WhatsApp swapped its six-digit two-step verification PIN for a real password
Meta replaced WhatsApp's six-digit two-step verification PIN with a full alphanumeric password, and accounts can now hold more than one passkey across Android and iOS.
WhatsApp’s two-step verification is no longer a six-digit PIN. Meta said Tuesday that the field now takes a full password, longer, alphanumeric and open to special characters, and that a single account can hold more than one passkey.
A six-digit PIN has 1 million possible values, and it sat at the end of the one path that account-takeover crews actually use: talk the owner into forwarding the registration code that arrives by SMS, or SIM swap the number outright, then work the recovery flow. Hardening that field raises the cost of the second step. The multi-passkey change fixes something else. An account could hold exactly one passkey, so anyone carrying an Android phone and an iPhone kept falling back to the SMS code on whichever device came second.
What changed in the settings
The two-step verification screen carries the visible change. “Until now, it was a six-digit PIN, but we’ve upgraded it to a full password: longer, alphanumeric, and even with special characters to make it harder to guess,” Meta wrote in Tuesday’s announcement. The mockup in that post shows the rules the new field enforces: at least eight characters, at least one letter, at least one number, and both entries matching. The PIN it replaces had been there since February 2017, when WhatsApp switched two-step verification on for everyone.
Passkeys got the other half of the post. “More than a billion people have already set one up, and you can now add more than one passkey to your account if you use both Android and iOS devices,” the company wrote, pointing people at Settings > Account > Passkeys. WhatsApp started rolling passkeys out on Android in October 2023 and reached iPhone in early 2024, per The Hacker News. A passkey is a WebAuthn credential bound to the device’s biometrics or screen lock, so there’s no code for a stranger to ask for.
Android picks up caller context as well. For a number that isn’t saved as a contact, the incoming-call card now shows the country the number is registered in and whether the caller shares any groups, as TechCrunch reported. Meta’s mockup renders that as “United States · Not a contact · You’re both in 2 groups including Fall Soccer Parents.” Scammers “rely on urgency,” the post says. iOS got no such promise.
None of this arrived unannounced. WABetaInfo spotted the password field in WhatsApp beta for Android 2.26.29.4 on July 23, and read the strings as replacing the PIN rather than stacking a second prompt on top of it. That build wanted six to 20 characters. The shipping mockup shows eight.
What’s still unclear
Meta’s post says “you’ll now see” without naming a date, a version or a staged rollout, which leaves the load-bearing questions open. The biggest one is the PIN that’s already sitting on an account. WABetaInfo’s read of the beta strings was that people with two-step verification enabled “can update their security code when this change rolls out”, which is not the same as being made to.
- Rollout timing. No platform-by-platform schedule was given, and the caller-context card is Android only for now.
- Forced migration. Nobody has said whether a six-digit PIN keeps working indefinitely or gets a mandatory upgrade prompt at next login.
- Accounts with nothing set. Two-step verification stays optional. The change does nothing for accounts that never turned it on, which are the ones the code-forwarding scam hunts.
- Where a second passkey lives. The mockup credits a password manager and lists Face ID as the first entry, without saying whether a second passkey can sit outside iCloud Keychain or Google Password Manager.
What this means for you
Open Settings > Account > Two-step verification and replace the PIN with a long random string out of your password manager. Add the recovery email on the same screen if there isn’t one on file, since that address is what gets the account back when the password is gone (Malwarebytes has the step-by-step). Then open Settings > Account > Passkeys and add one on every device you carry, which is the part that finally works when one of them is an iPhone and the other isn’t.
Be clear about what today’s change doesn’t buy. Malware on the phone still reads your messages, and a hijacked friend’s account can still ask you for money; the crews who run that play work the person rather than the cryptography, which is how three Scattered Spider members ended up pleading guilty. Device security is its own fight, as the US case over a GrapheneOS duress password showed from the other direction. The password field takes a minute to fix. The harder question lands the first time someone with a six-digit PIN, no passkey and no email on file gets phished, because nothing announced Tuesday makes any of that mandatory.
Share this article
Quick reference
Sources
- New Account Security Features for WhatsApp — Meta
- WhatsApp tightens account security with stronger two-step verification and more — TechCrunch
- WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android — The Hacker News
- WhatsApp may upgrade two-step verification with a password — WABetaInfo
- WhatsApp is launching passkey support on Android — TechCrunch
- Now you can enable two-step verification for your WhatsApp account — GSMArena
- How to set up two-step verification on your WhatsApp account — Malwarebytes