WhatsApp is giving users a more robust way to protect their accounts, replacing one of the weaker elements of its two-step verification system with support for proper passwords.
The messaging app now allows users to create an alphanumeric password for two-step verification rather than relying solely on the six-digit PIN that has been available since 2017. The feature remains optional, but the change gives people considerably more flexibility when securing their WhatsApp accounts.
Under the new system, a two-step verification password must contain at least eight characters, including a minimum of one letter and one number. Special characters are supported as well. That makes it possible to create credentials that are substantially harder to guess than a six-digit numeric PIN, particularly for anyone who previously relied on predictable combinations such as repeated or sequential numbers.
It is a relatively straightforward security upgrade, but an important one given WhatsApp’s scale and the amount of personal information that can pass through an account. Messaging services remain attractive targets for account takeover attempts, phishing campaigns and impersonation scams. A stronger second verification credential does not eliminate those risks, but it can make an account more difficult to compromise when other credentials or verification methods are exposed.
WhatsApp is also expanding its use of passkeys. People who access the same WhatsApp account across both Android and iOS can now associate multiple passkeys with that account. Additional passkeys can be created through Account > Passkeys in WhatsApp’s settings.
Passkeys have increasingly become an alternative to conventional passwords across major consumer platforms. They use cryptographic credentials stored on a user’s device and typically rely on the device’s existing authentication method, such as a fingerprint, facial recognition or PIN. Supporting multiple passkeys is particularly useful for people moving between devices and operating systems rather than remaining inside a single hardware ecosystem.
The third change focuses less on account authentication and more on identifying potentially suspicious calls. WhatsApp is adding more context when an incoming call originates from a number that isn’t saved in the user’s contacts.
These calls can now display the country associated with the number and indicate whether the caller shares any WhatsApp groups with the recipient. The extra information could help users distinguish an unfamiliar but legitimate contact from an unsolicited call or possible scam attempt. For now, this feature is limited to Android.
None of these additions will prevent every form of WhatsApp scam or account takeover, particularly when attackers rely on social engineering rather than technical vulnerabilities. They do, however, give users more information and stronger authentication choices. For a service that has become a routine communications tool for billions of people, small improvements to those defensive layers can have an outsized practical impact.

