WhatsApp Replaces Its Six-Digit PIN With a Full Password

WhatsApp’s August 25 security announcement says the service is replacing the six-digit PIN used for two-step verification with a longer password that can include letters, numbers and special characters. The extra credential is intended to protect an account even when someone else obtains its one-time registration code.
The rollout also allows more than one passkey on an account and gives Android users additional context about calls from numbers outside their contacts. A same-day TechCrunch report describes all three changes and notes that multiple passkeys are meant to accommodate people using WhatsApp across Android and iOS.
The password protects the step after the one-time code

WhatsApp’s stronger two-step verification targets account takeovers in which an attacker obtains the temporary code sent during phone-number registration. When two-step verification is enabled, the additional password remains a separate barrier: possession of the one-time code alone should not complete registration on another device.
The previous credential was restricted to six digits. Allowing a longer combination of letters, numbers and special characters expands the possible credential space and makes an unpredictable password harder to guess. The new format does not automatically make every password strong, however; a short, obvious or reused choice can still weaken the protection.
Users who receive the option should treat the replacement as a distinct account-security credential and choose a long, unique password. It should not be reused for an email account, mobile-carrier login or another service that could become part of an account-recovery attack.
Multiple passkeys cover Android and iOS devices

WhatsApp now permits more than one passkey on the same account. Passkeys let a returning user authenticate through an enrolled device using a fingerprint, facial recognition or screen-lock code, avoiding the need to enter a WhatsApp code or PIN for that login route.
The change matters most to people who use both Android and iOS. They can attach device-backed credentials from more than one platform instead of depending on a single passkey. Users can review the credentials attached to an account under Settings, Account and Passkeys, and should remove any entry associated with a device or credential store they no longer control.
Passkeys and the two-step-verification password are complementary rather than interchangeable. A passkey supplies a device-backed, phishing-resistant way to verify the returning user; the password supplies an additional secret when a phone number is being registered after a one-time code has been obtained.
Android shows context before an unknown call is answered

The caller feature is limited to Android in the current announcement. For a WhatsApp call from a number outside the recipient’s contacts, the incoming-call screen can show whether the number is from another country and whether the caller shares any WhatsApp groups with the recipient.
That information does not block the call, authenticate the caller or classify the number as fraudulent. It instead gives the recipient more evidence before answering, which can reduce the effectiveness of scams built around urgency or a false impression of familiarity.
A shared group is not proof that a caller is trustworthy, just as an international number is not proof of fraud. The practical value is narrower: users can compare the displayed context with what the caller claims and verify an unexpected approach through a known channel.
The protections operate at different security boundaries
The update is clearest when each control is matched to the threat it addresses:
- One-time registration code: demonstrates access to the phone number during registration, but it can still be disclosed or stolen through social engineering.
- Two-step-verification password: adds a separate secret after the temporary code, reducing the value of that code to an attacker.
- Multiple passkeys: provide device-backed authentication across enrolled Android and iOS environments and reduce reliance on credentials that can be typed into a phishing page.
- Android caller context: provides information about a non-contact caller before the call is answered, without blocking or authenticating that person.
End-to-end encryption protects a different boundary. It is designed to keep message and call content between the participating endpoints. It does not decide whether the person registering an account is its rightful owner, make a weak account password stronger or establish that an unfamiliar caller can be trusted.
If an attacker takes control of an authorized account or device, that attacker has reached an endpoint that message encryption is not designed to police. Account credentials, passkeys and caller context therefore remain relevant even though WhatsApp conversations are end-to-end encrypted by default.
The features are still reaching users gradually
The announcement does not mean every account already displays every option. An August 25 Android Authority account describes a gradual rollout and says the password option was not yet visible on the Android and iOS installations its writer checked; it also identifies the enhanced caller information as Android-only.
Users who already see the password control can replace a weak PIN, while those with the expanded passkey menu can check which credentials are enrolled. If a control is absent, the rollout may not yet have reached that account, device or app installation.
WhatsApp has not published a completion date for the rollout. As of August 26, the confirmed changes are a stronger two-step-verification credential, support for multiple passkeys and additional non-contact caller context on Android; universal availability remains the main unresolved part of the release.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.