Table of Contents
Pass-ta-key Targets Google-synced Passkeys on Windows
As the National Cybersecurity Alliance predicted for 2026, more organizations and platforms are adopting passkeys and device-based authentication, reducing reliance on traditional passwords. While passkeys offer strong protection against phishing, credential theft, and other common cyberattacks, new research demonstrates that they do not eliminate identity security risks.
On August 3, 2026, Palo Alto Networks Unit 42 disclosed three new attack techniques: Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. These methods target Google Password Manager’s synchronized passkeys in Chrome on Windows.
Of note, the name Pass-ta-key is a wordplay on the digital authentication term passkey with the phrase “pass the key,” alongside a nod to a plate of pasta to show how tangled and messy this key implementation can get.
The good news is that the researchers didn’t break passkey cryptography. Instead, the attacks show how malware on an already-compromised computer could target the devices and infrastructure supporting passkey authentication.
What Are Passkeys?
Passkeys replace passwords with cryptographic credentials. Users typically authenticate to unlock their device using the same method, such as a fingerprint, facial recognition, or a PIN.
The FIDO Alliance describes passkeys as phishing-resistant because they use public-key cryptography and are tied to the website or application for which they were created. With no traditional password to steal and reuse, passkeys can also protect against credential stuffing and other password-based attacks.
Google Password Manager can synchronize encrypted passkeys across supported devices, making them more convenient for users. The new research, however, demonstrates how attackers may shift their attention from stealing passwords to compromising the systems where passkeys are stored and used.
How Do Pass-ta-key Attacks Work?
All three attacks require malware to already be running on the victim’s Windows computer. From there, researchers demonstrated increasingly serious attacks:
- Pass-ta-key could allow malware to impersonate a trusted device and potentially authenticate using a victim’s passkey without requiring the victim to provide a PIN, biometric, or other interaction. However, websites can protect against this version by properly requiring and validating WebAuthn user verification. Researchers found that GitHub successfully blocked the attack because it validated user verification, whereas eBay initially did not and later corrected the issue.
- Silver Pass-ta-key goes further by exploiting the device re-enrollment process. Researchers found an attacker could register an attacker-controlled user-verification key, potentially allowing authentication from another computer without continued access to the compromised device.
- Golden Pass-ta-key presents the most serious scenario. Researchers found malware could potentially obtain a master encryption key known as the Security Domain Secret from Chrome’s process memory during certain registration or recovery operations. That key could then be used to decrypt synchronized passkey private keys.
This could potentially give attackers portable copies of a victim’s passkeys rather than simply allowing them to authenticate through the compromised computer.
Passkey Security Still Depends on Endpoint Protection
“Passkeys are a strong step forward in authentication because they eliminate many of the risks associated with passwords,” said Ron Bebus, PrivaPlan CIO. “But organizations need to remember that no authentication method operates in isolation. The security of the devices and systems surrounding it matters just as much.”
Pass-ta-key doesn’t crack the cryptography underlying passkeys or undermine their resistance to traditional phishing and credential-stuffing attacks. Instead, it exposes a different risk: a compromised endpoint can undermine even strong authentication.
Once malware is running on a trusted computer, attackers may target browsers, credential managers, device enrollment, and account recovery processes rather than the authentication technology itself.
7 Passkey Security Best Practices
The Pass-ta-key research reinforces the importance of layered cybersecurity controls.
- Strengthen endpoint security with endpoint detection, anti-malware protections, and monitoring for suspicious access to browser processes and local passkey data.
- Keep systems up to date by promptly patching browsers, operating systems, and security software.
- Strengthen authentication controls by ensuring passkeys properly require and validate user verification and by applying additional protections to privileged and high-risk accounts.
- Monitor authentication activity for unusual logins, device enrollment, account recovery, and key verification activity.
- Train workforce members to recognize phishing, malware, and other common attack methods used to compromise devices and accounts.
- Conduct a Security Risk Assessment that includes passwordless authentication, passkey implementation, and endpoint security risks.
- Conduct a Privacy Risk Assessment to identify and evaluate the potential privacy impacts of breaches and other security incidents.
“Pass-ta-key highlights the importance of looking beyond individual security controls to understand how endpoints, authentication, users, policies, and other systems work together,” Bebus said. “A PrivaPlan risk assessment can help identify vulnerabilities and provide actionable recommendations for reducing risk.”
Passkeys Are One Layer of Cybersecurity
Passkeys remain an important advancement in authentication. But like any security technology, they aren’t a stand-alone defense.
For healthcare organizations, business associates, and organizations across other regulated or security-sensitive industries, Pass-ta-key provides another reminder that identity security and endpoint security must work together.
Moving beyond passwords can make credential theft considerably harder. Organizations must also protect the devices and systems where those credentials are stored and used.
Safeguard Confidential Data
Protecting sensitive and private data is paramount in today’s digital age. That’s why PrivaPlan offers comprehensive Privacy Risk Assessments tailored for corporations, healthcare providers, and government agencies that handle vast amounts of personal and confidential data.
FAQs: Pass-ta-key Attacks
What is a Pass-ta-key attack?
Pass-ta-key refers to newly disclosed attack techniques that could allow malware on a compromised Windows computer to target Google-synced passkeys. Rather than breaking passkey cryptography, the attacks exploit weaknesses in the devices and systems surrounding passkey authentication.
Can Pass-ta-key steal passkeys?
Potentially. The most serious technique, Golden Pass-ta-key, demonstrated how malware could obtain a master encryption key from Chrome’s process memory during certain operations and use it to decrypt synchronized passkey private keys.
Are passkeys still safe to use?
Yes. Passkeys remain more resistant than traditional passwords for phishing, credential stuffing, and stolen password attacks. Pass-ta-key does not break the underlying cryptography; it demonstrates the risk that arises when the device where passkeys are used is already compromised.
Does Pass-ta-key affect all passkeys?
No. The research focused on Google Password Manager synchronized passkeys used through Chrome on Windows. The findings should not be interpreted as a vulnerability affecting every passkey implementation or device.
How can organizations reduce the risk of Pass-ta-key attacks?
Organizations should maintain strong endpoint detection and anti-malware protections, promptly update browsers and operating systems, monitor unusual authentication and device-enrollment activity, properly enforce user verification, train employees to recognize malware-delivery methods, and include passwordless authentication in security risk assessments.


