Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2513+ Articles
161+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins
NEWS

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins

Meta announces WhatsApp support for multiple passkeys per account on iOS and Android, ending password reliance with phishing-resistant biometric auth.

Dylan H.

News Desk

August 25, 2026
3 min read

WhatsApp Embraces Multi-Passkey Authentication

Meta has announced a significant upgrade to WhatsApp's account security model: users can now register multiple passkeys to a single account, enabling seamless phishing-resistant sign-in across both iOS and Android devices. The move expands on WhatsApp's earlier passkey rollout and positions the platform among the most security-forward consumer messaging apps available.


What's New

The updated feature set introduces several key capabilities:

  • Multiple passkeys per account: Users with both an iPhone and an Android phone can now register a passkey on each device, eliminating the need to choose a primary device or fall back to SMS verification when switching platforms
  • Cross-platform coverage: Support spans iOS (using Face ID / Touch ID with iCloud Keychain) and Android (using biometrics with Google Password Manager or third-party passkey managers)
  • Phishing-resistant by design: Passkeys use the FIDO2/WebAuthn standard, meaning credentials are cryptographically bound to the legitimate WhatsApp domain — a phishing site cannot intercept or replay them
  • No shared secrets: Unlike passwords or SMS OTPs, passkeys never leave the user's device in a form that could be stolen from a server

Why This Matters

More than 1 billion people use passkeys globally, according to Meta, and WhatsApp sits at the center of some of the most sensitive conversations in users' lives — from personal communications to business dealings and financial coordination.

The previous single-passkey limitation created friction for users who regularly switch between iOS and Android devices (common in markets where users carry dual SIMs or upgrade between ecosystems). Multi-passkey support removes that barrier and makes passkeys practical for the full WhatsApp user base.


Passkeys vs. Traditional Authentication

MethodPhishing ResistantServer Breach RiskUser Friction
PasswordNoHighMedium
SMS OTPNoMedium (SIM swap)Medium
TOTP (authenticator app)PartialLowMedium
PasskeyYesNoneLow

Passkeys represent the strongest widely-deployable authentication mechanism for consumer apps, combining strong cryptographic security with a familiar biometric UX.


The Broader Passkey Wave

WhatsApp's expansion joins a growing roster of major platforms that have adopted passkeys as a primary authentication method:

  • Apple — passkeys integrated across iCloud Keychain and supported in Safari
  • Google — passkeys available for Google accounts on Android and Chrome
  • Microsoft — passkey support across Microsoft 365 and consumer accounts
  • GitHub, Shopify, PayPal, Amazon — all have deployed passkey sign-in for users

The FIDO Alliance estimates that passkey-capable accounts have surpassed 13 billion globally, marking a genuine inflection point in the shift away from passwords.


How to Enable Passkeys on WhatsApp

  1. Open WhatsApp and go to Settings
  2. Tap Account → Passkeys
  3. Select Create Passkey and authenticate with your device biometrics
  4. Repeat on any additional device to register multiple passkeys

For users who have already registered a passkey on one platform, the new multi-passkey flow allows adding a second without removing the first.


Security Recommendations

  • Enable passkeys on WhatsApp as soon as the update is available in your region
  • Register a passkey on each device you regularly use to avoid SMS OTP fallbacks
  • Use a reputable passkey manager (iCloud Keychain, Google Password Manager, or a third-party like 1Password / Bitwarden) for backup and cross-device sync
  • Disable SMS OTP fallback where possible to close the weakest link in your authentication chain

Sources

  • The Hacker News — WhatsApp passkey announcement
#Passkeys#WhatsApp#Authentication#Phishing Resistance#iOS#Android#Meta#MFA

Related Articles

Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

Huntress reports a 155x surge in password spraying in H1 2026, with one campaign logging 81 million login attempts in two weeks via MFA and legacy auth gaps.

5 min read

WhatsApp Is Finally Getting Usernames to Help Keep Phone Numbers Private

WhatsApp has begun global rollout of optional usernames, allowing over 3 billion users to connect without sharing their phone numbers — closing a major...

3 min read

ZeroDayRAT Mobile Spyware Enables Total Surveillance of iOS

A new mobile spyware platform called ZeroDayRAT supports Android 5-16 and iOS up to version 26, providing real-time camera streaming, keylogging, 2FA...

2 min read
Back to all News