---
title: "PoisonSeed Hackers Exploit Cross-Device Authentication to Bypass FIDO Keys"
url: https://daily.dev/posts/poisonseed-hackers-exploit-cross-device-authentication-to-bypass-fido-keys-cmeai2ox1
source_url: https://daily.dev/posts/poisonseed-hackers-exploit-cross-device-authentication-to-bypass-fido-keys-cmeai2ox1
type: collection
source: "Collections"
published: 2025-07-22T10:45:19.599Z
updated: 2025-07-22T10:45:35.087Z
tags: ["security", "cyber", "authentication", "phishing"]
reading_time: 1
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# PoisonSeed Hackers Exploit Cross-Device Authentication to Bypass FIDO Keys

**[Collections](https://daily.dev/sources/collections)** · 1 min read · 1 upvotes · 0 comments

## Summary

The PoisonSeed hacker group has developed a method to bypass FIDO hardware security keys by exploiting cross-device authentication features. The attack uses phishing emails to direct victims to fake login portals that capture QR codes for cross-device authentication, allowing attackers to gain unauthorized access without physical access to the FIDO key. Security experts recommend disabling cross-device sign-in features and implementing additional safeguards like Bluetooth proximity checks.

## Content

The PoisonSeed hacker group has developed a sophisticated method to bypass FIDO hardware security keys using social engineering tactics, specifically targeting cross-device authentication features. This approach allows attackers to complete authentication sessions without having physical access to the FIDO key itself.

The attack begins with phishing emails directing victims to counterfeit login portals that resemble legitimate enterprise sites such as Okta. Once users input their credentials, these fake sites relay the information to the actual portal and capture QR codes intended for cross-device authentication. By persuading users to scan these QR codes, PoisonSeed effectively gains unauthorized access to the users’ accounts. This turns a normally secure feature into a vulnerability, leveraging real-time relay attacks to intrude on protected sessions.

While the fundamental encryption capabilities of FIDO keys remain intact, the PoisonSeed technique highlights how alternative authentication mechanisms, like cross-device sign-in using QR codes, can be manipulated. Security experts suggest disabling these cross-device sign-in features wherever feasible and reinforcing security measures with additional safeguards such as Bluetooth proximity checks to prevent similar breaches.

This incident underscores the importance of vigilance and robust security practices, as even well-regarded security measures can become susceptible through clever exploitation of their operation processes.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/poisonseed-hackers-exploit-cross-device-authentication-to-bypass-fido-keys-cmeai2ox1)
