BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Exploit FIDO Cross-Device Sign-In to Bypass MFA Security

Hackers Exploit FIDO Cross-Device Sign-In with Phishing and QR Code Attacks, Security Teams Urged to Enforce Phishing-Resistant Measures

  • A new phishing attack method targets FIDO key authentication by exploiting cross-device sign-in features.
  • The attack uses fake login pages and QR code relays to trick users into authorizing access for attackers.
  • The threat actor, known as PoisonSeed, has leveraged this method in recent campaigns aimed at stealing digital assets.
  • This technique does not exploit a protocol flaw in FIDO but downgrades authentication to a method susceptible to phishing when proximity checks are not enforced.
  • Security teams are advised to monitor for strange QR code logins, enforce device verification, and use phishing-resistant recovery options.

On July 21, 2025, Cybersecurity researchers revealed that attackers have developed a way to bypass protections offered by FIDO authentication keys by taking advantage of a cross-device sign-in feature used in many enterprise login systems. The attack works by tricking users into using their devices to validate fraudulent login attempts made from spoofed company portals.

- Advertisement -

According to findings from Expel, the technique centers on phishing emails that direct victims to fake company login pages, such as imitations of the enterprise Okta portal. When users enter their details on these sites, attackers relay the authentication request to the actual login page and trigger a cross-device sign-in, which returns a QR code. This QR code is sent back through the phishing site and presented to the victim, who may scan it using their mobile device, unknowingly allowing the attacker access.

Researchers Ben Nahorney and Brandon Overstreet noted that the method is part of adversary-in-the-middle (AitM) attacks. “The attacker does this by taking advantage of cross-device sign-in features available with FIDO keys,” they wrote. “However, the bad actors in this case are using this feature in adversary-in-the-middle attacks.” Expel attributes this activity to PoisonSeed, a group known for phishing campaigns that steal credentials and drain victims’ cryptocurrency wallets by distributing fake seed phrases.

The attack specifically targets situations where cross-device sign-in is not protected by strict proximity checks, such as Bluetooth or direct device connection. If hardware security keys are plugged directly into the device or if platform-bound authenticators (like Face ID) are enforced, the attack is ineffective.

Cross-device sign-in, explained by Passkey Central’s guidelines, lets users authenticate on one device by verifying their identity on another device that holds the digital key. Attackers exploit this feature by relaying QR codes quickly from the target system to the victim, who then unwittingly completes the malicious login process.

- Advertisement -

Expel also reported an incident where an attacker enrolled their own FIDO key after gaining access and resetting a victim’s password. To boost security, organizations are urged to verify the devices used during login, prefer same-device logins, monitor for unusual QR code logins, and use phishing-resistant account recovery. Visible security details such as device information and location can also help users spot suspicious activity.

Researchers emphasized the need for robust, phishing-resistant authentication at every step of user account management to prevent this type of exploitation.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

China Aims to Boost Small Biz Loans With Blockchain

Chinese banking and tax authorities have directed financial institutions to adopt blockchain and privacy...

German Police ID REvil Ransomware Boss Behind $40M Hits

German authorities have identified Daniil Shchukin, 31, as the Russian threat actor “UNKN,” a...

Shiba Inu’s “Middle Age” Crisis: Collapse Risk Grows

Once dubbed "The Dogecoin Killer", Shiba Inu's price action has stabilized, leaving its wild,...

Kiyosaki: 1974’s economic shift fuels debt, retirement crisis

Robert Kiyosaki warns the financial changes initiated in 1974 are now creating inflation and...

Dogecoin (DOGE) Post a Notable Rebound, Experts Show More Interest In Taurox (TAUX) as It Opens Pre-KYA Registration

DOGE trades near $0.09 after a notable rebound. The official account’s April Fools’ corporate...

Must Read

Crypto in New York: The 2026 Guide to Legal Exchanges and BitLicense Regulations

TL;DR: Trading crypto in New York is legal but heavily regulated by the New York Department of Financial Services (NYDFS). Platforms must hold a BitLicense...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading