WhatsApp Starts Username Reservations, Finally Decoupling Identity From Phone Numbers
The optional handle system lets users be reachable without exposing an E.164 number, a meaningful identifier change for a 3-billion-user directory.

Key points
- WhatsApp began global username reservations on Monday, giving its three-billion-plus users a handle that can replace a phone number for contact sharing.
- The feature is opt-in; connecting with someone by username rather than by digits comes in a later update.
- Phone numbers remain the underlying account identifier and still gate account creation via SIM-bound registration.
- Usernames reduce discoverability risk but do not remove SIM-swap exposure if the phone number stays the recovery factor.
- Meta has not published a technical writeup on reservation flow, claim disputes or the lookup protocol.
What actually changed here
This is an identity shift, not an authentication change. The phone number isn't going away as the account identifier, and SIM-bound registration still gates account creation. What's moving is the discoverability layer: the string other people use to find you.
E.164 numbers are poor identifiers. They're recyclable, regionally portable, often tied to government ID, and the namespace is predictable enough to enumerate systematically. Usernames don't fix that on their own, but they let a user share a contact handle on a business card or in a QR exchange without leaking a number that doubles as an SMS two-factor authentication target and a SIM-swap lure. We've covered SIM-swap risk in three stories since June, including the identity-path blind spots our pentest piece flagged on 10 June.
Should you worry about squatting and impersonation
Reservations opening now, ahead of full launch, suggests Meta has taken a lesson from platform land-rushes where launch-day collisions produce impersonation disputes before any moderation tooling is ready. Expect those disputes anyway. Namespace squatting is the most immediate and most tractable risk.
The harder questions are structural. When someone types a username, does the lookup happen client-side against a hashed directory, or server-side with Meta logging the query graph? The privacy gap between those two designs is large. WhatsApp Business also uses verified display names, and how usernames interact with that namespace and with deep links will determine whether phishing surfaces grow or shrink. Meta has published nothing on any of this yet.
What to do before you claim a handle
Account recovery deserves attention. If a username becomes the public identifier but the phone number stays the recovery factor, SIM-swap risk on WhatsApp accounts doesn't fall. It just acquires a cleaner face.
WhatsApp's two-step verification adds a user-set PIN that blocks re-registration of a number on a new device. That's the single most useful control against SIM-swap takeovers, and it was true before usernames existed. Enable it before claiming a handle.
The slow retreat of the phone number as a universal identifier isn't finished this week. But Monday's announcement moved the line.
Until Meta publishes the plumbing, treat this as an identifier change with real privacy upside and a technical design that's still a black box.



