Security1 distinct publisher3 min readPublished
BleepingComputer counts at least 39 published passkey attack methods. Most of the ones it names need code on the endpoint or control of a sync account first, and that is where the defensive work actually lands.
The Watch · Security desk
build
Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout1 distinct publisher
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
security
On Windows, a named pipe is a local API: assume everything on the box can knock1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
What matters most here is what the attacker has to hold before the technique works, since that varies a lot across the list.
The SpecterOps path is post-compromise. It needs a malicious Windows application already running on the user's machine [6]. What it changes is the value of that foothold. The malicious app calls the legitimate WebAuthn infrastructure, the user sees what looks like a normal Windows authentication experience and completes verification, and the attacker collects the signed assertion [6]. The private key stays where it was and the cryptography is never attacked [7]. Malware does not need to extract a key at all [5]. So for an operator, the honest translation is that a passkey removes the credential-theft and phishing path and leaves the endpoint exactly as decisive as it was.
Two entries in the published inventory do not start on the corporate endpoint: Apple or Google account takeover, and cloud recovery takeover [12]. Those reach the sync fabric from outside, which puts enterprise authentication assurance on top of consumer accounts the enterprise does not administer. Alongside them sit synced vault compromise, mobile malware, rooted devices, hybrid authentication manipulation, KeePassXC and Bitwarden export theft, credential exchange theft, malicious browser extensions, and a truncated entry covering CTAP and Bluetooth [12].
The tally itself needs care. Of the 39, the article names 27 techniques outright: 10 at the ceremony layer, 6 at the interface layer, 11 in the sync and sharing list [15]. A dozen are counted but not itemised, so nobody can map a control to them yet. The article also says some techniques are appearing in real world attack patterns [2] without naming an actor, a victim, a date or a CVE [16], and it states plainly that criminals have not operationalised all 39 [3]. The categories are documented in the piece; how widespread any of them actually is remains an assertion rather than a demonstrated count.
Enrollment is the weakest leg of the argument as published. The article lists enrollment among the trust boundaries a single ceremony crosses [8], and the promotional copy inside the piece leads with enrollment abuse and with a claim that passkeys are not completely secure unless tied to dedicated biometric hardware [14]. The named techniques do not carry that. None of the 27 is described as an enrollment attack [17]. The weight lands on the authentication ceremony, on the prompt itself, and on the sync fabric.
The interface work is the part that reads most like an operational campaign in waiting. Prompt flooding, credential interface deception, application metadata spoofing, window handle spoofing, remote desktop passkey phishing and FIDO interface overlay attacks are all published [10], and SpecterOps demonstrated tooling that repeatedly invokes legitimate-looking Windows passkey prompts, plus techniques that make malicious authentication appear to come from an application the employee already trusts [11]. That is the push-MFA fatigue problem rebuilt on a new prompt: once approval is routine, it can be manufactured, repeated, disguised or timed [13].
The load-bearing point survives the sponsorship around it. FIDO2 cryptography can stay entirely intact while the account it protects is taken [4], because phishing resistance at the protocol layer is not deception resistance at the operating system, browser and application layers wrapped around it [18].
Ranked by verification strength, evidence, and original report placement.
BleepingComputer reports there are now at least 39 publicly documented methods, attack paths, research techniques and exploitation scenarios involving passkeys and the infrastructure around them.
The article's central distinction is that the cryptography inside FIDO2 can remain completely intact while the account protected by the passkey is still compromised.
SpecterOps, in its Pass the Passkey research, observed that malware does not necessarily need to extract a private key.
Per the article, a malicious Windows application can ask the legitimate WebAuthn infrastructure to generate a signed assertion; the user sees what appears to be a legitimate Windows authentication experience, completes verification, and the attacker receives the resulting assertion.
In that technique the private key never left its protected location and the cryptography was not cracked, yet the authentication process was successfully manipulated.
The sync and sharing inventory in the article names synced vault compromise, Apple or Google account takeover, cloud recovery takeover, stolen or compromised phones, mobile malware, rooted mobile devices, hybrid authentication manipulation, KeePassXC export theft, Bitwarden export theft, credential exchange theft and malicious browser extensions, plus a further entry involving CTAP and Bluetooth that the available text cuts off mid-word.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One post carrying other people's research
Everything traces to a single BleepingComputer piece that links to nothing: SpecterOps' Pass the Passkey work is relayed secondhand, and the 39-method figure is an inventory no one outside that post has audited. The enumeration is its strongest asset — some 37 techniques are named, so the count is not hollow — but the one sentence claiming real-world use offers no actor, victim, date or CVE, individual entries carry no citations, and the text stops mid-sentence in the enrollment section.
Demonstrated tooling, zero named intrusions
The concrete capability in this story belongs to SpecterOps: prompts that can be raised at will on Windows, and an assertion handed to a caller that never touched the private key. Beyond that it is research inventory. No campaign, breach or victim organisation is identified, no telemetry is offered, and nothing indicates how many enterprises have changed passkey or sync policy in response. Capability is in public; attacker uptake is unmeasured.
A tally that flattens very unequal prerequisites
Counting 39 methods treats them as interchangeable when they are not. Stolen phones, malicious browser extensions and vault export theft sit in the same total as SpecterOps' assertion issuance, and most of what is named requires code already running on the endpoint or control of a sync account — a different threat model from the phishing passkeys were sold to defeat. 'New' is generous too: several entries are old tradecraft aimed at a new credential type. The one idea that deserves the headline, that protocol-layer phishing resistance is not interface-layer deception resistance, gets less room than the number does.
The pitch sits inside the argument
Midway through, the prose stops reporting and starts selling: passkeys are 'not completely secure unless they are tied to dedicated biometric hardware', followed by a download about attackers exploiting enrollment rather than cryptography. That is a product thesis, and it is precisely the thesis the surrounding taxonomy builds toward — the enrollment and recovery section is the one the report promotes. No sponsor is named in the text we have, which is itself the problem: a reader cannot tell where the reporting ends and the vendor's interest begins.
Sound mechanism, unverifiable scale
Two readings that circulated in our own earlier take on this story do not survive the fuller text: the piece names far more than 27 techniques, and it does itemise nine enrollment and recovery attacks, so the complaint that enrollment appears only as a boundary label is wrong. What remains is a plausible, specifically described Windows mechanism attributed to a known research shop, sitting inside a single-publisher article with no primary links, a vendor pitch in the middle, and a body that cuts off mid-word. Confident about the mechanism, not about the number.