Video summary

Delete THIS Hidden App Before It Steals Passkeys

Main summary

Key takeaways

News and Commentary

Overview

The video warns viewers that passkey-based account security is being targeted in 2026 through malicious “hidden” apps and browser/extension-based attacks. It argues the threat is urgent and already broadly relevant due to mass passkey adoption.


Main Claims and Analysis

Passkeys can be exploited without “breaking” cryptography

The video frames passkeys as vulnerable not because the underlying cryptography is broken, but because they depend on a trusted authentication environment (browser/phone/app ecosystem). If that environment is compromised (e.g., via malware or malicious extensions), attackers may bypass passkey security.

Defcon 2025 research (as cited)

It cites researchers at Defcon 2025 claiming passkey authentication can be intercepted at the browser level using malicious extensions or malware that manipulate authentication flows.

What attackers can allegedly do

The video claims attackers can:

  • Register fake passkeys / create their own authentication on a victim’s account
  • Bypass biometrics and user prompts
  • Force re-registration of passkeys under attacker control
  • Maintain access even after account recovery attempts

Attack Vectors Described

1) “Pass to key” attack

Malware is claimed to silently cause the browser/cloud system to create/register valid passkey logins for the attacker, without triggering typical biometric/PIN prompts.

2) “Golden passkey” (master key) attack

Malware is claimed to extract a Google security-domain secret (described as a master encryption key) to decrypt and reuse synced passkeys across sites/devices, even after device recovery or restores.

3) Malicious phone apps / “banking Trojan” route

The video alleges trojans delivered via fake utilities (e.g., PDF readers, document managers, file managers) can:

  • Intercept verification codes and keystrokes
  • Overlay fake screens
  • Detect passkey usage and inject into authentication
  • Persist as trusted authenticators

It emphasizes that removing apps from app stores may not help if the malicious app remains already installed and active.


Evidence and Scale (As Presented)

  • The video cites large passkey adoption figures (from Google and a FIDO Alliance-style coalition) to argue there are billions of potential targets.
  • It claims that between Dec 2025 and Aug 2026, multiple malicious apps (some with tens of thousands of downloads) were identified and distributed.
  • It references named malware and reports (e.g., Anata trojan; mentions companies like Zscaler, Kaspersky, McAfee, ESET; and dark web pricing claims) to argue that stolen-credential markets are mature and growing.

Why the Video Says This Is Worse Than Password Phishing

The threat is framed as foundational compromise of authentication, not only credential theft:

  • Attackers may become “de facto owners” by controlling passkey registration and recovery pathways.
  • Changing passwords or re-registering passkeys may be insufficient if attacker-controlled authenticators persist.
  • It warns fraud may be automated (mentioning “ATS”-style screen automation), enabling unauthorized transfers shortly after authentication.

Recommendations Given (Four Immediate Actions)

  1. Delete suspicious apps Especially PDF/document/file utility apps or anything installed long ago but unused.

  2. Run phone security scans Android: Play Protect is mentioned. iPhone: update the OS.

  3. Harden the cloud account used for passkey sync Use a strong unique password, advanced protection, and possibly a hardware security key.

  4. Prefer authenticator apps over SMS for 2FA.

Additional guidance mentioned

  • Review app permissions
  • Keep the OS updated
  • Be cautious with “security/cleaner” apps
  • Monitor bank statements/alerts
  • Consider credit freezes
  • Use unique passwords/password managers
  • Avoid unsolicited links

Overall Conclusion

The video’s thesis is that passkeys are not universally safe due to malware/extension attacks that can create attacker-controlled “trusted” authentication flows. It urges immediate defensive steps and argues that passkey ecosystems must be hardened at the browser/OS level and by providers to reduce this class of attack.

Key takeaway: The risk is largely framed as compromise of the trusted authentication environment, not failure of passkey cryptography alone.


Presenters / Contributors

  • Shya Prtap Singh (Square X)
  • Daniel Cedo (Square X)
  • Jonathan Lynn (Square X)

Mentioned Organizations / Companies

  • Square X
  • Defcon
  • Google
  • Microsoft
  • Apple
  • PayPal
  • Amazon
  • IBM
  • FIDO / Fhdo Alliance (referred to as “Phto Alliance” in subtitles)
  • Zscaler
  • Kaspersky
  • McAfee
  • ESET
  • Spec Ops threat intelligence team
  • Scalar

Original video