A Palo Alto Networks Unit 42 report reveals three attack techniques (collectively called Pass-ta-key) that can compromise passkey-protected accounts by exploiting onboarding, recovery, and device trust workflows rather than breaking the underlying cryptography. The attacks require prior malware installation on the victim's device. Security analysts stress the vulnerabilities stem from weak implementation and support processes around passkeys — such as optional user verification and synced (vs. device-bound) credentials — rather than flaws in the passkey standard itself. Recommendations include enforcing server-side user verification, preferring hardware-bound keys (e.g., YubiKeys) for privileged accounts, and implementing ITDR systems to detect suspicious authenticator activity.