By Matteo Giordano
A three-part series on passkeys for security engineers and offensive security specialists. You are reading the third part.
- Under the Hood: The Protocol. How passkey ceremonies work at the byte level.
- Under the Hood: The Architecture. Distinctive features, taxonomies, and deployment edge cases.
- Under Attack (whitepaper, PDF). Pentesting the passkey Chain of Trust.
TL;DR
The first blogpost walked through the protocol stack, the ceremonies, and the raw data structures on the wire. The second blogpost covered the architecture and the deployment edge cases practitioners run into. This third part is the offensive companion, mapping the passkey attack surface, and we've published it as a downloadable whitepaper (PDF).
Passkeys do effectively eliminate traditional credential stuffing and simplistic Adversary-in-the-Middle (AiTM) phishing. But a sign-in is only ever as strong as the weakest actor the ceremony depends on, and that list runs a long way past the cryptography. The paper examines that surface as of 2026, covering the six actors involved in passkey deployments and distinguishing research findings from deployment-level testing.
What's Inside
The paper breaks the passkey attack surface into six actors:
- The authenticator and the protocols. WebAuthn and CTAP as specified, formal verification, silicon, and the CTAP management surface.
- The hybrid transport. Cross-device authentication unexpected flaws.
- The client. Browser, extension, password manager. Assume-breach territory.
- The relying party. The heaviest stop, where a time-boxed engagement spends nearly all its hours.
- The sync fabric. Credential synchronization, sharing, export, and provider security.
- The user and recovery. Fallbacks, enrollment, revocations and inter-personal threat models.
It closes with a 43-row test-case reference for assessing a passkey deployment and a survey of the available tooling, including Passkey Editor, our Burp Suite extension for decoding, tampering with, and re-signing WebAuthn traffic.
Demystifying Passkeys: Under Attack
Whitepaper by Matteo Giordano. 60 pages.

