Passkeys were designed to improve account security. By replacing passwords with public-key cryptography, binding credentials to legitimate websites and applications, and keeping private keys off authentication servers, passkeys make many traditional phishing and credential-theft attacks significantly more difficult.
That security benefit remains real. However, the passkey security discussion has evolved quickly.
At least 39 publicly documented passkey attack methods, attack vectors, research techniques and exploitation scenarios now target passkeys or the infrastructure surrounding them. Security researchers and technology companies have published proof-of-concept tools demonstrating how these techniques work, and some approaches are beginning to appear in real-world attack activity.
This does not mean attackers are actively using all 39 methods. It means detailed playbooks are publicly available, reducing the need for attackers to develop these techniques from scratch.
More importantly, this research highlights a fundamental distinction in the passkey threat model: FIDO2 encryption can remain fully intact while an account protected by a passkey is still compromised.
Passkey attacks target more than cryptography
Modern passkey authentication crosses multiple trust boundaries. These include web applications, browsers, operating systems, password managers, cloud synchronization services, mobile devices, Bluetooth connections, account recovery systems, registration workflows, help desks and the employees who approve authentication requests.
Researchers are testing nearly every layer of this ecosystem. Publicly documented techniques include assertion mining, assertion replay, circuit breaker attacks, assertion phishing, browser hooking, assertion capture, challenge injection, bypass replay, user verification attacks and user presence attacks.
SpecterOps demonstrated the importance of this issue in its Pass the Passkey study. One of the study’s key findings was that malware may not need to extract a user’s private key.
A malicious Windows application could instead ask legitimate WebAuthn infrastructure to generate a signed assertion. If the user approves what appears to be a normal Windows authentication request, the attacker may receive the resulting assertion.
The private key never leaves its secure location. The cryptographic protocol is not broken. Nevertheless, the authentication process has completed successfully for the attacker.
This distinction is essential for understanding modern passkey security risks.
Passkeys are not completely secure unless they are paired with specialized biometric hardware.
Learn how attackers can target passkey enrollment instead of breaking passkey encryption, and why specialized biometric hardware can strengthen enterprise identity assurance.
The passkey authentication prompt can also be attacked
Several of the 39 documented techniques target the user interface surrounding passkey authentication rather than the cryptography itself.
Researchers have demonstrated passkey prompt flooding, deceptive credential interfaces, application metadata spoofing, window handle spoofing, remote desktop passkey phishing and FIDO interface overlay attacks.
These techniques resemble problems previously seen with push-based multifactor authentication. As users become accustomed to approving authentication prompts, attackers may attempt to fabricate, repeat, disguise or strategically time those prompts.
SpecterOps demonstrated a tool capable of repeatedly displaying a legitimate-looking Windows passkey prompt. Researchers also showed how malicious authentication activity could be made to appear as though it originated from trusted applications.
The lesson is clear: phishing resistance at the cryptographic protocol layer does not automatically provide protection against deception at the operating system, browser, application or user-interface layers.
Synced and shareable passkeys increase the attack surface
When passkeys can be shared, synchronized, exported, restored or transferred between devices, the overall attack surface becomes significantly larger.
Published research has described attacks involving synchronization vaults, Apple and Google account takeovers, cloud recovery, stolen or compromised mobile phones, mobile malware, rooted devices, hybrid authentication workflows, KeePassXC exports, Bitwarden exports, credential exchange systems, malicious browser extensions, CTAP and Bluetooth communications.
This is not necessarily a failure of encryption. It is an architectural challenge.
When credentials can move between devices, synchronize through a cloud account, be exported from a password vault or be restored through an alternative identity, the security boundary extends beyond the original authentication system.
Attackers may not need to break FIDO2. They may only need to compromise one trusted component within the broader passkey ecosystem.
As a result, synced passkeys can use strong encryption while still inheriting weaknesses from the phone, operating system, password manager, cloud account, browser, recovery process or synchronization service that manages them.
Passkey enrollment and account recovery create new risks
Some of the most serious passkey attacks do not involve stealing an existing credential. Instead, attackers create a new credential that is valid for the targeted account.
Publicly documented techniques include shadow passkeys, registration vishing, attacker-controlled phone registration, unauthorized passkey enrollment, help desk compromise, temporary credential abuse, SIM-based recovery, reverse vishing and migration pretexting.
For example, if an attacker gains enough control over an employee account to start a legitimate passkey enrollment process, the attacker may register a new passkey on a device they control. The employee’s existing credential does not need to be extracted.
Nothing is cracked, and no existing passkey necessarily needs to be stolen. The legitimate service creates a new credential that is valid for the attacker.
This reinforces an important identity security principle: phishing-resistant authentication is not enough if enrollment, credential exchange, account recovery and device registration are not protected to the same standard.
How dedicated biometric hardware changes passkey security
Dedicated biometric hardware approaches passkey security differently from credentials stored on general-purpose devices.
Purpose-built biometric authenticators can keep private credentials inside secure hardware without relying on cloud synchronization, credential exports or password managers to move passkeys between devices.
Authentication may require a live fingerprint on the authenticator, along with physical proximity to the endpoint requesting access.
A specialized authentication device also does not need to include a traditional operating system, application store, web browser or display.
Reducing these components can eliminate significant portions of the attack surface.
There is no third-party application that an attacker can replace with a malicious version. A rogue application cannot simply be installed on the authenticator. There is no browser extension ecosystem to compromise and no screen on which malware can display a fraudulent authentication prompt.
There is also no consumer operating system filled with unrelated applications, excessive privileges, background services and third-party update dependencies.
The authenticator performs a limited number of security-specific functions—and nothing else.
This changes the economics of an attack. Instead of compromising a large, general-purpose computing environment, an attacker must target tightly controlled hardware designed to protect cryptographic credentials and verify biometric identity.
Dedicated biometric hardware can also reduce the impact of employee manipulation. An employee may be persuaded to visit a malicious website, answer a fraudulent support call or follow instructions from an impersonated administrator. However, social engineering cannot install unauthorized applications on hardware that does not support normal applications.
An attacker cannot control a display that does not exist or synchronize credentials through cloud services that the authenticator does not use.
For these reasons, well-designed biometric hardware can provide additional resistance against both external attackers and employee mistakes.
Secure passkey configuration remains essential
Dedicated hardware alone is not enough. The services that rely on it must also be configured to preserve the intended security model.
In sensitive enterprise environments, authentication and registration should be limited to approved authenticator classes. Relying parties should verify authenticator identity, enforce user verification, validate challenges and sessions correctly, apply appropriate signature-counter protections and prevent weak methods from becoming fallback authentication paths.
Registration and recovery require particular attention. Adding a new authenticator should require proof of account control through an existing approved authenticator—not merely through a weak recovery channel.
When these controls are properly configured, an attacker cannot simply register an ordinary passkey from another laptop, phone, software vault or security key. Cloud account takeover does not automatically provide the required credentials, and compromising a password manager does not necessarily satisfy the authentication policy.
Mobile malware and malicious applications also cannot complete authentication when the process requires specialized hardware, biometric verification, physical proximity and legitimate service interactions.
What 39 documented passkey attacks reveal
The existence of 39 publicly documented attack techniques does not mean FIDO2 encryption has failed. In many ways, it demonstrates the opposite.
Well-designed cryptographic hardware is difficult to break directly. As a result, researchers and attackers increasingly focus on the software, synchronization services, registration processes, operating systems, browsers, recovery workflows and people surrounding the credentials.
These findings show security leaders where they need to establish stronger identity boundaries.
For high-value enterprise accounts, credentials should not be freely shared across consumer devices or cloud ecosystems. These users should be connected to specialized biometric hardware, verified individuals, approved services and company-managed enrollment and recovery procedures.
Passkeys address many of the security weaknesses associated with passwords. The 39 published passkey attack methods reveal what attackers are targeting next: the infrastructure and processes surrounding authentication.
When purpose-built biometric hardware is properly implemented across registration, authentication and recovery, organizations can reduce many of the surrounding attack surfaces before attackers have an opportunity to exploit them.
Download the Token Passkey Security Ebook to explore publicly documented passkey attack techniques and learn how specialized biometric hardware can change the trust model for enterprise identities.
Sponsored and written by Token.
Source: www.bleepingcomputer.com


