WhatsApp Adds Multiple Passkey Support to Combat Account Hijacking
The messaging platform is moving beyond simple PINs to shield users from SIM-swapping and unauthorized access.
WhatsApp has launched a series of security updates designed to shield user accounts from unauthorized access. The rollout introduces support for multiple passkeys and a revamped two-step verification process, marking a significant shift in how the platform handles identity authentication.
According to BleepingComputer, WhatsApp now allows users to utilize multiple passkeys for account authentication. This enables the use of biometric data or hardware security keys across various devices to verify ownership. In tandem with passkey support, the platform has upgraded its two-step verification (2SV) system. While the service previously relied on six-digit PINs, the updated system now supports alphanumeric passwords, providing a more complex and robust layer of security for account recovery and protection.
The Shift to Passwordless Security
These updates align with a broader industry transition toward passwordless authentication, a movement championed by the W3C and the FIDO Alliance. Passkeys replace traditional passwords with cryptographic key pairs, which are stored locally on a user's device. This architecture fundamentally changes the authentication handshake, removing the need for a shared secret—like a password—to be stored on a central server where it could be leaked or stolen.
Combating Sophisticated Attacks
This transition is a direct response to the increasing sophistication of account hijacking and SIM-swapping attacks. For years, many services relied on SMS-based verification, which attackers can bypass by tricking mobile carriers into porting a target's phone number to a new SIM card. By integrating multi-device biometric authentication and alphanumeric passwords, WhatsApp significantly raises the barrier for attackers, as gaining access now requires physical possession of a registered device or a complex password rather than just an intercepted text message.
Future Outlook
As more users migrate to passkeys, the reliance on legacy authentication methods is expected to dwindle. While the current rollout focuses on enhancing the existing 2SV and passkey infrastructure, the industry continues to monitor how these tools perform against evolving social engineering tactics. Users are encouraged to update their security settings to take advantage of these alphanumeric and biometric options to ensure their private communications remain secure.