Cybersecurity giants WhatsApp have rolled out a significant update to its mobile app, introducing multiple passkeys for phishing-resistant sign-ins on both iOS and Android devices. This move comes as part of an ongoing effort to protect users from increasingly sophisticated cyber threats.
The new feature allows users to generate and store multiple passkeys – essentially unique login credentials that can be used instead of passwords – which can be used in conjunction with the app’s existing security features, such as end-to-end encryption and two-factor authentication. This approach is designed to make it even more difficult for hackers to gain access to user accounts through phishing attacks or other forms of social engineering.
WhatsApp users will now have the option to generate a new passkey whenever they log in to their account, which can be stored securely within the app’s built-in keychain. When logging in, users can choose to use one of these generated passkeys instead of entering their actual password – providing an additional layer of security against password-based attacks.
What makes this feature particularly interesting is its reliance on a concept known as “passkey authentication”. This involves using public-key cryptography to securely generate and store unique login credentials, which are then used in place of traditional passwords. When implemented correctly, passkey authentication offers several key benefits over traditional password-based systems – including the ability to rotate or revoke compromised keys, reducing the risk of an attacker gaining persistent access to a user’s account.
The introduction of multiple passkeys is likely to be particularly welcomed by WhatsApp users who frequently switch between devices or share their accounts with others. By providing users with more control over their login credentials, this feature should help mitigate some of the risks associated with password reuse and sharing.
As the cybersecurity landscape continues to evolve, it’s clear that messaging apps like WhatsApp are working hard to stay ahead of emerging threats. The addition of multiple passkeys is a significant step forward in protecting user accounts from phishing attacks and other forms of cybercrime.
For users, this update should serve as a reminder that even seemingly secure platforms can benefit from additional layers of security. While WhatsApp’s existing security features have undoubtedly helped protect against various types of attack, the introduction of multiple passkeys offers another valuable tool for those seeking to stay one step ahead of potential threats.
Source: The Hacker News — 2026-08-25