WhatsApp is reportedly developing a major security upgrade aimed at protecting users against account hijackings and SIM-swapping attacks. According to early details spotted in Android beta builds, the messaging platform is preparing to swap its long-standing six-digit numeric Two-Step Verification (2FA) PIN for a stronger alphanumeric password option.
What’s Changing in Account Security?
-
Letters + Numbers: Rather than relying solely on a simple numeric code, users will be required to mix letters and numbers, drastically increasing complexity and resistance against brute-force guessing attempts.
-
Strength Verification: Beta strings indicate WhatsApp will automatically evaluate password strength before letting you save it.
-
Double-Layer Defense: The new password will act as a second barrier alongside standard phone verification. Even if an attacker intercepts or steals your SMS verification code (e.g., via SIM swapping), they won’t be able to log into your account without entering this custom password.
Current Status: The feature is still in early active development and has not yet rolled out to public beta testers or standard users.
Why the Shift Matters
Numeric 6-digit PINs offer 1,000,000 possible combinations, making them relatively basic compared to traditional account passwords. Transitioning to complex alphanumeric passphrases aligns WhatsApp with broader industry security standards, complementing existing account defenses like Device Verification and passkey support.

