WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app.

The announcement included two other security upgrades: a stronger two-step verification method and more context for incoming calls from unknown numbers. It marks one of the largest passwordless authentication rollouts to date. Passkeys are now firmly mainstream, with the FIDO Alliance estimating that 5 billion are in use worldwide and 75% of consumers have enabled one on at least one account.

Three things changed:

  1. Passkey support originally launched on Android and later extended to iOS. WhatsApp now supports multiple passkeys per account, so people who switch between an Android phone and an iPhone (or use both) can register a passkey on each device.
  2. Two-step verification is moving from a simple six-digit PIN to a longer alphanumeric password that can include special characters, making it much harder to guess or brute-force.
  3. On Android, WhatsApp now shows extra context about calls from numbers not saved in your contacts, including whether the number is from another country and whether you share any groups. It’s a small but useful nudge against the urgency tactics scammers rely on.

Passkeys are resistant to phishing because there is no password or SMS code to type into a fake website or hand over to a scammer. Instead, a passkey is stored on your device or in its credential manager and unlocked using your fingerprint, face, or screen-lock code. They’re also useful in regions where SMS one-time-passcode delivery is unreliable, which might explain why adoption reached a billion users so quickly.

The upgraded two-step verification password closes a real gap. PINs such as “123456” were common, weak, and reused, and a longer alphanumeric password with special characters raises the bar against account-takeover attempts, even if an attacker somehow obtains your one-time code.

The caller-context feature gives people more information to assess legitimacy before answering an unfamiliar number.


Phone Scam Check

What WhatsApp users need to do

Users need to set up a passkey and upgrade their two-step verification password, while the caller-context feature will appear automatically on supported Android devices:

  • Set up a passkey via Settings > Account > Passkeys, and follow the instructions on your device. Don’t forget to add a second one if you use both an Android and an iOS device.
  • If you still use a six-digit PIN for two-step verification, upgrade to the new password format when it becomes available, especially if your PIN is predictable. You can find instructions to set up two-step verification for WhatsApp in this blog. If it’s already enabled, select Two-step verification to find the option to change your PIN.
  • Add a recovery email to two-step verification if you haven’t already. It’s the only way to reset the password if you forget it.
  • Android users should pay attention to the new caller-context details before answering calls from unknown numbers, treating urgency as a red flag rather than a reason to rush.

Passkeys and stronger two-step verification aren’t retroactive or forced, so accounts still relying on an old PIN or no passkey at all will remain unchanged until users upgrade them.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android →