PULSE the living trend engine
▲ Peaking Technology 🔮 PULSE predicts: fades by tomorrow

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Researchers warn of new passkey attacks capable of recovering synced private keys and bypassing phishing-resistant multi-factor authentication.

2sources
2articles
1velocity
+0%since first seen
3h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

A security vulnerability has emerged that threatens the integrity of passkey systems, specifically those designed to be phishing-resistant. This development represents a significant shift in the threat landscape for users who have migrated from traditional passwords to passkeys for account security. The attacks target the very mechanisms intended to protect user identities from unauthorized access through cryptographic keys. Coverage of this development is appearing in specialized and generalist media. The Hacker News provides a detailed technical focus, explicitly stating that these attacks can recover synced private keys and undermine MFA that was previously considered phishing-resistant.

Simultaneously, GB News has highlighted the scale of the potential impact, reporting that researchers are warning that millions of Google accounts could be under attack due to these vulnerabilities. Both outlets emphasize that the security guarantees once associated with passkey adoption are now being challenged by these new methods of exploitation. To understand the significance of this trend, it is necessary to recognize that passkeys were implemented as a replacement for passwords to eliminate the risks associated with phishing. By using public-key cryptography, they were designed to ensure that a private key never leaves the user's device or a secure synchronization cloud. Because these new attacks can recover those synced private keys, the fundamental security premise of the technology is at risk.

This is particularly critical for Google accounts, where millions of users rely on these synchronized credentials for access to their personal data and connected services. Looking forward, the focus remains on the warnings issued by researchers regarding the vulnerability of Google accounts and the technical feasibility of bypassing MFA. The coverage does not yet specify a patch or a direct mitigation strategy provided by the affected service providers. Future developments will likely center on whether these attacks can be scaled further and how platforms like Google respond to the ability of attackers to recover private keys that were meant to be securely synced across devices.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 2h ago.

Quick answers

What specific risk do these new passkey attacks pose?

The attacks can recover synced private keys or bypass multi-factor authentication (MFA) that was previously thought to be phishing-resistant.

Which major platform is specifically mentioned as being at risk?

GB News reports that researchers are warning that millions of Google accounts could be under attack.

Why is this a significant development for security?

Passkeys were designed to be phishing-resistant; the ability to recover private keys undermines the core security benefit of the technology.

Coverage (2)

Topics

Related trends