Listen to this Post
A New Security Push for Billions of WhatsApp Users
WhatsApp is making a significant push to strengthen account security across iOS and Android, introducing several features designed to make unauthorized access, impersonation and scams harder to succeed. The latest changes include a password-based option for two-step verification, support for multiple passkeys, and additional information about unknown callers on Android.
These improvements arrive at a time when messaging apps have become much more than simple communication tools. WhatsApp is increasingly used for business, payments, communities, channels and personal conversations, making an account compromise potentially far more damaging than simply losing access to a chat history.
The company is therefore moving toward a broader security model that combines traditional credentials with modern authentication technologies, device-based intelligence and additional context for suspicious interactions.
WhatsApp’s Security Strategy Is Becoming More Sophisticated
The most important development is the upgrade to two-step verification. WhatsApp is allowing some users to protect their accounts with a password instead of relying solely on the traditional six-digit PIN.
The new password must contain at least eight characters, including at least one letter and one number. This creates a considerably larger credential space than a short numerical PIN and makes simple guessing attacks much less practical.
At the same time, WhatsApp is expanding passkey support. Users can now set up more than one passkey for their account, providing additional ways to authenticate without repeatedly entering traditional passwords or verification codes.
Android users are also receiving more information when calls arrive from unknown numbers. WhatsApp can provide context such as whether the number originates from another country and how many groups the caller shares with the recipient.
That seemingly small addition could become an important anti-scam tool. Context can make the difference between answering an apparently legitimate call and recognizing that an unexpected contact has little connection to your existing WhatsApp network.
Passwords Give Two-Step Verification a Stronger Foundation
Two-step verification has long been one of
A numerical PIN is convenient, but convenience also limits its complexity. A password containing letters and numbers can be considerably harder to guess, particularly when users choose a unique credential rather than reusing a familiar password.
The feature is being introduced gradually, so not everyone will immediately see the option in WhatsApp’s settings.
Users who do not have access to it yet should not assume that anything is wrong with their account or installation. WhatsApp frequently rolls out features progressively, meaning availability can depend on account, platform, region and rollout stage.
Multiple Passkeys Could Make Account Recovery More Flexible
Passkeys are another major part of
Unlike traditional passwords, passkeys rely on cryptographic credentials stored by a compatible password manager or device authentication system. Depending on the platform, users can authenticate using mechanisms such as a fingerprint, face recognition or device PIN.
Allowing multiple passkeys is particularly interesting because people increasingly use several devices.
A user may have a primary smartphone, a secondary device or another compatible authentication environment. Supporting multiple credentials can make account access more flexible while maintaining strong cryptographic protection.
It also reduces dependence on SMS-based authentication, which has historically been exposed to risks such as SIM swapping and social engineering.
Unknown Calls Now Come With More Context
WhatsApp is also attempting to make suspicious calls easier to identify.
On Android, users can receive additional information about unknown callers, including whether the number is associated with another country and how many groups the caller has in common with them.
This does not automatically determine whether a caller is malicious. Instead, it provides clues that allow users to make a better decision.
For example, an unexpected international number calling someone who has no contacts or groups connected to that country may deserve more caution.
The same principle applies to shared groups. If WhatsApp shows that the caller has no meaningful connection to the recipient’s existing communities, users may be less likely to trust the call immediately.
Scam Alert Brings On-Device Machine Learning
WhatsApp is also testing a Scam Alert feature with a limited number of Android beta users.
The system is designed to identify potentially fraudulent messages from unknown contacts by analyzing suspicious patterns using an on-device machine-learning model.
One of the most important aspects of this approach is that the analysis is designed to take place on the device rather than requiring the incoming message to be sent to WhatsApp or Meta for analysis.
That approach could provide a useful balance between security and privacy.
When the system identifies a potentially suspicious conversation, WhatsApp can display a warning and provide actions such as blocking or reporting the sender.
Users can also mark a conversation as trusted.
The feature is optional and disabled by default, giving users control over whether they want to use this additional layer of automated protection.
Why On-Device Detection Matters
The move toward on-device scam detection is particularly interesting from a privacy perspective.
Machine learning can be powerful at identifying patterns associated with fraudulent messages, but users understandably do not want every private conversation uploaded to a remote server for inspection.
On-device processing offers a different model.
The device can inspect relevant content locally and make a security decision without necessarily transferring the analyzed message to the service provider.
That does not make the system perfect, however. Scam messages constantly evolve, and attackers can deliberately change wording, links and conversation patterns to avoid detection.
The real test will therefore be how accurately Scam Alert can distinguish legitimate conversations from genuine fraud without producing excessive false warnings.
WhatsApp Is Also Preparing for Payments Expansion
Security is becoming even more important as WhatsApp expands beyond messaging.
According to the reported development in WhatsApp beta for iOS 26.33.10.70, the company is working on a new section for managing payment cards and billing information.
The planned functionality includes an option for paying contacts directly within WhatsApp.
The broader billing section is expected to support information such as credit and debit cards, shipping details and billing addresses.
Interestingly, the country selector reportedly includes a broader range of countries than WhatsApp’s existing payment markets.
That does not necessarily mean payments are immediately launching everywhere listed in the interface. Beta software frequently contains preparations for future expansion before a feature becomes publicly available.
Nevertheless, the direction is clear: WhatsApp is continuing to evolve into a platform where communication, commerce and payments can coexist.
Security Becomes More Important as WhatsApp Adds Payments
The connection between security and payments should not be underestimated.
A compromised messaging account can already expose private conversations, contacts, photos and business information. Once financial functionality becomes part of the same ecosystem, the consequences of account theft can become even more serious.
This makes stronger authentication particularly important.
Passwords, passkeys, scam detection and contextual information about unknown callers are therefore not isolated features. Together, they form part of a larger security architecture designed for a platform that is becoming increasingly central to users’ digital lives.
Channel Administrators Get New Profiles
WhatsApp is also introducing administrator profiles for channels.
The feature allows channel administrators to create a separate identity that can include a name and profile picture.
This can help followers understand which administrator published a particular update.
It may also be useful for channels with multiple administrators, where identifying who posted specific content can improve transparency and accountability.
Administrators can reportedly modify or remove their channel profile through the channel information screen.
Chat Themes Are Getting More Personal on iOS
Security is the headline story, but WhatsApp is simultaneously working on several customization improvements.
iOS users are receiving five new chat-theme categories: Featured, Nature, Live, Minimal and Doodle.
Featured focuses on
Live introduces animated wallpapers that move subtly in the background.
Minimal takes a simpler approach with plain backgrounds, while Doodle brings back familiar WhatsApp-style patterns.
WhatsApp also automatically chooses suitable bubble colors to maintain contrast and preserve readability.
It is a small design detail, but one that matters. A visually attractive theme is not particularly useful if the text becomes difficult to read.
A Smarter “To You” Chat List Is Also in Development
Another potentially useful productivity feature is a new chat filter reportedly called “To You.”
The concept is straightforward: WhatsApp would create a dedicated view for conversations in which someone mentioned the user or replied directly to one of their messages.
In busy group chats, important messages can easily disappear beneath hundreds of unrelated conversations.
A smart filter could make it significantly easier to find messages that actually require attention.
The filter is expected to remain optional, allowing users to keep it in the primary chat list or move it to a separate section.
WhatsApp’s Weekly Beta Cycle Shows a Bigger Direction
Taken together, these developments reveal something larger about WhatsApp’s development strategy.
The company is not simply adding isolated features. It is gradually transforming WhatsApp into a broader communication platform with stronger authentication, automated security, payments, channels, personalization and intelligent organization.
Some features may remain limited to beta testers for an extended period.
Others may be released gradually to the public.
And some experimental features may ultimately change substantially or never receive a full rollout.
That is why beta availability should not automatically be interpreted as confirmation of an immediate public launch.
What Users Should Do Now
Users should start by checking whether two-step verification is enabled on their WhatsApp account.
If the new password-based option is available, creating a strong and unique credential is preferable to choosing something predictable.
Users should also enable passkeys when supported by their devices and authentication ecosystem.
Unknown callers should be treated cautiously, particularly when there is no obvious connection between the caller and the recipient.
Messages requesting money, passwords, verification codes, cryptocurrency transfers, remote access or urgent action deserve additional scrutiny.
No security feature can completely eliminate social engineering.
The safest defense remains a combination of strong authentication, careful judgment and skepticism toward unexpected requests.
Deep Analysis
WhatsApp’s latest security changes represent a move away from relying on a single authentication mechanism.
Traditional SMS verification remains useful, but it is not sufficient as the sole defense against modern account-takeover techniques.
Two-step verification adds another barrier.
Password-based verification increases the complexity of that second layer.
Passkeys introduce modern public-key cryptography into the authentication process.
Multiple passkeys make the system more practical across different authentication environments.
Unknown-caller intelligence adds contextual security before a user interacts with a potentially suspicious contact.
On-device Scam Alert adds another defensive layer directly inside conversations.
These mechanisms work best when they are combined rather than treated as independent features.
For technically minded users, the broader principle can be represented conceptually through a simple local security audit.
Check whether a local password manager is configured pass --version
Generate a strong random credential with OpenSSL
openssl rand -base64 24
Generate a cryptographically strong hexadecimal value
openssl rand -hex 32
These commands are not WhatsApp commands and should not be entered into WhatsApp. They simply demonstrate the security principle behind strong, unpredictable credentials.
A practical security checklist can also be represented as:
WhatsApp Security Baseline
[+] Two-step verification enabled
[+] Strong unique password/PIN configured
[+] Passkey configured where supported
[+] Recovery information protected
[+] Unknown callers treated cautiously
[+] Suspicious messages reported
[+] Unexpected payment requests verified independently
[+] WhatsApp kept updated
The most important lesson is that authentication should be layered.
If one defensive mechanism fails, another should still stand between the attacker and the account.
Why Passkeys Could Become the Bigger Story
The password update is immediately understandable, but passkeys may ultimately have a larger impact.
Passwords are vulnerable because people choose them, reuse them and sometimes expose them through phishing.
Passkeys fundamentally change the authentication model.
Instead of asking users to remember a secret that can be typed into a fraudulent website, passkey systems use cryptographic credentials associated with the user’s device or password manager.
That makes conventional phishing substantially more difficult.
For a service with billions of users, moving millions of people toward phishing-resistant authentication could have a meaningful impact on the wider threat landscape.
Scammers Are Adapting Too
There is an important limitation to
Scammers increasingly use convincing social-engineering techniques rather than obvious spam.
A fraudulent message can be written naturally, imitate a family member or colleague, and create artificial urgency.
AI can make this problem worse by helping attackers produce better-written messages at scale.
This makes contextual security particularly valuable.
The future of messaging security will probably depend less on simply blocking known malicious messages and more on identifying suspicious behavioral patterns.
Privacy Will Remain a Critical Test
WhatsApp’s use of on-device machine learning for Scam Alert is significant because privacy expectations around private messaging remain high.
Users want stronger protection, but they also want confidence that security systems are not turning private conversations into a massive centralized dataset.
Local processing can reduce some of those concerns.
However, transparency will remain important.
Users will want to understand what is analyzed, when it is analyzed, how warnings are generated and what information leaves the device.
The success of these systems will therefore depend not only on detection accuracy but also on user trust.
Payments Could Raise the Stakes
The reported payment-management developments make these security improvements even more relevant.
If WhatsApp becomes a place where users store payment credentials and conduct transactions, account security becomes financially consequential.
A stolen account could potentially become more valuable to criminals.
This is one reason stronger authentication should arrive alongside financial expansion rather than after it.
The safest ecosystem is one where security is designed into the platform before users depend on it for sensitive transactions.
WhatsApp Is Becoming More Than a Messenger
The latest feature cycle demonstrates how dramatically messaging applications have evolved.
WhatsApp now sits at the intersection of communication, business, communities, channels, payments and increasingly sophisticated artificial intelligence.
That evolution creates convenience, but it also increases the platform’s attractiveness to criminals.
Every new capability creates another potential target.
Consequently, WhatsApp’s investment in account protection is not simply a response to today’s scams.
It is preparation for a future in which a WhatsApp identity could represent much more of a user’s digital life.
What Undercode Say:
WhatsApp’s newest security features arrive at exactly the right time.
Messaging accounts have become valuable targets for cybercriminals.
A stolen WhatsApp account can expose private conversations and trusted relationships.
It can also give attackers a powerful platform for impersonation.
The password upgrade is therefore more than a cosmetic change.
It increases the complexity of the second authentication layer.
That makes automated guessing attacks harder.
Passkeys are potentially even more important.
They move authentication toward stronger cryptographic protection.
Multiple passkeys also make modern authentication more practical.
Users should not have to choose between security and convenience.
The ability to maintain multiple authentication credentials can improve both.
The unknown-caller information is another smart idea.
People often make security decisions based on context.
Knowing that an unfamiliar caller is from another country can immediately change how a user evaluates the call.
Shared-group information provides another useful signal.
It does not prove that a caller is trustworthy.
It simply gives users additional evidence before they engage.
That distinction is important.
Security systems should assist human judgment rather than pretend they can replace it.
Scam Alert could become one of
On-device analysis is particularly notable.
It potentially allows WhatsApp to improve scam detection without requiring every analyzed message to be processed remotely.
However, detection accuracy will determine whether users embrace the feature.
Too many false positives could cause users to ignore warnings.
Too few detections would limit its value.
WhatsApp therefore has to find a difficult balance.
The
Financial functionality increases the consequences of account compromise.
Strong authentication should therefore become a default expectation.
The
Administrators now have more ways to establish identities.
That can improve transparency.
But impersonation remains a risk.
Users must still verify who they are dealing with.
The same principle applies to
Automation can improve security.
Automation can also introduce new attack surfaces.
The company needs to make security part of every layer of its platform.
That includes accounts.
It includes devices.
It includes messages.
It includes channels.
It includes payments.
It includes AI-powered functionality.
The security model must evolve alongside the product.
WhatsApp’s biggest challenge will not be adding security features.
It will be making those features simple enough for ordinary users to actually use.
A complicated security system is often abandoned.
A seamless security system can protect millions of people without requiring them to understand the technology underneath.
That is where passkeys have enormous potential.
They can make sophisticated cryptographic authentication feel almost effortless.
Meanwhile, contextual warnings can help people recognize suspicious interactions before damage occurs.
The combination is much stronger than either technology alone.
WhatsApp is clearly moving toward layered security.
That is the correct direction.
But users should not interpret these improvements as a reason to become careless.
No automated detection system catches every scam.
No authentication method eliminates every form of social engineering.
And no messaging platform can prevent a user from voluntarily handing sensitive information to a criminal.
The strongest defense remains layered technology combined with informed users.
For WhatsApp, the next phase will be about turning these individual features into one coherent security ecosystem.
If the company succeeds, account takeovers could become substantially harder.
If it fails, scammers will simply adapt around the new defenses.
The security race is therefore far from over.
WhatsApp has made an important move.
Now the real test is how effectively these protections perform in the hands of hundreds of millions of everyday users.
✅ Password-Based Two-Step Verification
WhatsApp has announced a password option for two-step verification requiring at least eight characters, including a letter and a number. The rollout is gradual, so availability can vary between users and platforms.
✅ Multiple Passkeys
The article correctly identifies support for more than one passkey as part of WhatsApp’s security direction. Passkeys provide a modern authentication method that can reduce reliance on traditional passwords and SMS-based verification.
✅ Unknown Caller Context
The reported Android feature provides additional context about unknown callers, including country-related information and shared groups. This is intended to help users make better-informed decisions rather than automatically label every unknown caller as malicious.
✅ On-Device Scam Detection
The reported Scam Alert test uses an on-device machine-learning approach to identify potential scam patterns. The feature is optional and is being tested with a limited group of Android beta users.
⚠️ Payments Expansion
The payment-card and billing developments are reported as beta work rather than confirmation of an immediate worldwide payments launch. Users should therefore distinguish between WhatsApp testing payment infrastructure and actual availability in their country.
Prediction
(+1) WhatsApp is likely to continue expanding passkeys and stronger authentication as the platform becomes more deeply integrated with payments, business communication and channels.
(+1) On-device scam detection could eventually become one of WhatsApp’s most important security features if the company can maintain high detection accuracy without generating excessive false positives.
(+1) Multiple passkeys are likely to become increasingly useful as people use WhatsApp across multiple devices and authentication ecosystems.
(+1) Contextual warnings for unknown contacts may expand beyond calls and eventually cover suspicious links, payment requests and unusual account behavior.
(+1) As AI-generated scams become more convincing, WhatsApp will probably invest more heavily in automated detection and behavioral analysis.
(-1) Criminals are likely to adapt their social-engineering techniques to bypass automated scam detection.
(-1) Excessive security warnings could create alert fatigue and cause users to ignore legitimate warnings.
(+1) The long-term direction is likely to be a WhatsApp ecosystem where authentication, scam prevention, privacy controls and payment security work together rather than functioning as isolated features.
▶️ Related Video (82% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: wabetainfo.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




