Buried in WhatsApp’s security announcement this week is a sentence that reads less like a product note and more like a public callout: “If you’ve been using ‘123456’, this is your sign to upgrade.”
Somebody at Meta clearly looked at the data on six digit PINs and lost patience. So the PIN is gone, replaced by an actual password. That is one of three changes rolling out to more than two billion accounts, and they are not equally important. One of them is a genuine upgrade to how WhatsApp accounts get stolen. One is overdue housekeeping. One is a small interface tweak that will probably stop more fraud than either.
The short version
- Two-step verification grew up: the six digit PIN is now a full password, minimum eight characters, at least one letter and one number, special characters allowed
- Multiple passkeys per account: useful if you carry an iPhone and an Android, or a phone and a tablet. Over a billion people have already set one up since WhatsApp added support in 2023
- Caller context on Android: when an unknown number rings you, WhatsApp now shows whether it is from another country and whether you share any groups with the caller
- Where to find it: Settings, then Account, then Passkeys or Two-step verification
- What it is aimed at: account takeovers that start with somebody talking you out of a code, which is still the single most common way a WhatsApp account changes hands
The three changes, in plain terms
WhatsApp’s own framing lumps these together as one security release. In practice they attack different problems, and it is worth separating them.
| Feature | Before | Now | What it stops |
|---|---|---|---|
| Two-step verification | Six digit numeric PIN | Alphanumeric password, 8 characters or more, symbols allowed | Guessing and brute force against a million possible combinations |
| Passkeys | One passkey per account | Multiple passkeys, so iOS and Android can both hold one | Phishing, code interception, “read me the number you just got” |
| Unknown caller info | A number and nothing else | Country of origin plus shared groups, on Android first | Cold call impersonation scams that rely on you answering fast |
Why the password change matters less than it sounds
A six digit PIN has exactly one million possible values. That is a small number by any modern standard, and it is the sort of thing security researchers have been complaining about for years. Moving to eight or more characters with letters, digits and symbols pushes the search space into territory where guessing stops being a realistic attack.
Here is the catch. Almost nobody loses a WhatsApp account to guessing. The two-step verification PIN is not something an attacker can hammer at from the internet. It gets asked for when somebody tries to register your number on a new device, and by that point the attacker has usually already convinced you to hand over a one-time code. The PIN was never the weak link so much as the last speed bump.
That does not make the change pointless. It closes off the small set of cases where somebody who knows you well can guess a birthday or a repeated digit, and it removes an embarrassing default. If you are setting a new one, the same rules apply as everywhere else, and our guide on how to build a password that is actually hard to guess covers the mechanics. Do not reuse anything.
The passkey is the part that changes the math
This is the change worth acting on today. A passkey is a cryptographic key pair. The private half stays locked in your phone’s secure hardware and never travels. When WhatsApp needs to confirm it is you, your device signs a challenge with that key after your face, fingerprint or screen lock unlocks it. Nothing that can be typed, screenshotted or repeated over the phone ever leaves the device.
Compare that to the flow that dominates real world account theft.
That is the whole argument for passkeys, and it is why over a billion WhatsApp users have already set one up. The new part is that you can register more than one. Until now, keeping a passkey on an iPhone and an Android tablet meant picking a side. Now both can hold their own key, which removes the most common reason people abandoned passkeys and fell back to codes.
Caller context is the quietly practical one
The third change gets the least attention and may prevent the most money from moving. On Android, when a number you do not know calls you through WhatsApp, the app now shows whether the number is registered in a different country and whether you and the caller share any groups.
Two data points, and both of them are the exact questions a fraud victim wishes they had asked. A “bank security team” calling from a number registered three time zones away is a fairly loud signal. So is a “colleague” you share no groups with.
WhatsApp’s own framing is that scammers rely on urgency, and the fix is context that lets you take a beat before answering. The scale of what that is aimed at is not small.
What none of this fixes
Worth being honest about the limits, because “major security upgrade” headlines have a way of making people feel safer than they are.
- Social engineering still works. If somebody talks you into approving a login on your own device, biometrics do not save you. The passkey will happily sign the challenge, because you told it to.
- Caller context is Android first. iPhone users are waiting, and Apple’s own call screening sits in a different place in the system.
- Your backups are a separate question. End-to-end encrypted backups have their own key or password, and this release does not change them.
- Losing every device is still painful. Multiple passkeys help, but if all of them go, you fall back to a code and the new password.
None of that is a reason to skip the setup. It is a reason to keep the rest of your basics in order, which is roughly the same argument behind the NSA’s recent push to get people to actually maintain their routers. The single change is rarely the whole fix.
The five minute version
Do these three things now
- Update the app first. None of this appears on an old build. App Store or Play Store, then reopen WhatsApp.
- Add a passkey. Settings, then Account, then Passkeys. Do it on every device you actually use, now that more than one is allowed.
- Replace the PIN. Settings, then Account, then Two-step verification. Eight characters or more, letters and numbers, throw in a symbol. Store it in a password manager, not your notes app.
The reason to bother is not that WhatsApp suddenly became insecure. It is that the attacks aimed at it have not been technical for years. They are phone calls, borrowed urgency and a six digit number read out loud. Everything in this release is a way of removing that number from the conversation, and the passkey removes it entirely.
If you only do one thing, do that one. And if you want the wider checklist that sits underneath all of this, our plain English guide to online safety basics is the place to start.

