FIDO Keys Hacked? Shocking New Phishing Technique Bypasses Top-Tier Security

Listen to this Post

Featured Image

Introduction: A New Cybersecurity Alarm Bell

In a shocking development, cybersecurity researchers at Expel have discovered a groundbreaking phishing technique that bypasses even the most robust FIDO key protections. The attack, orchestrated by the notorious PoisonSeed group, takes advantage of a little-known feature in cross-device sign-in protocols. This alarming tactic marks a major escalation in identity-based threats, challenging long-held beliefs about the invulnerability of physical security keys. With identity-based attacks now dominating the cybersecurity threat landscape, the discovery forces organizations and security experts to rethink their defenses and adapt quickly to a new kind of adversary-in-the-middle threat.

How the New Phishing Method Works

Cyber attackers are now exploiting a vulnerability in the very feature designed to enhance convenience: cross-device sign-in. The method begins with a standard phishing email directing users to a counterfeit login page disguised to look like the real thing. Once the victim enters their credentials, the attackers immediately relay that information to the genuine login portal and trigger a legitimate cross-device sign-in request. This triggers the creation of a QR code meant for authentication on a secondary device. Here’s where the trap is set: the phishing site instantly captures this QR code and displays it to the victim. Believing it’s legitimate, the user scans it using their authentication app, effectively completing the login process—but for the attacker.

This clever adversary-in-the-middle (AitM) exploit renders the FIDO

Expel’s Q1 2025 threat report highlights a concerning shift: 66.2% of security incidents are now identity-based, showing how attackers increasingly rely on psychological manipulation rather than purely technical exploits. Security professionals are urged to adapt, focusing more on monitoring patterns, such as unexpected geographic login attempts, strange FIDO key registrations, and sudden QR code requests. Experts recommend introducing geographic restrictions, Bluetooth-based verification requirements, and thorough auditing of authentication logs to detect anomalies early.

While FIDO keys still offer strong protection against traditional phishing attacks, they are no longer foolproof. The PoisonSeed group’s campaign proves that even cutting-edge tools can be exploited when human trust and convenience collide. The battle now moves from just stronger tech to smarter monitoring and awareness across organizations.

What Undercode Say:

Exploiting Trust in Security Systems

The PoisonSeed campaign doesn’t just exploit technical gaps—it targets user trust in secure systems. That trust, ironically, becomes the tool used against them. By mirroring legitimate login portals and using actual authentication workflows, the attackers create a nearly flawless illusion of legitimacy. This goes beyond ordinary phishing and into the realm of psychological cyber warfare.

The Blind Spot in Cross-Device Convenience

The cross-device sign-in feature was introduced to ease authentication across multiple devices, especially when passkeys are not directly available. However, it opened a backdoor most organizations didn’t anticipate. By hijacking the QR code in real-time and presenting it to the user, attackers essentially trick the victim into authorizing their own breach.

Bypassing the Unbreakable

FIDO keys were designed as the gold standard of phishing resistance. Yet, this exploit doesn’t “break” the FIDO key—it renders it irrelevant by sidestepping its protections. It’s not a flaw in the cryptographic model, but a manipulation of legitimate authentication flows that bypasses the key entirely. This shows how the battlefront has shifted from encryption to authentication architecture.

From Defense to Detection

Traditional prevention-based approaches are no longer enough. Organizations must adopt a detection-first mindset. This means real-time monitoring of authentication logs, unusual login patterns, and behavioral anomalies. Artificial intelligence and machine learning tools can assist by flagging deviations from normal user activity.

Multi-Layered Defense: Still the Best Bet

Despite the exploit, FIDO keys remain a vital part of modern cybersecurity. However, they must be layered with behavioral analytics, geo-fencing, and continuous user education. Relying solely on hardware tokens or QR-based validation is proving insufficient in today’s threat landscape.

PoisonSeed’s Larger Agenda

The PoisonSeed group has been tied to cryptocurrency phishing campaigns in the past. This evolution into exploiting cross-device authentication suggests a strategic shift toward more persistent and scalable identity attacks. It’s likely we’ll see this method adapted across different industries, especially where remote access and BYOD (Bring Your Own Device) policies are in place.

Mitigating the Next-Gen Threats

To defend against such nuanced attacks, organizations must enforce:

Geo-restrictions on cross-device sign-ins

Bluetooth-only pairing requirements for QR-based authentication

Time-based anomaly detection for simultaneous login attempts

FIDO key audit logs that flag rapid or bulk registrations

User alerts whenever a new device is authorized

The Human Element Remains the Weakest Link

At its core, this attack once again confirms the age-old truth of cybersecurity: humans are the most exploitable vector. Even with state-of-the-art technology, if users aren’t trained to recognize deceptive patterns, the defenses can crumble from within.

🔍 Fact Checker Results

✅ Confirmed Exploit: The phishing attack targeting FIDO key cross-device sign-in has been validated by cybersecurity firm Expel.
✅ PoisonSeed Attribution: The technique has been linked to the known group PoisonSeed, active in crypto-related phishing.
❌ FIDO Key Compromise: FIDO keys themselves are not broken, but rather bypassed through social engineering.

📊 Prediction

The success of this technique will inspire copycats, especially among state-sponsored groups and advanced persistent threats (APTs). Over the next 12 months, expect a surge in identity-based AitM attacks targeting QR-code workflows and mobile authenticator apps. Companies that rely heavily on QR sign-ins without multi-factor redundancy or behavioral analytics will face rising breach risks. As more attackers leverage the illusion of legitimacy, authentication architecture—not just hardware—will become the new battleground.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin