There are now at least 39 publicly documented methods, attack paths, research techniques, and exploitation scenarios involving passkeys and the infrastructure around them.
The expanded attack surface around passkeys
Passkeys replaced passwords with public key cryptography and promised to make phishing and credential theft dramatically harder. But researchers now document attacks against the many layers that surround a modern passkey ceremony: the web application, browser, operating system, password manager, cloud synchronization service, mobile device, Bluetooth transport, account recovery system, enrollment process, help desk, and the human approving the authentication.
Published techniques include assertion mining, assertion replay, circuit breaker attacks, assertion phishing, browser hooking, assertion capture, challenge injection, detour replay, user verification manipulation, and user presence manipulation — showing that the cryptography can remain intact while the account is compromised.
SpecterOps and the “malware need not extract the private key” demonstration
SpecterOps' Pass the Passkey research underscores the central distinction: "malware does not necessarily need to extract a private key." A malicious Windows application can ask the legitimate WebAuthn infrastructure to generate a signed assertion; the user completes what appears to be a legitimate Windows authentication flow, and the attacker receives the resulting assertion. The private key never left its protected location, yet the authentication process was manipulated.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleUser interfaces and prompt-level attacks
Several of the methods target the authentication UI itself. Researchers demonstrated passkey prompt flooding, credential interface deception, application metadata spoofing, window handle spoofing, remote desktop passkey phishing, and FIDO interface overlay attacks. Tooling can repeatedly invoke legitimate-looking Windows passkey prompts and make malicious activity appear to originate from trusted applications. The finding: "Phishing resistance at the cryptographic protocol layer does not guarantee deception resistance across the operating system, browser, application, and user interface layers."
Shareable passkeys, synchronization, and architectural risk
When passkeys can be shared, synchronized, exported, restored, or moved, the attack surface grows. Researchers catalog synced vault compromise, Apple or Google account takeover, cloud recovery takeover, stolen or compromised phones, mobile malware, rooted mobile devices, hybrid authentication manipulation, KeePassXC export theft, Bitwarden export theft, credential exchange theft, malicious browser extensions, and CTAP and Bluetooth-related attacks.
As the source puts it, "This is not fundamentally a cryptography problem. It is an architectural problem." Once a credential moves between devices or through cloud ecosystems, attackers only need to compromise a sufficiently trusted component in that ecosystem — not the FIDO2 cryptography itself.
Enrollment, recovery, and the danger of new credentials
Some of the most consequential attacks create new credentials rather than stealing existing ones. Published techniques include shadow passkeys, enrollment vishing, attacker phone enrollment, attacker-controlled passkey registration, help desk takeover, temporary credential abuse, SIM-based recovery, reverse vishing, and migration pretext attacks. An attacker who gains enough control to register a passkey can have the relying service create a valid credential on the attacker's device — again leaving cryptography intact while granting the adversary access.
What this means for technologists, enterprises, and end users
- Technologists and security teams: configure relying parties to restrict authentication and enrollment to approved authenticator classes; validate authenticator identity; enforce user verification; properly validate challenges and sessions; use appropriate signature counter protections; and prevent weaker methods becoming fallback authentication paths.
- Affected enterprises and procurement leaders: require enrollment and recovery flows to demand proof from an already authorized authenticator rather than weaker account control proofs, and prefer architectures that avoid freely shareable credentials across consumer cloud ecosystems.
- End users and the general public: be aware that synchronized vault compromise, stolen or compromised phones, mobile malware, and deceptive authentication prompts can yield account access even when underlying FIDO2 cryptography is sound.
The 39 published methods do not indicate a failure of FIDO2 cryptography; they show where attackers focus instead: the surrounding software, sync systems, enrollment processes, operating systems, browsers, recovery mechanisms, and people. The remedy suggested by the research is architectural: for high-value enterprise identities, bind credentials to dedicated biometric hardware, the verified individual, the legitimate service, and enterprise-controlled enrollment and recovery. Properly designed dedicated biometric authenticators — with no cloud sync, no export, and minimal functionality beyond authentication — remove large swaths of the surrounding attack surface before an attacker ever gets the opportunity to exploit it.
Sponsored and written by Token. Read the original coverage: https://www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/




