Bottom line: According to Unit 42, malware on already compromised endpoint devices can take over passkey-protected Google accounts via onboarding, recovery and trust mechanisms, without breaking the passkey cryptography itself.
A report from Palo Alto Networks Unit 42 outlines three attack paths through which malware on an already compromised endpoint device can take over passkey-protected accounts. What is affected is not the cryptography of the passkeys themselves, but the onboarding, recovery and device trust mechanisms surrounding them.
Unit 42 at Palo Alto Networks has described three categories of attacks against Google-synced passkeys under the collective term “Pass-ta-key.” In “Pass-ta-key,” an attacker uses malware on the victim’s device to take over a passkey-protected account without requiring privilege escalation, device unlock, or user interaction. “Silver Pass-ta-key” tricks the Google Cloud Authenticator into accepting a biometric unlock as if performed by the victim, enabling full account takeover without access to the victim’s device during authentication. “Golden Pass-ta-key” allows extraction of all synced passkeys in a form that can be resold on the underground market for access credentials.
Analysts and advisors consistently emphasize that the underlying cryptography of the passkeys was not broken. Justin Greis, CEO of the consultancy Acceligence, puts it this way: the researchers did not attack the cryptography itself but exploited the interfaces around it — onboarding flows, recovery mechanisms, and trust signals that were not validated. Frank Dickson, Group VP for Security at IDC, points out that the attacks presuppose a prior successful compromise of the endpoint. This is not an attack on passkeys from the internet, he says, but rather what an attacker does once they are already inside the system. “Phishing-resistant” stops being resistant the moment the endpoint is no longer clean.
For CISOs introducing passwordless strategies with passkeys as a first step in complex environments — some still shaped by legacy systems or virtualization — the distinction between specification and implementation is central. Greis notes that in several cases mentioned in the report, the underlying problems do not lie with the standard itself but with the fact that implementations have not kept pace — the specification is solid, but the implementation ecosystem is inconsistent. Brian Levine, Executive Director of FormerGov, adds a concrete recommendation: services where one’s own organization acts as the relying party should require user verification and actually check the corresponding “user-verified” flag in the authentication response. The researchers found real-world services that accepted logins without this flag, effectively reducing a multi-factor login to a single factor.
Since a successful initial compromise often requires only a single privileged user clicking on a crafted link or attachment, the experts interviewed consider the assumption of prior penetration realistic and the report’s relevance well established. Dickson advises CISOs to stop treating verification as an optional step and instead review and enforce it as a mandatory component of every passkey implementation.
Source: www.csoonline.com · Published August 6, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.