New Pass-ta-key Malware Attacks Put Google-Synced Passkeys at Risk — What to Know 

New Pass-ta-key Malware Attacks Put Google-Synced Passkeys at Risk — What to Know 

Researchers found three ways malware could abuse Google-synced passkeys on infected Windows computers. Here’s what the attacks mean and how you can better protect your accounts and personal data online.

What Happened?

According to BleepingComputer, Palo Alto Networks’ Unit 42 reported three new attacks on August 3, 2026. Researchers call them Pass-ta-key attacks.

The attacks target Google Password Manager passkeys synced through Chrome on Windows computers with a Trusted Platform Module, or TPM. A TPM is a security chip that protects digital keys.

Passkeys let you sign in using your device, fingerprint, face, or PIN instead of typing a password. The attacks do not crack passkey encryption. Malware must already be running on the computer.

Researchers said the malware could then abuse how Google handles trusted devices, account recovery, and synced passkeys. Unit 42 reported the findings to Google and affected websites.

eBay fixed a user-verification problem after researchers showed the first attack could work on its website. The same test failed on GitHub because it checked the verification correctly.

BleepingComputer said Google had not responded when its story was published.

Malware can reach a computer through harmful downloads or phishing messages. These messages may look more convincing when criminals already have leaked personal details.

Many people do not know their information appeared in an earlier data breach. If you are unsure, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Could Be Affected and What Was at Risk?

The research focused on Google Password Manager in Chrome on Windows computers with a TPM. Other browsers and platforms were outside the main tests.

The reports did not identify a confirmed number of affected users. They also did not say criminals had used these methods in real attacks.

On an infected computer, malware could identify services where you saved passkeys and see the usernames linked to them. It could also target the private digital keys that prove your identity.

The first method worked during a controlled eBay test because the website did not fully check whether the user approved the sign-in. The same test failed on GitHub, which checked correctly.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How the Three Pass-ta-key Attacks Work

All three methods begin with malware already running on your Windows computer. Each method then targets a different part of Google’s passkey system.

1. Pass-ta-key Impersonates Your Trusted Computer

Malware uses the computer’s protected device identity to make a request that appears to come from your trusted PC.

Google may then return a valid sign-in response. The attack can work when a website fails to confirm that you approved the login.

This confirmation normally involves a PIN, fingerprint, or facial recognition.

2. Silver Pass-ta-key Adds an Attacker-Controlled Key

Malware forces Chrome to register the computer again with Google’s cloud system. During that process, the attacker adds a verification key they control.

Google may then treat the attacker’s key as proof that you unlocked the device. The attacker could later sign in from another computer.

3. Golden Pass-ta-key Targets the Master Key

The most serious method forces Chrome through another registration or recovery process. Malware then looks for the master key in Chrome’s memory.

That master key protects all passkeys synced through the Google account. If stolen, it could help decrypt current passkeys and passkeys added later.

Google removed the master key from Chrome’s internal logs after Unit 42 reported the issue. However, researchers said it still briefly appears in Chrome’s memory.

Unit 42 also said Google’s current system does not offer a way to rotate or revoke this master key.