Connect with us

NEWS

WhatsApp Parks a Billion Passkeys in Apple and Google Vaults

WhatsApp’s billion passkeys live in Apple and Google vaults that cannot sync, which is why a real password is arriving too.

WhatsApp said Tuesday that more than a billion of its users have created a passkey, a login that uses a fingerprint, a face, or the phone’s screen lock instead of a typed code. The same update replaces the six-digit two-step PIN with a full password and lets one account hold more than one passkey.

Those extra keys exist because the first one never leaves the vault that made it.

A Billion Passkeys Now Live on Apple and Google

A WhatsApp passkey is not a secret the company stores for you in the way a password hash is stored. When you create one, the phone builds a key pair. WhatsApp keeps the public half. The private half stays in the device’s password manager, unlocked by the same fingerprint, face, or screen lock you already use to open the phone.

On iPhone that manager is iCloud Keychain. On most Android phones it is Google Password Manager, or Samsung’s manager on some Galaxy devices. WABetaInfo, walking through the setup, notes that WhatsApp saves the passkey in whatever default password manager the phone already uses. Your face never leaves the device. The login secret does leave it, encrypted, into Apple’s or Google’s sync fabric.

That is the quiet transfer inside the milestone. Meta can say more than a billion people have already set one up, which it did in Tuesday’s blog, and still not hold the private keys. Apple and Google do. If someone takes over the iCloud or Google account that syncs those vaults, the WhatsApp passkey travels with the rest of the saved logins.

THE SCALE BEHIND TUESDAY’S TALLY

  • WhatsApp users with a passkey: More than 1 billion, according to the company on August 25, 2026.
  • Global passkeys in use: The FIDO Alliance estimates 5 billion passkeys are now in use worldwide as of its May 7, 2026 report.
  • Consumer awareness: 90 percent of people in FIDO’s ten-country survey had heard of passkeys, and 75 percent had turned one on for at least one account.
  • Regular use: 49 percent said they use passkeys regularly when the option is there, so a created passkey is not the same as a habit.

FIDO’s 5 billion figure counts credentials, not unique people, and it mixes every bank, shop, and workplace login the alliance can see. WhatsApp’s number is a single app claiming a billion human accounts. No other consumer chat app has published a comparable tally. The FIDO Alliance’s Andrew Shikiar, its executive director and CEO, said passkeys are moving into the mainstream because they are both harder to phish and easier to use than passwords.

Why Android Passkeys Do Not Open an iPhone

Native passkeys do not sync between Apple and Android. A key born in iCloud Keychain stays in the Apple circle. A key born in Google Password Manager follows Chrome and Android, not Safari on an iPhone. Third-party managers such as 1Password or Bitwarden can bridge that gap if you put them in the middle. Most people never do.

That is why Tuesday’s “multiple passkeys” line is the load-bearing change, not a footnote. Until now, WhatsApp supported one passkey on the account. A person who used Android at home and iPhone at work, or who jumped ship during a phone sale, had a passkey on one side and a dead end on the other. Settings, Account, Passkeys is now the place to add a second one, including separate keys for Android and iOS.

Check What you prove Where the secret lives Works after an OS switch
Six-digit PIN (2017 model) A number you memorised Your memory, optional recovery email Yes
New two-step password A longer secret with letters and numbers Your memory, optional recovery email Yes
Passkey Fingerprint, face, or screen lock Apple or Google password manager No, unless you add a second passkey

The practical move is to enrol the second passkey while both phones still work. A lost handset is a bad moment to discover that the only private key sat in a vault you can no longer open. Some people who went looking for the new screens on Tuesday already found nothing, which matches WhatsApp’s own staged rollout more than a broken standard.

9to5Mac, citing the company, said passkeys arrived on Android in October 2023 and on iPhone the following April. The Hacker News, also citing Meta, said Facebook login gained passkeys in June 2025. WhatsApp got there first, at chat scale, and still had to invent a second slot because the platform vaults never agreed to share.

Six Digits Lasted From 2017 Until Tuesday

Two-step verification on WhatsApp was never an authenticator app. The Verge and Ars Technica reported the launch on February 10, 2017 as an optional six-digit PIN you typed when you registered the same number on a new phone. WhatsApp also asked for that PIN every so often so you would not forget it. An optional backup email could turn the PIN off if you lost it.

Six digits allow a million combinations. That is a real barrier only when guesses are slowed down. It is a weak barrier if the PIN is 123456, a birthday, or the same code used on a SIM card. Account takeovers on WhatsApp still start with the SMS registration code, which the Help Center still treats as the only way to activate a number. The PIN was the second gate after someone already held that SMS.

  1. February 10, 2017: WhatsApp rolls out optional two-step verification with a six-digit PIN and an optional recovery email, after a beta that began in late 2016.
  2. October 2023: Passkeys reach WhatsApp on Android, stored in the phone’s password manager.
  3. April 2024: Passkeys reach iPhone, stored in iCloud Keychain.
  4. October 30, 2025: Meta Newsroom says passkeys can also encrypt chat backups, so a fingerprint or screen lock can replace a 64-digit backup code.
  5. August 25, 2026: WhatsApp says more than a billion users have a passkey, adds a second passkey slot, and replaces the PIN with a password.

Ars Technica, quoting WhatsApp’s 2017 FAQ, said a number could be re-verified without the PIN after seven days, with pending messages deleted, and that after 30 days without the PIN the old account could be wiped and replaced. That lockout design punished people who forgot a six-digit code they were told to memorise. A longer password will be harder to guess and easier to forget, which is why the passkey, and a second passkey, have to carry recovery.

The New Password Needs Eight Characters

The Help Center now tells people they can upgrade the 6-digit PIN to a password if they already turned two-step verification on. Two-step verification remains optional. Registration still begins with a six-digit SMS or call code. The password is the extra gate after that code, the same job the PIN had, with a larger alphabet.

WABetaInfo, which watched the Android beta and then the public rollout, said the new password must be at least eight characters, with at least one letter and at least one number. Engadget reported the same floor. Special characters are allowed. WhatsApp’s own blog put the case in one line aimed at the laziest PINs.

Until now it was a six-digit PIN, we’ve now upgraded it to a full password: longer, alphanumeric, and even with special ch@racters to make it harder to guess. If you’ve been using ‘123456,’ this is your sign to upgrade.

WhatsApp, official blog, August 25, 2026

WHAT THE NEW PASSWORD ALLOWS

  • Length floor: At least eight characters, per WABetaInfo’s read of the live screens and Engadget’s report of the same rule.
  • Mix: At least one letter and at least one number; symbols such as @ and $ are allowed.
  • Where it sits: Settings, then Account, as a dedicated account password that replaces the old PIN after you enter the SMS code.
  • Who sees it: Android and iOS in a gradual rollout; WABetaInfo said people who already have a PIN may be asked to update it when the new screen appears.

The Help Center still warns people not to share the registration code or the password with anyone, and it still tells users of a recycled number that they may have to wait a few days if the previous owner left two-step verification on. The password does not retire SMS. It makes the second factor less of a joke, while the passkey tries to skip the typed secret on the next login.

Unknown Callers Get a Country and Shared Groups

The third change is smaller and Android-only for now. When a call arrives from a number that is not in your contacts, WhatsApp will show extra context: whether the number is from another country, and whether you share any groups with that caller. 9to5Mac ran the line from the company’s note: a little context can help you decide whether to pick up.

WhatsApp said scammers rely on urgency, and the extra facts are meant to give you a pause before you answer. A foreign number with zero groups in common is a useful warning. It is not a verdict. The screen does not say the call is safe if you share a group, and it does not block the call. iPhone users do not get the extra panel yet.

Account takeovers and voice scams are different problems. The passkey and the password try to stop someone who already stole an SMS code from finishing a hijack. The caller panel tries to stop you from handing money or a one-time code to a stranger who sounds official. Only one of those tools sits in the Apple or Google vault. The other is a label on a ringing screen.

Third-Party Chats Do Not Inherit the Passkey

Europe is the other stakeholder the announcement barely names. Under the Digital Markets Act, Meta has had to let rival messengers plug into WhatsApp. In a November 14, 2025 newsroom post, Meta said third-party chats rolling out across Europe would start with two apps, BirdyChat and Haiket, after small tests. Users opt in. They can send messages, images, voice notes, videos, and files. Groups wait until those partners are ready.

Meta said third-party apps must use the same level of end-to-end encryption as WhatsApp. That rule is about the contents of a thread. It is not about how the person on the other app proves they own their account. A passkey protects your WhatsApp login. It does not protect the account of whoever is writing to you from another service, and Meta’s own interoperability write-up does not explain how those guarantees line up at the login layer.

The European Commission, answering a parliamentary question in February 2026, said Meta is the only designated messaging gatekeeper so far, for WhatsApp and Messenger, and that BirdyChat and Haiket had managed to interoperate. Encryption, it said, should be preserved across the bridge. Login identity was not in that answer. A state-issued EU digital wallet is also moving in parallel, a second way of proving who you are that does not run through iCloud or Google Password Manager. Tuesday’s WhatsApp update does not connect those systems.

The Same Fingerprint Already Unlocks Chat Backups

Passkeys on WhatsApp already do more than reopen the app after a reinstall. WABetaInfo notes that a passkey can add a second layer to chat backups, so end-to-end encrypted backups can open with a fingerprint, a face, or a screen lock instead of a 64-digit code people write on paper and lose. Meta Newsroom described that backup path in October 2025 as a way to skip memorising another password.

That is the through-line. The billion passkeys are a Meta headline and an Apple-and-Google custody reality. The second passkey slot is a patch for vaults that refuse to talk. The new password is a patch for everyone whose next phone is not already inside the same vault. SMS still arrives. Two-step verification is still a choice. The new caller labels are still Android-only, and the new settings screens are still appearing in waves, which is why some people tapped through on Tuesday and saw the old PIN.

People who already chose a six-digit PIN can switch it once the password screen shows up under Settings and Account. People who use two operating systems can add the second passkey in the same Passkeys menu while both phones are still in their hands. After that, the private key that says you are you lives where it has lived since 2023, in a vault with someone else’s name on the door.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *