New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

A new wave of Passkey attacks has emerged, putting users’ sensitive data at risk by exploiting a vulnerability in password managers that sync private keys across devices. These sophisticated attacks can not only recover synced private keys but also bypass even the most secure multi-factor authentication (MFA) systems.

The targeted threat actors use complex methods to gain access to victims’ accounts, often starting with phishing or social engineering tactics to obtain login credentials. Once inside, they exploit vulnerabilities in popular password managers like LastPass and 1Password, which store users’ private keys securely on their servers. By manipulating the syncing process, attackers can recover these sensitive keys, giving them unencumbered access to victims’ online presence.

But that’s not all – the same group of attackers has also developed a way to bypass even phishing-resistant MFA systems. These systems are designed to prevent attackers from obtaining login credentials through phishing or other social engineering methods by requiring users to provide a second form of verification, such as a biometric scan or a one-time password generated on their device. However, the new Passkey attacks can manipulate this process, essentially “spoofing” the MFA system into accepting fake verification codes.

It’s worth noting that these attacks don’t require any user interaction – once an attacker has gained access to a victim’s account, they can execute the attack in the background without alerting the user. This makes it even more difficult for users to detect and prevent such breaches.

The affected groups are those who use popular password managers to sync their private keys across devices. The vulnerability lies in these syncing processes, which make it possible for attackers to recover sensitive information even if the original login credentials have been compromised.

Experts warn that this new threat is particularly concerning because it combines social engineering tactics with sophisticated technical exploits, making it difficult for users to detect and prevent such attacks. As more users rely on password managers to secure their online presence, it’s essential that these tools are regularly updated to address emerging threats like the Passkey attacks.

In light of these findings, cybersecurity experts recommend that users take immediate action to protect themselves from this new threat. First and foremost, make sure your password manager is up-to-date with the latest security patches. Additionally, consider enabling two-factor authentication (2FA) or multi-step verification processes whenever possible. While no solution can guarantee absolute security, taking these precautions will significantly reduce the risk of falling victim to Passkey attacks.


Source: The Hacker News — 2026-08-10