WhatsApp has rolled out new security tools including stronger two-step verification options and support for multiple passkeys, responding to growing threats from phishing and hacking attempts.
WhatsApp announced a series of security enhancements this week aimed at protecting users from account hijacking and related cyber threats. The updates reflect broader industry efforts by messaging platforms to strengthen defenses as online scams become more advanced and widespread.
Among the new features is an upgraded two-step verification system that moves beyond the standard six-digit PIN. Users can now set longer, alphanumeric passwords that include special characters, making brute-force attacks more difficult. Additionally, WhatsApp now permits multiple passkeys on a single account—a particularly useful feature for users who switch between different devices or operating systems.
Passkeys, which WhatsApp began supporting in 2024, represent a significant security advancement over traditional password-based authentication. By enabling login through biometric methods such as fingerprint or Face ID, passkeys eliminate vulnerability to phishing attacks that typically target username-password combinations. According to WhatsApp, this approach requires potential attackers to have physical access to a user's device, substantially raising the barrier for unauthorized account access.
The rollout aligns with similar initiatives by other messaging platforms including Signal and Telegram, which have also prioritized user security improvements. WhatsApp's focus appears to be on providing robust protection without complicating the user experience, addressing a key challenge in security implementation.










