Passkey attacks expose serious authentication weaknesses. Attackers use downgrade tricks to bypass FIDO2 passkeys and force weaker sign-in methods. Users are at risk unless they remove backup options and enforce strong access policies.


How Downgrade Attacks Work

Proofpoint researchers show that phishing kits can prompt users to sign in using passwords instead of passkeys—especially when systems lack full support for FIDO2 across browsers or operating systems. This forces a fallback to password + MFA flows and defeats the security benefits of passkeys


Widespread Technique in Phishing Tools

Downgrade is now a staple in modern phishing toolkits like Evilginx. These kits modify the MFA prompt—removing the passkey option and pushing users toward less secure backup methods like SMS or authenticator apps


Cross-Device Phishing Loophole

Earlier this year, Expel analysts reported a phishing method exploiting FIDO’s cross-device QR code authentication. Attackers captured and relayed QR codes in real time, tricking users into unknowingly approving malicious login attempts. Though not a flaw in the FIDO protocol, the hybrid flow became exploitable when proximity checks were weak


Broader Context and Implementation Risks

Security experts warn that vulnerable fallback options and improper passkey setups leave systems open to adversary-in-the-middle (AitM) phishing attacks. If passkey flows are not enforced or backups aren’t disabled, even passkey-secured accounts remain phishable


Recommended Mitigations

To strengthen defenses:

  • Eliminate or restrict backup authentication methods entirely
  • Use conditional access to enforce login from approved, managed devices only
  • Prefer phishing-resistant alternatives like magic links if fallback is unavoidable

Conclusion

Passkey attacks, mainly through downgrade and cross-device phishing, reveal the fragile state of current MFA setups. Even phishing-resistant methods fail without proper backup controls and secure implementations. Strong conditional access policies and backup removal are essential to truly safeguard authentication systems.


0 responses to “Passkey Attacks Expose Authentication Weaknesses”