Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Did PoisonSeed bypass FIDO-protected sign-in? No successful bypass was established. Expel corrected its report after concluding that the evidence did not support its original claim: the victim’s password passed, but the later MFA challenges failed and the attacker did not gain access to the requested resource.
What Expel corrected about the PoisonSeed report
Expel published its original account on July 17, 2025, then issued a correction on July 25 after reviewing the evidence and discussing the event with security community members. Expel said its original interpretation—that the attacker had authenticated successfully and accessed the protected resource—was inaccurate. It wrote, “On further review, we found our original findings are unsupported by the evidence.” (Expel’s correction)
In Expel’s corrected account, PoisonSeed phished a user’s username and password, and the password factor passed. The user was then shown an attacker-supplied QR code. Scanning it began a FIDO Cross-Device Authentication flow, but the subsequent MFA challenges failed. Expel says Okta’s logs showed that the attacker was never granted access to the requested resource.
Dark Reading’s contemporaneous coverage records both the initial claim and its correction. The earlier account is historical context, not the final finding: the corrected report says the attempt did not succeed. (Dark Reading’s coverage and update)
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why the QR-code attempt did not establish a FIDO bypass
Cross-device authentication lets a person use an authenticator on one device to sign in on another. In the flow Expel described, scanning the QR code initiated a request that requires local proximity to the device running the WebAuthn client. Expel said that without proximity, a properly implemented flow times out and fails: “When properly implemented, without proximity, the request will time out and fail.”
The distinction matters: a QR code can start an authentication flow, but that alone does not mean the flow completed or that the protected account was accessed. In Expel’s corrected account, the password step passed; the later MFA checks did not.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What this incident says—and does not say—about passkeys
The corrected report does not establish a weakness in FIDO cryptography, passkeys, or security keys. It describes stolen password credentials and an attempted cross-device flow that failed its later MFA challenges. Yubico’s spokesperson, quoted by Dark Reading, likewise said: “Expel’s research does not demonstrate a flaw in the design of passkeys and is not a bypass of FIDO security keys.”
It helps to separate three parts of an authentication system:
Recommended Free Tools
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- The authenticator and protocol: the passkey or FIDO2 security key and the cryptographic sign-in process.
- The relying party’s implementation: how a service configures cross-device sign-in, verifies authentication, and permits fallback methods.
- Account lifecycle controls: how users enroll new authenticators and recover accounts if they lose access.
FIDO Alliance CTO Nishant Kaushik has argued that many reported passkey compromises involve weaknesses elsewhere in the operational environment rather than the passkey cryptography itself. That is the Alliance’s position, not a guarantee that every deployment is configured safely. (FIDO Alliance)
Why fallback, enrollment, and recovery still matter
Using passkeys does not automatically make every route into an account phishing-resistant. The FIDO Alliance warns that a service can weaken protection if it keeps a phishable password fallback, allows passkey registration after only phishable authentication, or relies on email or SMS alone for account recovery. An attacker who reaches one of those weaker paths may undermine the protection offered by the primary sign-in method. (FIDO Alliance guidance on passkeys)
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The Alliance recommends moving toward passkey-only protection where practical, potentially by user group or high-risk feature. A transition needs to account for usability and access needs, including how users enroll credentials and regain access when a device or authenticator is unavailable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How passkeys compare with other FIDO2 credentials
The UK National Cyber Security Centre (NCSC) concludes that FIDO2 credentials, including passkeys, offer greater security than traditional MFA against common credential attacks. Its comparison also distinguishes synced passkeys from FIDO2 tokens: synced passkeys can be available across devices through a synchronization system, while FIDO2 tokens cannot synchronize or export their credentials. These different storage and recovery models affect how an organization manages access and lost credentials. (NCSC guidance on choosing authentication methods)
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Neither label alone settles whether a real-world deployment is strong. Consider the credential itself alongside fallback sign-in, enrollment checks, recovery procedures, and the usability of the chosen approach. A physical FIDO2 security key is one option for phishing-resistant authentication; buying a key does not, by itself, fix weak password fallback or account recovery.
What defenders should take from the report
The reported QR-code attempt failed; it is not evidence that buying a security key would have prevented a successful PoisonSeed attack. The useful operational lessons are broader:
- Review identity-provider sign-in logs to distinguish a passed password from completed MFA and actual access to an application or resource.
- Understand how cross-device authentication is configured, including how the flow validates proximity and what happens when it times out.
- Audit password fallback, authenticator enrollment, and account recovery for routes that are weaker than the primary sign-in method.
- Plan passkey adoption around both phishing resistance and the practical needs of users who must enroll, replace, or recover credentials.
Expel said it would add clearer evidence and additional technical review to future posts. Its correction is the primary account of the report’s disposition; Dark Reading provides contemporaneous coverage. The full Okta logs and complete incident evidence package are not available in those sources, so claims withdrawn by Expel should not be treated as established findings.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

