WhatsApp is replacing its six-digit two-step verification PIN with a full password, Meta said in a newsroom post on August 25. The change turns what was a short numeric code into a longer alphanumeric secret that can include special characters, and it lands alongside two other account-security changes: extra context on calls from people who aren’t in your contacts on Android, and support for more than one passkey per account.

WhatsApp two-step verification becomes a password
Two-step verification is the code WhatsApp asks for when someone tries to register your phone number on a new device. It exists precisely because the six-digit SMS one-time passcode is the weak link — it can be socially engineered out of you, intercepted, or handed over by a SIM-swapped carrier account. Until now, the second factor protecting against that was itself just six digits, which is a keyspace a determined attacker can work through.
Meta describes the upgrade in its own words:
Until now, it was a six-digit PIN, but we’ve upgraded it to a full password: longer, alphanumeric, and even with special characters to make it harder to guess.
The company’s post doesn’t state a rollout schedule, whether existing PINs are converted automatically, or what happens to people who already have a PIN set. If you have never turned two-step verification on, it remains the single most useful thing you can do to stop an account takeover — and account takeovers are the mechanism behind most of the “your friend is asking you for money on WhatsApp” scams that plague large markets like India and Brazil.
Unknown callers now come with context on Android
The Android-specific change is smaller but arguably more visible day to day. When a call comes in from a number that isn’t saved in your contacts, WhatsApp will now show extra information about it — Meta gives two examples: whether the number is registered in a different country, and whether you share any groups with that person.
That is a genuinely useful signal. A “job offer” call from an unfamiliar international number with no groups in common is a different proposition from a call from someone in your building’s residents group. It is worth being clear about what it is not, though: this is context about the number, not verification of who is holding the phone. A scammer operating from a local SIM will look no different from a legitimate stranger under this system, so it narrows the problem rather than solving it.
Passkeys: more than one per account
Meta says more than a billion people have now set up a WhatsApp passkey, and the notable change here is that you can register more than one — useful if you move between an Android phone and an iPhone, or between a phone and a tablet, since each device stores its own passkey. WhatsApp’s stated path is Settings > Account > Passkeys.
A passkey replaces the login code with your fingerprint, face unlock or screen lock, which removes the SMS code from the equation entirely on that device. The trade-off worth understanding is that passkeys live inside your platform’s credential store — Google Password Manager on Android, iCloud Keychain on Apple devices — so your WhatsApp login becomes as recoverable, and as exposed, as that account is. Being able to hold a second passkey on a second platform is a hedge against exactly that single point of failure, which is why the multi-passkey change matters more than it sounds.
What to do now
Open WhatsApp, go to Settings > Account, and check whether two-step verification is switched on at all. If it is, expect the PIN field to give way to a password prompt as the change reaches your device, and pick something you would use for a bank rather than a birth year. If you use both Android and iOS, add a passkey on each. None of this costs anything, and all of it sits between your account and someone else registering your number on their phone.





