WhatsApp is changing account security. You should reconfigure this immediately

  • Two-step verification on WhatsApp is no longer limited to a six-digit numerical PIN
  • You can now set a full-fledged password with letters, numbers, and special characters, at least eight characters long
  • Multiple passkeys can be linked to one account, which will be appreciated by people switching between Android and iPhone

Sdílejte:
Jakub Kárník
Jakub Kárník
28. 8. 2026 14:30
WhatsApp novinky
Advertisement

Two-step verification on WhatsApp has been unchanged since 2017, and since then, one rule applied: six digits, nothing more. Meta is finally changing it and allowing users to set a real password. It sounds like a minor detail, but this very code stands between an attacker and your account when someone tries to re-register you on their phone.

What exactly is changing

The existing PIN is being replaced by a full-fledged password, which can be longer, contain letters and numbers, and now also special characters like an at sign or a dollar sign. The requirement is a minimum of eight characters, including at least one letter and one digit; symbols are optional.

Why does this make sense? Six digits offer a million possible combinations, which sounds like a lot, but in reality, it’s too few for a brute-force attack. Even worse, people commonly choose their birth date or the most cliché sequence imaginable as their PIN. Meta is clearly aware of this – in its announcement, it notes that if you’ve been using 123456 until now, this is your moment.

How two-step verification on WhatsApp actually works

When someone wants to register your account on another phone, you receive a one-time SMS code. If an attacker gets hold of it – for example, because your phone was out of sight for a moment or they tricked you into revealing the code through social engineering – two-step verification is the last obstacle. Without knowing the PIN, or now the password, they won’t get past it.

The feature remains optional, which is a shame. You can set it up in WhatsApp settings under the Account section, and if you’ve never enabled it before, now is a good time to do so.

A billion people and passkeys

The second new feature concerns access keys, or so-called passkeys, which WhatsApp has supported since 2024. Meta announced on this occasion that more than a billion people are already using them. You can now link several keys at once to a single account – useful for anyone who switches between Android and iPhone or uses multiple devices.

Passkeys are more secure than passwords because they are not sent anywhere. You log in with a fingerprint, face, or screen lock, and an attacker has nothing to intercept or trick you into revealing. Additionally, on Android, WhatsApp has added more information about callers not in your contacts – you’ll see the call context before answering, which should help identify scammers.

What a strong password isn’t enough for

One thing needs to be said aloud: even the best password won’t protect you from scams involving linked devices. If you yourself scan a QR code or confirm a pairing that someone tricks you into, an attacker will gain access to your messages regardless of how complex your password is.

Therefore, it’s worth checking the list of linked devices in your settings from time to time and logging out of any you don’t recognize. And most importantly: never confirm a pairing you didn’t initiate yourself, no matter who sends it to you.

Do you even have two-step verification enabled on WhatsApp?

Sources: 9to5Google, TechCrunch, Engadget, BleepingComputer

About the author

Jakub Kárník

Jakub is known for his endless curiosity and passion for the latest technologies. His love for mobile phones started with an iPhone 3G, but nowadays… More about the author

Jakub Kárník
Sdílejte: