WhatsApp Strengthens Account Security with Better Two-Step Verification, Multi-Device Passkeys, and Call Screening

WhatsApp announced on August 25, 2026 a suite of new security features aimed at hardening account protection, including a stronger two-step verification system, support for more than one passkey per account, and contextual information for calls originating from unknown numbers (TechCrunch).
The most consequential change targets WhatsApp's two-step verification, which has remained largely unchanged since its introduction on February 10, 2017. Originally, the feature required a six-digit passcode entered at the time of phone registration (TechCrunch; Engadget). Users set it up by navigating to Settings > Account > Two-Step Verification. WhatsApp's FAQ describes the feature as an optional layer that adds security by requiring two different forms of authentication, and notes that users can choose their phone number, password, or email address for the additional factor (WhatsApp FAQ).
Under the new update, users can now replace the six-digit PIN with a longer, alphanumeric password that supports special characters, making it substantially harder to guess or brute-force (TechCrunch). A six-digit PIN has only one million possible combinations. A longer password mixing letters, numbers, and symbols expands that into the trillions. This brings WhatsApp's second-factor approach closer to what security teams have long recommended for credential strength, moving away from the numeric-only constraint that has been a limitation since launch.
WhatsApp has also expanded its passkey support. The company first introduced passkeys in 2024, allowing users to authenticate using Face ID or a fingerprint instead of a password. Passkeys are a newer authentication method that uses cryptographic key pairs — one half stored on your device, the other on the service's server — so that no password ever travels over the internet. Unlike passwords or SMS-based verification codes, passkeys make remote account compromise significantly harder because an attacker would need physical access to the device storing the user's portion of the key (WhatsApp FAQ). The August 2026 update now permits users to register more than one passkey on a single account. WhatsApp says this is particularly useful for people who use both iOS and Android devices, as each platform can hold its own passkey credential (TechCrunch).
On the call-screening side, Android users now receive additional context when a call comes in from a number not saved in their contacts. The app displays whether the caller's number originates from a different country and whether the caller shares any WhatsApp groups in common with the recipient (TechCrunch). This gives users a quick way to assess whether an incoming call is likely spam, social engineering, or a legitimate contact they simply have not saved.
These features arrive within a broader product cadence. In late June 2026, WhatsApp launched usernames, enabling people to share their profiles without exposing their phone number. In late May 2026, Meta introduced a subscription plan for WhatsApp that unlocks features like profile customization, super reactions, and story insights, alongside similar Plus offerings for Instagram and Facebook. In January 2026, WhatsApp began rolling out a "Strict account settings" mode accessible via Settings > Privacy > Advanced, designed to protect users from cyber attacks (TechCrunch).
WhatsApp's FAQ also notes that one-time passcodes received on WhatsApp appear only on a user's primary device, the phone used to register the account (WhatsApp FAQ), which limits the exposure of OTPs to linked companion devices.
The broader pattern here is worth pausing on. WhatsApp is steadily layering security controls that were once the province of enterprise identity systems onto a consumer messaging app with roughly three billion users. Multi-passkey support, in particular, addresses a real friction point. Anyone who has juggled passkeys across an iPhone and an Android tablet knows that the previous single-credential-per-account limitation forced awkward workarounds. Allowing multiple device-bound passkeys removes that barrier without weakening the cryptographic model.
The move to alphanumeric passwords for two-step verification is a quieter but meaningful upgrade. Six-digit PINs have always been vulnerable to guessing attacks, particularly when users default to predictable sequences like 123456 or 111111. Permitting longer, complex passwords closes that vector while keeping the optional nature of the feature intact.
Taken together, these incremental improvements compound. Each layer, from usernames that hide phone numbers to multi-passkey authentication to caller-context metadata, narrows the attack surface for social engineering and account takeover. None of these features is revolutionary on its own. But the cumulative effect is a messaging platform whose security posture has shifted meaningfully closer to what a security team would design from scratch, rather than what a consumer app added after the fact.


