WhatsApp Upgrades Account Security With Alphanumeric Passwords and Expanded Passkey Support
Meta expands passkey deployment to over one billion accounts while introducing multi-device security management and anti-fraud tools on Android.

Meta-owned messaging platform WhatsApp is rolling out a series of security updates, substituting its long-standing six-digit numerical PIN system with full alphanumeric passwords while scaling device-based passkey authentication to over one billion users. The company is also deploying new caller context tools for Android users designed to mitigate phone scams from unknown contacts.
The updated two-step verification framework replaces the traditional six-digit personal identification code with complex passwords that accept letters, numbers, and special characters. Security experts have long cited six-digit numeric codes as offering limited protective margins—permitting just one million total permutations—which required rate-limiting measures to prevent brute-force entry. The transition to standard passwords allows users to construct significantly stronger security credentials for account recovery and identity verification.
Simultaneously, Meta disclosed that WhatsApp's passkey implementation has reached more than one billion active deployments, creating the world's largest consumer passwordless authentication ecosystem to date. Passkeys replace traditional SMS-based one-time passwords by anchoring authentication directly to the hardware level of a user's smartphone. Account access is confirmed using local security controls, such as fingerprint sensors, facial recognition cameras, or hardware screen locks.
To support users operating multiple hardware devices, WhatsApp has introduced multi-passkey management within its account settings. The configuration update allows users to register and store distinct passkey credentials for separate hardware platforms—such as individual Android phones and iOS tablets—under Settings > Account > Passkeys.
On the Android platform, WhatsApp is deploying anti-fraud measures targeted at calls received from unrecognized phone numbers outside a user's contact list. The application will automatically display context clues alongside incoming calls, revealing details such as the country origin of the phone number or whether the caller shares common group memberships with the target recipient.
The security changes arrive as WhatsApp navigates stringent regulatory obligations in Europe, where the service operates as a primary communication utility for hundreds of millions of consumers. Under the European Union’s Digital Markets Act (DMA), Meta has been compelled to open its core messaging infrastructure to third-party messaging platforms, enabling cross-app communication across European markets.
As reported by The Next Web, the expansion of hardware-level security measures raises technical questions regarding cross-platform interoperability. While passkey architecture secures individual WhatsApp user accounts on Meta's infrastructure, Meta's published interoperability proposals have yet to detail how security and identity assurances line up when messages originate from external third-party services connecting to the network.
The update positions WhatsApp at the center of a broader convergence around digital identity in Europe. As Meta deploys private-sector passkey authentication across its user base, European Union regulatory frameworks are simultaneously mandating state-backed digital identity wallets across member states, setting up parallel private and public models for user verification.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.

