Particle.news

WhatsApp Tests Password 2FA, Multiple Access Keys and On‑Device Scam Alerts

The changes aim to curb fraud by adding password-based login, multiple biometric keys and local scam warnings that keep message content off Meta servers.

Overview

  • In late August 2026 WhatsApp started testing three security changes with Android beta users: replacing the six-digit two-step PIN with a full account password, permitting multiple access keys, and surfacing context for calls from unknown numbers.
  • A separately rolled out optional feature called Scam Alert uses a local machine-learning model to flag suspicious messages from unknown senders and prompts users to block, report, or mark the sender as trusted without sending message content to Meta.
  • Multiple access keys let users register more than one biometric or device-unlock method and can be used to add end-to-end protection to chat backups so users need not rely only on a single numeric PIN.
  • WhatsApp will show contextual signals for calls from unknown numbers such as the caller’s registered country and number of shared groups to help users decide whether to answer those calls.
  • Meta has not given a general release date and the company is rolling features out gradually, so users should keep checking linked-device lists, keep two-step verification and biometrics enabled, and treat these beta tools as evolving protections.