Scams & malware

Can passkeys be phished?

Passkeys are one of the best security upgrades most people can make: type your details into a look-alike scam page and there is nothing for a scammer to steal. That part is still true. But in 2026, researchers documented a workaround — scammers do not attack the passkey, they attack the weaker backup logins sitting next to it. Here is how it works, in plain terms.

Why passkeys are hard to phish

A passkey replaces your password with a secret that lives on your phone or laptop and is tied to one exact website. When you sign in, your device checks the real web address before it does anything. Land on a look-alike scam page and the passkey simply refuses to work — there is no code or password for the scammer to grab and reuse.

That protection is real, and it is why passkeys are worth using. The catch is not the passkey. It is everything else your account still lets you sign in with.

The weak spot: your backup logins

When you set up a passkey, the older sign-in methods usually stay switched on — a password, a text-message code, an app code, or an email reset link. They sit there as a “just in case,” so you are not locked out if you lose your device.

Scammers know this. Instead of fighting the passkey, they steer you toward one of those weaker backups, because a code you can read or type is something you can be tricked into handing over. The passkey did its job; the scam just went around it.

The trick, in plain terms

The “downgrade” push: a fake login page quietly hides the passkey option and only offers “sign in with a code” or “use your password instead.” You follow along and enter the code — which the scammer types into the real site at the same moment.

The fake “security upgrade”: a message or pop-up says you must “re-register” or “add a new passkey.” Following it actually registers the scammer’s device on your account. And the help-desk call: someone posing as support asks you to read out a recovery code “to verify your identity.” In every case the passkey held — you were simply guided around it.

How to protect yourself

Be suspicious of any login that skips your passkey. If a page suddenly asks for a code or password when your passkey normally just works, stop, and open the site yourself from a bookmark or its app. Never read a code or recovery phrase to anyone — real support will not ask. And ignore “add a new passkey” prompts you did not start; only add passkeys from inside an app’s own settings.

Where a service allows it, turn off the weakest backups: drop text-message codes in favour of an app code or a second passkey. And keep your most sensitive files out of the login picture entirely — stored in encrypted storage on your own device, so even a hijacked online account exposes nothing.

Where Sealby fits in

Sealby keeps your private photos, notes, and files in a vault encrypted with AES-256 on your iPhone, unlocked only by you. It is not a login service and cannot manage your passkeys — and it does not claim to.

What it shares with good passkey habits is one idea: a lock is only as strong as its spare key. Keep what matters most behind a lock only you control, and treat any request to switch to a “backup” way in as a reason to slow down.

This is general education, not security advice. Scam tactics and account settings change over time and differ by service and device — check current, reputable sources and treat any unexpected sign-in step with caution.

Quick answers

Should I stop using passkeys?

No. Passkeys remain far safer than passwords, because there is no reusable secret to steal and they do not work on look-alike sites. The risk described here is in the weaker backup logins beside them, not in the passkey itself.

How do I know if a login page is real?

Do not judge by how it looks — scam pages copy the real thing. Open the site yourself from a bookmark or its app instead of following a link, and be suspicious if your passkey is suddenly skipped in favour of a code or password.

Someone asked me to read out a code. Is that ever okay?

No. A code sent to your phone or shown in an app is a key, not an identity check. Real support will never ask you to read one out. Anyone who does is trying to sign in as you at that moment.

What should I do if I already handed over a code or approved a prompt?

Act quickly. Open the real site or app, change your password, and check the list of signed-in devices or active sessions — remove any you do not recognise. Then review the account’s backup login methods and turn off the weakest ones.

← Learn

Your vault is waiting.

Download Sealby and protect what matters. Setup takes under a minute, and there’s no account to create.

Download on the App Store

iPhone & iPad · iOS 17+ · Free