Security researchers detail 39 publicly documented attack vectors against passkey authentication, underscoring that the threat model now extends beyond cryptography to the surrounding ecosystem.
Security researchers have cataloged 39 publicly documented attack vectors targeting passkey authentication, revealing that vulnerabilities extend far beyond the cryptographic algorithms themselves.
Why Passkeys Were Considered Secure
Passkeys, built on the FIDO2 standard, were praised for eliminating passwords and resisting phishing by tying credentials to device hardware and biometric verification.
Expanding the Threat Landscape
The new research shows that attackers can exploit weaknesses in implementation, user behavior, and device management, effectively bypassing the intended security guarantees.
- Compromised device firmware allowing key extraction
- Social engineering to trick users into registering malicious authenticators
- Man‑in‑the‑middle attacks on the registration flow
- Exploitation of insecure backup and sync mechanisms
Key Findings from the Study
Among the 39 methods, the most prevalent involve credential leakage during backup and abuse of weak authenticator enrollment policies that permit unauthorized devices to register.
The authors stress that organizations must adopt a holistic security approach, incorporating strict device hygiene, regular firmware updates, and user education to mitigate these risks.
The ecosystem around passkeys is as critical as the cryptography itself, and neglecting it opens doors for attackers.
For a detailed breakdown of all 39 attack vectors, see the BleepingComputer coverage of the research.
BleepingComputer coverage of 39 new methods that compromise passkey authentication