Future TechnologyFuture Technology
Security

Malware Just Learned to Steal the Login Method That Was Supposed to Be Unstealable

· 4 min read · By Future Technology

Key takeaways

  • Security researchers found malware capable of extracting synced passkeys from Google accounts, not just passwords and cookies
  • Passkeys were sold as phishing proof because the private key never leaves your device, but syncing that key across devices creates a new copy worth stealing
  • The attack targets the account holding your passkeys rather than the passkey mechanism itself
  • Reviewing which passkeys are saved to your account and adding a hardware key as an offline backup closes the gap

Passkeys have spent the last two years being pitched as the thing that finally kills password theft. The private key never leaves your device, so there is nothing for a phishing page to capture. That pitch just took a hit. Researchers have identified malware that can pull synced passkeys straight out of a compromised Google account, alongside the usual haul of saved passwords and session cookies.

How this squares with "phishing proof"

The phishing-resistance claim still holds in the narrow sense: an attacker cannot trick you into typing a passkey into a fake login page the way they could a password. But most people do not keep passkeys on one device. Apple, Google and Microsoft all sync them across your phone, laptop and tablet through your account, for convenience. That sync mechanism means a copy of your passkey material exists somewhere reachable, and if malware can get into the account managing that sync, it can potentially get at the passkeys too.

This does not make passkeys worse than passwords. A stolen password works immediately, anywhere, for anyone who has it. Getting at synced passkey data is a harder, more targeted job. But "harder" is not the same as impossible, and this incident is the first real proof that attackers are working on it.

Why it matters

The lesson is not to abandon passkeys. It is to stop treating the account that syncs them as low value. If your Google or Apple account is the single point that unlocks every passkey on every device, that account needs its own strong protection, not an afterthought. Go into your account's security settings, look at the list of saved passkeys, and remove anything for a service you no longer use or do not recognise. For accounts you cannot afford to lose, add a hardware security key like a YubiKey as an offline backup that never touches the cloud at all. We covered the basics of how passkeys work and how to switch a couple of weeks ago, and none of that advice has changed. This is a reason to tighten the account behind them, not to go back to passwords.

Some links in this article are affiliate links. If you buy through them, we may earn a small commission at no extra cost to you.

Browse all Cybersecurity stories →