weak points and adding friction for hurried decisions.

Closing observation

WhatsApp’s updates stitch together three distinct moves: broader, device-flexible passkey use; a harder two-step verification secret; and added caller context on Android. Together they reflect a push toward reducing reliance on easily phished credentials and on-the-spot social-engineering tactics. The immediate questions left open by the announcement are practical: how rapidly users will enable stronger two-step verification, how adoption of multiple passkeys will change support workflows, and whether the extra call context will measurably reduce scam success — outcomes Meta and WhatsApp will be positioned to report on only after uptake and operational use.

Original story