New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

A new class of attacks has emerged, targeting sensitive information stored in password managers and multi-factor authentication (MFA) systems. Dubbed “Passkey Attacks,” these exploits can recover synced private keys or bypass phishing-resistant MFA, leaving users vulnerable to credential theft and identity compromise.

The Passkey Attack methodology relies on exploiting a previously unknown vulnerability in the way cross-domain privilege escalation is handled by password managers and MFA platforms. In essence, when sensitive information is synced across multiple domains, a backdoor is created that allows attackers to bypass security controls and access private keys or MFA credentials. This vulnerability can be exploited through various means, including phishing attacks or even exploiting vulnerabilities in the underlying infrastructure.

One of the key concerns surrounding Passkey Attacks is their potential impact on password managers, which are designed to securely store and manage sensitive information. A compromised password manager can have far-reaching consequences, as it can lead to a loss of control over synced private keys and MFA credentials. This vulnerability not only affects users but also organizations that rely on password managers for employee authentication.

The fact that Passkey Attacks can bypass phishing-resistant MFA is particularly alarming. Phishing-resistant MFA solutions are designed to provide an additional layer of security, making it more difficult for attackers to compromise user credentials through social engineering attacks. However, the vulnerability exploited by Passkey Attacks allows attackers to circumvent these controls and access sensitive information directly.

The scope of the problem is significant, with numerous password managers and MFA platforms potentially affected. While no specific vendors or products have been named in the reported incidents, it’s clear that a wide range of organizations and individuals are at risk. The consequences of a successful Passkey Attack can be devastating, including unauthorized access to sensitive information, financial loss, and reputational damage.

To mitigate the risks associated with Passkey Attacks, users should take immediate action by reviewing their password manager and MFA settings. This includes regularly updating software, enabling two-factor authentication (2FA) where possible, and using a secure password generator for all online accounts. Furthermore, it’s essential to stay informed about any vulnerabilities or patches related to your specific password manager and MFA platform.

In the face of emerging threats like Passkey Attacks, staying vigilant and proactive is crucial for maintaining digital security. By understanding the risks and taking steps to protect sensitive information, individuals and organizations can reduce their exposure to cyber attacks and minimize potential damage.


Source: The Hacker News — 2026-08-10