WhatsApp is rolling out security updates to protect user accounts and help users recognize potentially suspicious calls. The platform is introducing multi-passkey support, moving beyond simple six-digit PINs for two-step verification, and adding context features for incoming calls from unknown numbers on Android.
Multi-Passkey Implementation Across Mobile Ecosystems
Over a billion people have already configured passkeys on WhatsApp. Passkeys allow users to enter their account using a fingerprint, facial recognition, or the screen lock code.
The update allows adding multiple passkeys to the same account. This is useful for those using the service on both Android and iOS, as it allows associating a different access key with each operating system. To set this up, users navigate to WhatsApp Settings, select Account, and access the Passkey section.
Moving Beyond Six-Digit PINs in Two-Step Verification
Two-step verification has also been strengthened. The previous six-digit PIN is replaced by a full password.

The new credential can be longer and contain letters, numbers, and special characters. This increases the available combinations, making the password harder to guess.
Users who used a predictable sequence like “123456” should update it. This tool serves to prevent another person from taking control of the account even when they manage to obtain the one-time code used during access.
Metadata Context for Unknown Calls on Android
WhatsApp is introducing more information for calls received from people who are not in the user’s contacts.

On Android, before answering, the user can view more information about the number. The app indicates if the call comes from another country and shows the presence of mutual groups with the caller.
These data do not automatically prove that a call is dangerous, but they offer useful context to evaluate if it is a potential scam, as scammers often rely on urgency. At present, a date has not been communicated for the arrival of this function on iPhone.
Securing Session Handshakes and Associated Hardware
Beyond native feature updates, account security requires monitoring active sessions and connected devices. Ignoring active sessions via WhatsApp Web can allow third parties to access messages, photos, and files. Users must review connected devices under Settings to close unknown or forgotten sessions.
Furthermore, local device hygiene remains critical. Physical device access or monitoring software can compromise privacy. Android users are advised to check device administrator apps under Settings > Security and Privacy > Other security settings > Device admin apps to ensure no unauthorized application is installed.
The 30-Second Verdict
WhatsApp’s security updates focus on identity verification and evaluating who is trying to contact the user, without modifying the end-to-end encryption, which is already active by default. By deploying multi-device passkeys, complex alphanumeric passwords for verification, and call metadata screening on Android, the platform strengthens account security.