Security researchers have cataloged 39 distinct attack vectors capable of bypassing passkey authentication, revealing that the technology’s primary vulnerabilities stem from deployment practices rather than cryptographic design. Analysis by security firm Token demonstrates that threat actors are successfully circumventing FIDO2 standards by exploiting operational gaps, user interface manipulation, and legacy fallback mechanisms instead of attempting to break underlying encryption.
While passkeys effectively neutralize legacy threats like phishing and credential stuffing, their integration into production environments has introduced new operational attack surfaces. Token’s research maps these vulnerabilities across four critical trust boundaries: authentication prompts, cloud-synced credential stores, initial device enrollment, and account recovery workflows. The industry’s push for frictionless logins has inadvertently expanded these boundaries, with lenient consent flows and automated synchronization creating exploitable seams. Attackers now leverage approval fatigue, UI redressing, and deceptive prompt designs to trick users into authorizing malicious sessions or intercept credentials during cross-device synchronization.
To counter these operational threats, the findings advocate treating passkey adoption as a continuous security lifecycle rather than a static configuration. Resilient deployments require strict device attestation, explicit user consent protocols, and the decoupling of recovery workflows from legacy channels like SMS or email. Security teams must also implement aggressive rate-limiting to neutralize prompt flooding and maintain comprehensive audit logs to detect authentication anomalies. Regular audits of cloud-synced credential ecosystems are essential to identify interception risks before they escalate.
For IT architects and open-source developers, the research underscores a necessary shift in threat modeling. Security frameworks must evolve to account for non-cryptographic attack vectors, prioritizing secure-by-default implementations and continuous governance over convenience-driven shortcuts. By proactively updating internal risk assessments, enforcing rigorous validation controls, and treating passkey deployment as an ongoing security program, organizations can preserve the cryptographic advantages of FIDO2 while closing the operational gaps that attackers are actively exploiting.
安全研究人員已歸類出 39 種可繞過 Passkey 身份驗證的獨特攻擊途徑,揭示該技術的主要漏洞源於部署實踐,而非密碼學設計。安全公司 Token 的分析顯示,威脅行為者正透過利用運作漏洞、使用者介面操控及傳統後備機制,成功繞過 FIDO2 標準,而非嘗試破解底層加密。
儘管 Passkeys 能有效抵禦網絡釣魚及憑證填充等傳統威脅,但其整合至生產環境時,亦引入了新的運作攻擊面。Token 的研究將這些漏洞劃分至四個關鍵信任邊界:身份驗證提示、雲端同步憑證儲存庫、初始裝置註冊,以及帳戶復原工作流程。業界推動無縫登入的趨勢無意中擴大了這些邊界,寬鬆的同意流程與自動同步機制產生了可被利用的縫隙。攻擊者現正利用審批疲勞、UI redressing 及具誤導性的提示設計,誘騙用戶授權惡意工作階段,或在跨裝置同步期間攔截憑證。
為應對這些運作威脅,研究建議將 Passkey 的採用視為持續的安全生命週期,而非靜態設定。具韌性的部署需要嚴格的 device attestation、明確的用戶同意協議,並將復原工作流程與 SMS 或電郵等傳統渠道分離。保安團隊亦必須實施嚴格的 rate-limiting 以抵禦提示泛濫攻擊,並維持全面的審計日誌以偵測身份驗證異常。定期審計雲端同步憑證生態系統至關重要,以便在攔截風險升級前及時識別。
對 IT 架構師及 open source 開發者而言,該研究強調 threat modeling 必須作出必要轉變。保安框架必須演進以涵蓋非密碼學攻擊途徑,優先採用 secure-by-default 的實作方式及持續管治,而非追求便利的捷徑。透過主動更新內部風險評估、執行嚴格的驗證控制,並將 Passkey 部署視為持續進行的保安計劃,機構既能保留 FIDO2 的密碼學優勢,亦能修補攻擊者正積極利用的運作漏洞。
