Can Passkeys Be Stolen? What You Should Know
Short answer
Passkeys can be stolen if attackers gain access to the device or cloud service where they are stored, such as through malware, physical theft, or unauthorized cloud access. While passkeys provide stronger protection than passwords, securing your devices, backups, and accounts remains essential to prevent theft or misuse.
What Are Passkeys and How Do They Work?
Passkeys are digital credentials that replace traditional passwords for logging into websites and apps. Instead of typing a password, your device uses a unique cryptographic key combined with your biometric data (like a fingerprint or face scan) or a PIN to prove your identity securely.
For example, imagine you want to sign in to your email on your smartphone. Instead of entering a password, you place your finger on the phone’s fingerprint reader. Your phone then creates a special encrypted message using the stored passkey and sends it to the email service. The service confirms this message matches your public key on their side and grants access. Since the private key never leaves your phone, it can’t be intercepted or stolen during this process.
This process relies on public key cryptography: the private key is stored only on your device, while the service holds the public key to verify requests. This setup prevents attackers from capturing usable login information from the network or the service's servers.
Why Are Passkeys Still Vulnerable to Theft?
While passkeys are more secure than passwords, they can be stolen if an attacker accesses the device or the cloud storage where passkeys are saved. Some common ways this can happen include:
- Malware infections: Malicious software installed on your device can scan for stored credentials, including passkeys, and transmit them to attackers.
- Physical theft: If your unlocked or poorly secured phone or computer is stolen, someone could use the stored passkeys to access your accounts.
- Cloud backup compromises: Many devices back up passkeys to cloud services. If your cloud account is hacked, attackers may retrieve those stored passkeys.
- System vulnerabilities: Security flaws in your device’s operating system or hardware can sometimes allow attackers to extract passkeys.
For example, if someone downloads a fake app that secretly installs spyware, it could capture your passkeys and send them to a hacker. Or, if you lose your smartphone without a strong lock screen, the finder might sign into your accounts using your saved passkeys.
The main point is that passkey technology itself is strong, but the security of the surrounding environment—your devices, cloud accounts, and software—is crucial.
How Are Passkeys Different from Passwords and Why Does This Matter?
Passwords are words or phrases you memorize and type in to access accounts. They are stored on servers and can be stolen during hacks or reused in phishing attacks. Passkeys, by contrast, stay on your device and never get sent as text to websites.
Phishing scams trick users into entering passwords on fake sites. Passkeys prevent this because the cryptographic proof your device sends cannot be duplicated by a fraudulent website.
However, some people worry that if their device is lost or stolen, so are their passkeys. While that risk exists, it’s less common because devices require a PIN, password, or biometric to use passkeys. In comparison, stolen passwords can be used repeatedly if leaked.
In summary, passkeys reduce risks related to password theft and phishing but require you to protect your physical devices and backups carefully.
What Terms Are Often Confused with Passkeys?
To avoid confusion, here are some related terms and how they differ from passkeys:
- Passwords: Text-based secrets you enter manually; passkeys replace these with cryptographic keys.
- Two-Factor Authentication (2FA): An additional verification step (such as a code sent to your phone) after entering a password; passkeys combine authentication and verification into one process.
- Security Keys: Physical devices (like USB sticks or NFC tokens) used for authentication; passkeys may be stored on your device or such security keys.
- Biometrics: Methods such as fingerprint or facial recognition used by your device to confirm it’s you before using passkeys.
People sometimes mix up biometrics and passkeys, but biometrics are only used to authorize the use of passkeys stored on your device.
Why Does Passkey Security Matter to You?
As more websites adopt passkeys, they make logging in easier and safer. But this convenience depends on how well you protect your devices and cloud backups. If someone steals your passkeys, they can access your accounts without needing passwords.
For example, if your phone has no screen lock and gets stolen, the finder could access your accounts with stored passkeys. Or if your cloud backup password is weak and someone hacks your account, your passkeys could be retrieved and used to impersonate you online.
Understanding these risks encourages you to take protective steps like setting strong device locks, securing your cloud accounts with two-factor authentication, and checking devices regularly for suspicious activity. Protecting your passkeys helps safeguard your digital identity.
What Specific Actions Can You Take to Protect Your Passkeys?
Here are detailed steps you can take right now to keep your passkeys secure:
- Set a Strong Screen Lock: Use a PIN, password, or biometric lock (fingerprint or face ID) on your smartphone and computer. For example, instead of a simple 4-digit PIN like “1234,” choose a longer PIN or alphanumeric password or enable biometric verification.
- Enable Auto-Lock on Your Devices: Configure your phone and computer to lock automatically after a short time (such as 30 seconds to 1 minute) of inactivity. This prevents unauthorized access if you leave your device unattended.
- Keep Software Updated: Frequently install updates for your operating system and apps. Updates patch security vulnerabilities that attackers might exploit to steal passkeys.
- Protect Cloud Backup Accounts: If your device backs up passkeys to a cloud service (like iCloud or Google Drive), secure these accounts with strong, unique passwords and enable two-factor authentication. For example, use an authenticator app or SMS codes to add an extra step before logging into your cloud backup.
- Avoid Installing Untrusted Apps: Download apps only from official app stores and avoid clicking suspicious links, which can install malware that steals passkeys.
- Use Secure Networks: Avoid public WiFi when logging into sensitive accounts or syncing passkeys. If you must use public WiFi, connect through a trusted virtual private network (VPN) to encrypt your data.
- Learn Account Recovery Options: Understand how to recover your account if you lose access—such as backup codes or trusted contacts—so you don’t lose access permanently if your device is lost or stolen.
These steps help reduce the chances that someone can steal your passkeys and access your accounts.
What Should You Do If Your Device or Passkeys Are Lost or Stolen?
If your device containing passkeys is lost or stolen, act quickly:
- Use Remote Lock and Erase Tools:
Services like “Find My iPhone” or “Find My Device” for Android let you lock or erase your phone remotely to prevent unauthorized use.
- Change Passwords for Cloud and Important Accounts:
Immediately update passwords for your cloud backups and key accounts to stop attackers from accessing backups or linked services.
- Enable Two-Factor Authentication Everywhere:
Turn on two-factor authentication on your cloud and email accounts if not already active to add an extra layer of security.
- Notify Your Mobile Carrier and Authorities:
Inform your mobile carrier to suspend your service if necessary, and consider filing a police report—particularly if personal data is at risk.
- Set Up Passkeys on a New Device:
After securing your accounts, configure passkeys again on your new or restored device.
For example, if you lose your phone, use your computer to log into your cloud account, erase the phone remotely, reset passwords, and then set up passkeys on a new device. Acting swiftly helps prevent misuse of your accounts.
What Are the Limits of Passkey Security and What’s Next?
Passkeys reduce common risks like phishing and password reuse, but they rely on how well you protect your devices and cloud accounts. If those are compromised, passkeys can still be stolen.
Not all websites and devices support passkeys yet, so you may still need passwords for some services. Over time, more platforms will adopt passkeys, improving overall security.
Meanwhile, maintain good security habits—strong device locks, cautious app use, and monitoring accounts—to keep your digital identity safe. Multiple layers of protection remain your best defense.
Frequently asked questions
Can malware steal my passkeys without physical access to my device?
Yes. Malware can extract passkeys from your device and send them to attackers. Protect your device by installing apps only from trusted sources, keeping software up to date, and avoiding suspicious downloads.
What should I do if I suspect my cloud backup was hacked?
Immediately change your cloud account password, enable two-factor authentication if you haven’t already, review recent activity for unauthorized access, and contact your cloud provider’s support for help.
Are passkeys completely immune to phishing attacks?
Passkeys make phishing attacks much harder because they require cryptographic proof only your device can generate. However, always be cautious about links and websites to avoid other scams.
Can I use passkeys on multiple devices?
Yes. Many systems let you sync passkeys securely across your devices using cloud backups. Protect your cloud account strongly to keep passkeys safe on all your devices.
How do passkeys improve privacy compared to passwords?
Passkeys never send secret passwords over the internet or store them on servers. Each login uses a unique cryptographic message, so intercepted data can’t be reused to access your accounts.