New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Researchers warn of new passkey attacks capable of recovering synced private keys and bypassing phishing-resistant multi-factor authentication.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A security vulnerability has emerged that threatens the integrity of passkey systems, specifically those designed to be phishing-resistant. This development represents a significant shift in the threat landscape for users who have migrated from traditional passwords to passkeys for account security. The attacks target the very mechanisms intended to protect user identities from unauthorized access through cryptographic keys. Coverage of this development is appearing in specialized and generalist media. The Hacker News provides a detailed technical focus, explicitly stating that these attacks can recover synced private keys and undermine MFA that was previously considered phishing-resistant.
Simultaneously, GB News has highlighted the scale of the potential impact, reporting that researchers are warning that millions of Google accounts could be under attack due to these vulnerabilities. Both outlets emphasize that the security guarantees once associated with passkey adoption are now being challenged by these new methods of exploitation. To understand the significance of this trend, it is necessary to recognize that passkeys were implemented as a replacement for passwords to eliminate the risks associated with phishing. By using public-key cryptography, they were designed to ensure that a private key never leaves the user's device or a secure synchronization cloud. Because these new attacks can recover those synced private keys, the fundamental security premise of the technology is at risk.
This is particularly critical for Google accounts, where millions of users rely on these synchronized credentials for access to their personal data and connected services. Looking forward, the focus remains on the warnings issued by researchers regarding the vulnerability of Google accounts and the technical feasibility of bypassing MFA. The coverage does not yet specify a patch or a direct mitigation strategy provided by the affected service providers. Future developments will likely center on whether these attacks can be scaled further and how platforms like Google respond to the ability of attackers to recover private keys that were meant to be securely synced across devices.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 2h ago.
Quick answers
What specific risk do these new passkey attacks pose?
The attacks can recover synced private keys or bypass multi-factor authentication (MFA) that was previously thought to be phishing-resistant.
Which major platform is specifically mentioned as being at risk?
GB News reports that researchers are warning that millions of Google accounts could be under attack.
Why is this a significant development for security?
Passkeys were designed to be phishing-resistant; the ability to recover private keys undermines the core security benefit of the technology.
Coverage (2)
- Millions of Google accounts could be under attack, researchers warn GB News · 12h ago
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA The Hacker News · 12h ago
Topics
Related trends
A cybersecurity researcher covered a Toyota in an AI-generated pattern to confuse Flock cameras
A cybersecurity researcher is testing the limits of automated license plate recognition by wrapping a Toyota in AI-generated patterns.
"This is why physical media matters": anger as Google yanks access to The Lord Of The Rings films, even if you 'bought' them - What Hi-Fi?
Google's removal of purchased Lord of the Rings digital films has sparked a wider debate over the fragility of digital ownership and physical media.
What to expect from Google’s 2026 Pixel hardware launch event
Google is preparing for its Made by Google event to unveil the Pixel 11 and Watch 5 hardware updates.
OpenAI introduces a new cyber model amid fears of AI cyberattacks
OpenAI has launched a new cyber model to bolster defenses as concerns grow over the potential for AI-driven cyberattacks.
UK Navy Drone Camera Components Were Secretly Communicating With China
The UK Navy is facing a security breach after drone camera components were found to be secretly communicating with China.
The Pixel Watch 5 is about to get the Stephen Curry treatment
Google is expanding its wearable lineup by introducing a dedicated Stephen Curry edition of the upcoming Pixel Watch 5.