WhatsApp has announced a set of new security features aimed at reducing account takeover risk and improving the way people make decisions when they receive suspicious communication. The update focuses on WhatsApp passkeys, a stronger version of two-step verification (2SV), and additional caller context when calls come in from people outside your contacts.
According to WhatsApp, more than one billion people now use a passkey to sign in to their WhatsApp accounts. With this rollout, the messaging app is expanding what passkeys can do and making the second layer of protection more flexible and harder to guess.
Multiple WhatsApp passkeys for more devices
One of the biggest changes is that users can now add more than one passkey to their WhatsApp account. This is useful if you use WhatsApp on multiple devices—for example, both an iPhone and an Android phone.
Instead of being limited to a single passkey, you can register additional sign-in credentials so each device can authenticate you securely. That can make everyday access smoother while keeping the account protected in a modern, phishing-resistant way.
WhatsApp’s announcement frames passkey adoption as already widespread, which is why improving multi-device support is a practical next step for many users.
Stronger 2SV: from PINs to password-style codes
WhatsApp is also upgrading its two-step verification experience. Previously, the second factor relied on a one-time passcode presented as a six-digit PIN. With the update, WhatsApp is moving to a password format for 2SV.
This change allows the verification secret to be longer and to include alphanumeric characters as well as special characters. In practice, that means the credential can be more complex than a simple six-digit code, which can help improve resistance against guessing.
If you already have 2SV enabled, the update signals a meaningful shift in how the protection is structured, because users will no longer be confined to a short numeric PIN.
Caller context for unknown calls on Android
The final security feature is targeted, for now, at Android users. When someone receives a call from a number that is not saved in their contacts, WhatsApp will display more information about the caller before the call is answered.
Specifically, the app will show details including the caller’s country and whether they are part of the same WhatsApp groups as the recipient.
WhatsApp’s message to users is clear: scammers often create pressure and urgency to push people into acting quickly. By providing additional context, the app aims to give users a moment to pause and make a more informed decision.
How these updates fit together
Taken as a set, the changes address security at multiple stages. WhatsApp passkeys strengthen the sign-in process and reduce reliance on traditional approaches that can be more vulnerable to social engineering. The upgraded 2SV adds another barrier to account access, moving from a numeric PIN toward a more configurable password-style secret.
Meanwhile, the caller context feature addresses a different kind of threat—unsolicited calls from unknown numbers—by improving the information a user sees at the moment they decide whether to answer.
In other words, WhatsApp is not only protecting accounts behind the scenes, but also improving the information users receive in real-world interactions.
Related protection: Scam Alert for suspicious messages
These announcements arrive shortly after WhatsApp introduced Scam Alert, an optional feature that uses AI to flag suspicious messages from people who are not in your contacts.
That earlier step shows a broader strategy: combining account-level security measures with assistance that helps users recognize risky communication. While Scam Alert focuses on message content, the newly announced caller context is designed for calls, and the passkey and 2SV changes focus on protecting the account itself.
What to do after the update
If you want to make the most of WhatsApp’s security improvements, consider the following actions:
- Check your passkey setup: If you use WhatsApp on more than one device, add additional passkeys where available so each device can authenticate securely.
- Review two-step verification: If you have 2SV enabled, ensure you understand the updated password-style option and choose a strong, unique credential with a good mix of characters.
- On Android, pay attention to caller details: When you receive a call from an unknown number, use the added country and shared-group information to decide whether the call seems legitimate.
These steps can help you align your day-to-day use with the new protections WhatsApp is rolling out.
Why passkeys and stronger 2SV matter
Passkeys are designed to improve security compared to older login methods by changing how authentication works. Instead of relying solely on codes that could be intercepted or replayed, passkey sign-in is built to be more resistant to phishing attempts and account takeovers.
Pairing passkeys with enhanced 2SV provides layered protection. Even if an attacker could find a way to bypass one mechanism, the second factor adds an extra checkpoint before the account can be accessed.
In parallel, richer caller context helps reduce the impact of social engineering in live interactions—where timing and pressure are often used to push people into mistakes.
Bottom line
WhatsApp’s latest security updates bring meaningful improvements for both account protection and real-time decision-making. With WhatsApp passkeys, users can now store multiple passkeys for different devices. Two-step verification is being strengthened by replacing the six-digit PIN approach with a password-style secret that supports longer, more complex entries. For Android users, WhatsApp will also provide extra information when an unknown caller reaches out, including country and shared group status.
For many people, these upgrades translate into less friction in everyday access and better defenses against common tactics used by scammers.
