ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Artificial Intelligence

Researchers document 39 passkey attack methods

The article said passkeys were still being compromised through the systems around them, listed 39 published attack methods, and argued that dedicated biometric hardware and tighter enrolment controls reduced that risk.

BleepingComputer

The article said passkeys were intended to make phishing and credential theft harder, but that attention had shifted to the systems around them. It said there were now at least 39 publicly documented ways to compromise passkey authentication or the infrastructure that supports it.

It described passkey authentication as crossing many trust boundaries, including the web application, browser, operating system, password manager, cloud synchronisation service, mobile device, recovery process, enrolment process, help desk and the person approving access. SpecterOps’ Pass the Passkey work was cited as an example, with a malicious Windows application asking WebAuthn infrastructure to produce a signed assertion while the private key stayed in place.

The article said some published methods focused on the prompt and interface layer rather than the cryptographic protocol. It listed repeated prompt attacks, interface deception, metadata spoofing, window spoofing, remote desktop phishing and overlay attacks, and compared that problem with push-based MFA because users can become used to repeated prompts.

It also said shareable or synchronised passkeys expanded the attack surface through cloud accounts, exported vaults, restored credentials, recovered phones, malware, rooted devices, browser extensions and Bluetooth-related paths. Other techniques were described as creating new credentials through enrolment or recovery, including shadow passkeys, help desk takeover and account recovery abuse.

The piece said dedicated biometric hardware reduced this exposure because it could avoid cloud synchronisation, export features, ordinary applications and a browser. It also said the service side still had to enforce approved authenticator classes, challenge validation, user verification and stronger controls for enrolment and recovery.

Named in this story

Companies

Token
sponsored and wrote the piece, promoting dedicated biometric hardware
SpecterOps
published Pass the Passkey research cited in the article
Apple
named in account takeover examples affecting synchronised passkeys
Google
named in account takeover examples affecting synchronised passkeys

Organisations

FIDO2
the cryptographic framework discussed as remaining intact
WebAuthn
the infrastructure used in the example assertion attack

Products and systems

Windows
the platform used in the cited malicious application example
Bitwarden
its export theft was listed as one passkey-related attack path
KeePassXC
its export theft was listed as one passkey-related attack path

How the source tells it

The register was promotional and urgent, combining a counted threat catalogue with repeated claims that the sponsor’s hardware approach narrowed the attack surface.

  • Urgency a rapidly changing security picture and repeated calls for enterprises to understand the new threat model
  • Threat inflation a long inventory of attack methods presented as a growing public playbook
  • Vendor boosterism the sponsor’s hardware is framed as removing most of the attack surface and the piece ends with a download pitch
  • Reassurance it repeatedly says the underlying cryptography was not broken and the weakness sits in surrounding systems