A shift toward passwordless authentication has been a major goal for enterprises and security researchers alike, but a recent report from Palo Alto Networks Unit 42 highlights significant risks in how passkeys are currently implemented. The findings reveal that attackers can bypass passkey protections using malware already present on a victim’s device, effectively enabling full account takeover without needing to crack the underlying cryptography. These findings underscore critical passkey security vulnerabilities that organizations must address as they accelerate passwordless strategies.
The report, which details three distinct attack categories collectively dubbed “Pass-ta-key,” shows how onboarding flows, recovery mechanisms, and device trust signals can be exploited. While the vulnerabilities do not break the FIDO2 standard itself, they expose critical gaps in the surrounding infrastructure that many organizations rely on for enterprise authentication.
Three Attack Vectors Exposed
Palo Alto Networks Unit 42 outlined three specific methods that attackers can use to compromise passkey-protected accounts. The first, Pass-ta-key, involves malware running on a victim’s device taking over an account protected by a Google-synced passkey. This attack requires no privilege escalation, device unlock, or direct user interaction, making it particularly insidious for users who believe their accounts are secure.
The second method, Silver Pass-ta-key, tricks the Google Cloud Authenticator into believing the victim has unlocked their device using biometrics. This allows a full account takeover without the attacker ever needing to use the victim’s physical device during the authentication process. The attack exploits the trust signals between the device and the authenticator, bypassing user verification requirements entirely.
The most severe category is Golden Pass-ta-key, which enables an attacker to extract all synced passkeys from a device. Once extracted, these credentials can be shared or sold on the credential black market, creating a widespread risk for anyone using synced passkey solutions. This method highlights the vulnerability of centralized credential storage and the potential for large-scale data breaches.

Understanding Passkey Security Vulnerabilities
Security analysts emphasize that these vulnerabilities stem from weaknesses in implementation rather than flaws in the passkey protocol itself. Justin Greis, CEO of consulting firm Acceligence, noted that researchers exploited the seams around the cryptography, including onboarding flows and recovery mechanisms that lacked proper validation. “The distinction matters because it tells us where the actual risk lives,” Greis said.
Brian Levine, executive director of FormerGov, pointed out that many services accept logins without properly validating the user-verified flag. This oversight effectively collapses a multi-factor login back into a single factor, undermining the security benefits of passkeys. “On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” Levine advised.
Frank Dickson, group VP for security at IDC, stressed that these attacks assume a prior successful penetration. “This isn’t passkeys getting hacked from across the internet. It’s what an attacker does once they’re already inside the house,” he said. He advised organizations to require user verification server-side and to reserve hardware-bound keys for high-value accounts. “Stop treating verification as optional,” Dickson emphasized. “Flip it to required, check it server side every single time, and save your hardware bound keys for the accounts that matter most.”
What This Means for Enterprise Security
For enterprise CISOs, the report underscores the importance of treating passkey adoption as a multi-layered security challenge. While passcodes have been embraced as a step toward passwordless strategies, the Palo Alto findings reveal that synced passkeys reintroduce credential theft risks that hardware-bound keys were designed to eliminate. J. Wolfgang Goerlich, a cybersecurity consultant, highlighted that a passwordless system is only as strong as the flow that re-establishes it.
Goerlich recommended requiring device-bound authenticators for all privileged and sensitive access, while allowing wallets only for lower-risk scenarios. “Much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk,” he said. This stance aligns with the broader security community’s push for hardware-based authentication for high-value accounts.
Or Finkelstein, head of marketing at Secret Double Octopus, advised CISOs to review how user verification is enforced, how enrollment and recovery work, and to implement clear policies on credential syncing. He also emphasized the need for ITDR systems to quickly mitigate suspicious endpoints and authenticators. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path,” Finkelstein noted.

What You Should Do Now
If you are using synced passkeys, consider the following steps to enhance your security posture:
- Review Sync Policies: Evaluate whether syncing passkeys across devices is necessary for your use case. For high-value accounts, consider using device-bound keys instead. This reduces the risk of large-scale credential theft.
- Enable User Verification: Ensure that your authentication systems require and validate user verification flags during login. This prevents attackers from bypassing biometric checks.
- Monitor Endpoint Security: Since these attacks assume prior penetration, focus on robust endpoint detection and response (EDR) solutions to prevent initial compromise. Regularly update your security software and train employees on phishing awareness.
- Test Recovery Flows: Regularly test your passkey recovery mechanisms to ensure they cannot be exploited by attackers who have gained access to a device. Implement multi-factor authentication for recovery processes.
- Consider Hardware Keys: For critical accounts, use hardware security keys like YubiKeys. These devices store private keys locally and cannot be extracted or synced, providing an additional layer of security.
The shift toward passwordless authentication is inevitable, but it requires careful implementation and ongoing vigilance. By addressing the gaps highlighted in the Palo Alto Networks report, organizations can better protect their accounts and maintain the security benefits of passkeys.
How are you balancing convenience and security with your current passkey setup? Share your thoughts in the comments below.
Source: Computerworld
Over to you: Are you still relying on synced passkeys across devices, or have you switched to hardware tokens for sensitive accounts?



