Researchers have discovered vulnerabilities in passkey systems, allowing attackers to bypass phishing-resistant multi-factor authentication or recover synced private keys. Specifically, three separate research efforts demonstrated that passkey protections can be defeated without compromising the underlying cryptography. One attack reused signed authentication material exposed by Windows, while another exploited a cloud-synced passkey system using malware already present on the victim's machine. These findings highlight the potential risks associated with passkey implementations, particularly those that rely on cloud syncing or store sensitive authentication material on the client-side. The fact that these attacks can be carried out without breaking the cryptography itself makes them particularly concerning1. So what this means for security practitioners is that they must remain vigilant and closely monitor the evolving threat landscape to ensure their passkey implementations are secure and resistant to emerging attacks.
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
⚡ High Priority
Why This Matters
Security developments continue reshaping the threat landscape — staying informed is the first line of defense.
References
- The Hacker News. (2026, August 10). New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA. *The Hacker News*. https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html
Original Source
The Hacker News
Read original →