The FIDO Downgrade Attack: When Passkeys Quietly Fall Back to Passwords

Attackers don't break passkeys — they convince the browser not to use them.

Attackers don’t break passkeys directly — they convince the browser not to use them, quietly falling back to passwords.

  • The attack targets the fallback path rather than the passkey cryptography itself.
  • When a stronger method is skipped, weaker password authentication takes over.
  • Defenders should watch where strong authentication can silently downgrade.

This briefing is part of SecureW2’s Cybersecurity Intelligence series, which tracks identity, certificate, and network-security events for the teams who have to respond to them.