Demystifying Passkeys — Under Attack (Whitepaper)

Demystifying Passkeys — Under Attack (Whitepaper)

By Matteo Giordano

A three-part series on passkeys for security engineers and offensive security specialists. You are reading the third part.

  1. Under the Hood: The Protocol. How passkey ceremonies work at the byte level.
  2. Under the Hood: The Architecture. Distinctive features, taxonomies, and deployment edge cases.
  3. Under Attack (whitepaper, PDF). Pentesting the passkey Chain of Trust.

TL;DR

The first blogpost walked through the protocol stack, the ceremonies, and the raw data structures on the wire. The second blogpost covered the architecture and the deployment edge cases practitioners run into. This third part is the offensive companion, mapping the passkey attack surface, and we've published it as a downloadable whitepaper (PDF).

Passkeys do effectively eliminate traditional credential stuffing and simplistic Adversary-in-the-Middle (AiTM) phishing. But a sign-in is only ever as strong as the weakest actor the ceremony depends on, and that list runs a long way past the cryptography. The paper examines that surface as of 2026, covering the six actors involved in passkey deployments and distinguishing research findings from deployment-level testing.

What's Inside

The paper breaks the passkey attack surface into six actors:

  1. The authenticator and the protocols. WebAuthn and CTAP as specified, formal verification, silicon, and the CTAP management surface.
  2. The hybrid transport. Cross-device authentication unexpected flaws.
  3. The client. Browser, extension, password manager. Assume-breach territory.
  4. The relying party. The heaviest stop, where a time-boxed engagement spends nearly all its hours.
  5. The sync fabric. Credential synchronization, sharing, export, and provider security.
  6. The user and recovery. Fallbacks, enrollment, revocations and inter-personal threat models.

It closes with a 43-row test-case reference for assessing a passkey deployment and a survey of the available tooling, including Passkey Editor, our Burp Suite extension for decoding, tampering with, and re-signing WebAuthn traffic.

Demystifying Passkeys: Under Attack

Whitepaper by Matteo Giordano. 60 pages.

Download the Whitepaper (PDF)

About the Author

Matteo Giordano headshot.Matteo Giordano is a Security Engineer at Anvil Secure, working across AppSec and NetSec, with a focus on AI red teaming and GenAI security.

He came into security from kernel-side development at rev.ng Labs, where he worked on a next-generation decompiler.

Tools

aqlmap - A tool to extract information from ArangoDB through AQL injection. See the introductory blogpost.


awstracer - An Anvil CLI utility that will allow you to trace and replay AWS commands.


awssig - Anvil Secure's Burp extension for signing AWS requests with SigV4.


ByteBanter - A Burp Suite extension that leverages LLMs to generate context-aware payloads for Burp Intruder. See the introductory blogpost.


dawgmon - Dawg the hallway monitor: monitor operating system changes and analyze introduced attack surface when installing software. See the introductory blogpost.


GhidraGarminApp - A Ghidra processor and loader for Garmin watch applications. See the introductory blogpost.


HANAlyzer - A tool that automates SAP HANA security checks and outputs clear HTML reports. See the introductory blogpost.


IPAAutoDec - A tool that decrypts IPA files end-to-end via SSH. See the introductory blogpost.


nanopb-decompiler - Our nanopb-decompiler is an IDA python script that can recreate .proto files from binaries compiled with 0.3.x, and 0.4.x versions of nanopb. See the introductory blogpost.


OffTempo - A Burp Suite extension for statistical timing side-channel analysis. See the introductory blogpost.


Passkey Editor - A Burp Suite extension for testing WebAuthn/FIDO2 passkey ceremonies. See the introductory blogpost.


PQCDump - A passive PCAP analyzer that shows whether SSH and TLS sessions actually used PQC algorithms. See the introductory blogpost.


PQCScan - A scanner that can determine whether SSH and TLS servers support PQC algorithms. See the introductory blogpost.


SAPCARve - A utility Python script for manipulating SAP's SAR archive files. See the introductory blogpost.


ulexecve - A tool to execute ELF binaries on Linux directly from userland. See the introductory blogpost.


usb-racer - A tool for pentesting TOCTOU issues with USB storage devices.

Recent Posts