Skip to content
Bellator Cyber Guard
News7 min readStandard

WhatsApp Adds Multi-Passkey Support, Stronger 2FA

WhatsApp rolled out multiple passkey support and stronger two-step verification to help block SIM-swap and phishing account takeovers.

By Bellator Cyber Guard Security Team

WhatsApp Strengthens Account Security With Multiple Passkeys

WhatsApp began rolling out an update on August 25, 2026 that lets users register multiple passkeys per account and adds a stronger version of its existing two-step verification feature. WhatsApp is the Meta-owned messaging app used by billions of people for personal and business communication. The update targets a well-documented weak point in messaging-app security: account takeover attempts that rely on SIM-swapping or social engineering to intercept SMS-based verification codes.

A passkey is a cryptographic credential, typically unlocked with a device's biometric sensor or PIN, that replaces a traditional password and cannot be phished or reused across sites because the underlying key never leaves the user's device. WhatsApp previously supported only a single passkey per account; the new update lets users add and manage several passkeys across multiple devices, so losing or replacing a phone no longer removes the fastest path back into the account. Two-step verification, found in WhatsApp's settings menu, is an optional feature that requires a six-digit PIN in addition to standard SMS verification whenever someone tries to register the account's phone number on a new device. According to WhatsApp's own support documentation, two-step verification is described as "an optional feature that adds more security to your WhatsApp account," and the company positions the new passkey option as a way to speed up login while keeping that additional PIN layer available.

The distinction between the two mechanisms matters operationally. Two-step verification is a shared-secret PIN model: effective, but still something a user can be tricked into revealing through phishing, and something that has to be remembered or recovered if forgotten. Passkeys remove the shared secret entirely, instead relying on device-bound cryptography validated through Face ID, Touch ID, Windows Hello, or a device PIN. Security researchers and industry analysis have broadly described passkey-based logins as reducing the friction associated with one-time codes while closing off the credential-phishing paths that PIN- and SMS-based systems remain exposed to.

WhatsApp has not published a specific global rollout timeline, and phased feature rollouts are typical across Meta's platforms, meaning the multi-passkey option and updated two-step verification screen may appear for some users before others depending on app version and operating system. Readers who don't yet see the option under Settings, Account, Two-step verification should check for an app update or wait for the staged rollout to reach their account rather than assume the feature is unavailable to them.

Key Takeaway

Multi-passkey support closes a real gap: if your only passkey was tied to a lost or replaced phone, you previously had no fallback and could be locked out of recovering your WhatsApp account. Registering a passkey on at least two trusted devices now, before you need it, is the practical fix.

What This Means for Practices and Small Businesses

Many healthcare practices, tax preparation offices, and small businesses now use WhatsApp for client communication, appointment reminders, or informal team coordination, often alongside or instead of SMS. That makes WhatsApp account takeover a business-continuity and confidentiality risk, not just a personal-privacy issue: an attacker who gains control of a business's WhatsApp number could access message history, contact lists, and any client or financial information exchanged in chat threads. Note that WhatsApp is not a HIPAA-compliant messaging platform on its own, so practices should already be limiting what protected health information is shared through it, regardless of these security updates.

Bellator Cyber Guard recommends the following steps for readers who rely on WhatsApp for business or sensitive personal use:

  • Enable two-step verification now if it isn't already on: open WhatsApp Settings, tap the three-dot menu, and toggle on two-step verification with a PIN that isn't reused for any other account.
  • Register a passkey on every device you regularly use WhatsApp from once the feature reaches your account, rather than relying on a single device that could be lost, stolen, or replaced.
  • Add a recovery email address to your two-step verification settings so you aren't permanently locked out if you forget your PIN and lose access to your passkey-registered devices at the same time.
  • Protect your phone number as a security asset. SIM-swap attacks that redirect a victim's mobile carrier account remain the underlying threat this update is meant to blunt, so check whether your carrier offers a port-out PIN or account lock.
  • Audit admin access on shared or business accounts and confirm passkeys are registered only on devices controlled by current, trusted staff.

This pattern, passkeys as a phishing-resistant complement to a PIN-based second factor, not a full replacement for it, mirrors the direction most major platforms have taken as the FIDO Alliance's passkey standard has gained broader adoption. Readers responsible for security at a practice or small business should treat this update as a prompt to review passkey and two-step verification coverage across all business messaging and email accounts, not just WhatsApp.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Phishing & email security

Recognize manipulation, protect email accounts, and give people a clear way to report suspicious messages.

Learn first. Decide when you are ready.

Keep learning—or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.