Passkeys were supposed to be more secure than passwords. Now they’re getting hacked
Aug 31, 2026 | Guides
The promise of passkeys was a higher level of security than passwords, stemming from the fact that you can’t give away a passkey. You cannot share it, and a malicious actor cannot phish a passkey like they can a password. But a recent post by Arie Olshtein, who works for cybersecurity company Palo Alto Networks, detailed a set attacks collectively nicknamed Pass-ta-key that can, in the worst case, extract all locally synced passkeys and then use them to log in to websites and do all kinds of bad things. The catch is that Pass-ta-key is possible to pull off only on Windows, and by the looks of it, only if the passkeys are managed by Google Password Manager in Chrome for Windows.