Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method. A clean PC won’t be vulnerable when passkeys are used, but the researchers found malicious software can attack passkeys at the authentication stage, even if they were created on a healthy device. The malware then authenticates itself with Google Password Manager without user consent. The “silver” passkey attack method goes a step further and tricks the password manager into assuming the user has unlocked the device using biometrics. Unit 42’s last attack method is the most frightening because it means any future passkeys generated through Google Password Manager are easily decrypted by the attacker.