WhatsApp Boosts Account Security with Multi-Device Passkeys and Enhanced 2FA
**Meta** has rolled out significant security enhancements for **WhatsApp** users, including support for multiple passkeys across devices and a more robust two-step verification system. These updates aim to bolster protection against phishing attacks and unauthorized account access, making it easier and safer for over a billion users to secure their messaging experience.
Privacy-conscious users and IT security professionals will welcome the latest suite of account security features announced by **Meta** for its **WhatsApp** platform. The updates prioritize phishing resistance and stronger authentication methods, building on previous security initiatives.
### Multi-Device Passkey Support Arrives
A key highlight is the introduction of support for multiple passkeys linked to a single **WhatsApp** account. This enhancement is particularly beneficial for users who operate across both **iOS** and **Android** devices, allowing them to leverage phishing-resistant sign-in methods seamlessly.
**Meta** reports that over a billion people now use a passkey to log into **WhatsApp**. Passkey support was initially rolled out for **Android** in October 2023, subsequently expanding to **iOS** in early 2024. The company further integrated passkeys into **Facebook** logins in June 2025, demonstrating a broader commitment to this secure authentication standard.
Users can manage their passkeys by navigating to `Settings > Account > Passkeys` within the application.

### Upgraded Two-Step Verification
In addition to passkeys, **WhatsApp** has also enhanced its two-step verification (2SV) process. Previously relying on a six-digit PIN, the system now supports a full password option, allowing for longer, alphanumeric combinations, including special characters.
"Two-step verification is an extra protection layer that helps prevent someone from taking over your account, even if they get hold of your one-time passcode," **WhatsApp** stated in a blog post. "Until now it was a six-digit PIN, we've now upgraded it to a full password: longer, alphanumeric, and even with special ch@racters to make it harder to guess. If you've been using '123456,' this is your sign to upgrade."
This move significantly strengthens the 2SV mechanism, making it considerably more difficult for unauthorized parties to bypass, even if they manage to obtain a user's initial login credentials.

### Enhanced Call Context for Unsaved Contacts
For **Android** users, **WhatsApp** is also rolling out an update that provides more context for calls originating from numbers not in their contact list. This feature aims to help users identify potential scam calls more effectively by displaying details such as the call's origin, whether the caller is in their contacts, and if they share common groups.
"Scammers rely on urgency β now you can take a beat with some more info before answering," the messaging app noted. This proactive measure empowers users with critical information, allowing them to make more informed decisions before engaging with unknown callers, thereby mitigating risks associated with social engineering and phishing attempts.