Passkeys Aren't Bulletproof: New Research Shows Ways Attackers Can Bypass Them
Passkeys have been promoted as a major upgrade over passwords, offering strong resistance to phishing because they rely on cryptographic keys rather than something a user types in. However, new research presented last week shows that attackers don't need to crack the cryptography itself to defeat passkeys — they can exploit weaknesses in how the technology is implemented or synced across devices.
Three separate research efforts revealed different attack paths. One method reused signed authentication material that Windows had exposed. Another abused a cloud-synced passkey system, but only after malware was already present on the victim's device. A third approach found additional ways to bypass protections that were supposed to be resistant to phishing.
These findings don't mean passkeys are unsafe to use — they remain far stronger than traditional passwords. But they highlight that no security technology is immune to flaws in how it's built into operating systems, browsers, or cloud services. For small businesses relying on passkeys or considering the switch, staying informed about vendor security updates and maintaining strong endpoint protection remains essential, since several of these attacks required a device to already be compromised by malware.