New Attack Targets Google Passkeys
Passkeys have been widely promoted as the future of passwordless authentication, offering stronger protection against phishing and credential theft than traditional passwords. However, new research from Palo Alto Networks Unit 42demonstrates that even passkey ecosystems are not immune to sophisticated attacks once a device has already been compromised by malware.
Researchers identified three attack techniques-Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that target different components of Google Password Manager's synchronized passkey architecture. Rather than breaking cryptography, the attacks exploit weaknesses in device verification, passkey synchronization, recovery, and re-registration processes. If malware is already running on a Windows device, attackers may be able to authenticate as the victim, register malicious devices, or in the most severe scenario, recover encryption secrets used to protect synchronized passkeys.
One technique reportedly enabled authentication against websites that failed to properly validate user verification, while another manipulated device re-registration to establish attacker-controlled trust. The most advanced attack targeted the Security Domain Secret, which protects synchronized passkeys, potentially allowing attackers to decrypt passkey data and transfer credentials to another system.
Importantly, these attacks are post-compromise techniques. They require malware to already be present on the victim's endpoint and do not represent a remote bypass of passkeys by themselves. There is no indication that attackers can exploit these techniques against fully protected devices without first gaining access.
The research reinforces an important cybersecurity reality: strong authentication cannot compensate for a compromised endpoint. While passkeys remain significantly more secure than passwords and resistant to phishing, their security ultimately depends on the integrity of the device, browser, operating system, cloud synchronization service, and surrounding authentication infrastructure.
For enterprises, the findings highlight the need to move beyond authentication alone toward a Zero Trust security model. Organizations should combine passkeys with endpoint detection and response (EDR), hardware-backed security, behavioral analytics, continuous monitoring, device attestation, and real-time risk assessment. Websites should also enforce proper validation of user verification signals and strengthen device enrollment and recovery processes.
The disclosure is expected to accelerate improvements across the passwordless authentication ecosystem. Browser vendors and credential providers are likely to strengthen passkey synchronization, secure sensitive secrets in memory, harden device re-registration workflows, and improve key rotation and recovery mechanisms. Enterprises will increasingly adopt layered security strategies that combine passkeys, behavioral biometrics, AI-driven threat detection, and continuous identity verification to defend against sophisticated post-compromise attacks.
The broader message is clear: passwords may disappear, but identity security remains an ongoing process. The future belongs to continuous, adaptive authentication that verifies not only the credential but also the trusted device, the user, and the behavior behind every digital session.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




