BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Exploit FIDO Cross-Device Sign-In to Bypass MFA Security

Hackers Exploit FIDO Cross-Device Sign-In with Phishing and QR Code Attacks, Security Teams Urged to Enforce Phishing-Resistant Measures

  • A new phishing attack method targets FIDO key authentication by exploiting cross-device sign-in features.
  • The attack uses fake login pages and QR code relays to trick users into authorizing access for attackers.
  • The threat actor, known as PoisonSeed, has leveraged this method in recent campaigns aimed at stealing digital assets.
  • This technique does not exploit a protocol flaw in FIDO but downgrades authentication to a method susceptible to phishing when proximity checks are not enforced.
  • Security teams are advised to monitor for strange QR code logins, enforce device verification, and use phishing-resistant recovery options.

On July 21, 2025, Cybersecurity researchers revealed that attackers have developed a way to bypass protections offered by FIDO authentication keys by taking advantage of a cross-device sign-in feature used in many enterprise login systems. The attack works by tricking users into using their devices to validate fraudulent login attempts made from spoofed company portals.

- Advertisement -

According to findings from Expel, the technique centers on phishing emails that direct victims to fake company login pages, such as imitations of the enterprise Okta portal. When users enter their details on these sites, attackers relay the authentication request to the actual login page and trigger a cross-device sign-in, which returns a QR code. This QR code is sent back through the phishing site and presented to the victim, who may scan it using their mobile device, unknowingly allowing the attacker access.

Researchers Ben Nahorney and Brandon Overstreet noted that the method is part of adversary-in-the-middle (AitM) attacks. “The attacker does this by taking advantage of cross-device sign-in features available with FIDO keys,” they wrote. “However, the bad actors in this case are using this feature in adversary-in-the-middle attacks.” Expel attributes this activity to PoisonSeed, a group known for phishing campaigns that steal credentials and drain victims’ cryptocurrency wallets by distributing fake seed phrases.

The attack specifically targets situations where cross-device sign-in is not protected by strict proximity checks, such as Bluetooth or direct device connection. If hardware security keys are plugged directly into the device or if platform-bound authenticators (like Face ID) are enforced, the attack is ineffective.

Cross-device sign-in, explained by Passkey Central’s guidelines, lets users authenticate on one device by verifying their identity on another device that holds the digital key. Attackers exploit this feature by relaying QR codes quickly from the target system to the victim, who then unwittingly completes the malicious login process.

- Advertisement -

Expel also reported an incident where an attacker enrolled their own FIDO key after gaining access and resetting a victim’s password. To boost security, organizations are urged to verify the devices used during login, prefer same-device logins, monitor for unusual QR code logins, and use phishing-resistant account recovery. Visible security details such as device information and location can also help users spot suspicious activity.

Researchers emphasized the need for robust, phishing-resistant authentication at every step of user account management to prevent this type of exploitation.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BancaStato launches regulated crypto trading via Sygnum, Avaloq

Swiss cantonal bank BancaStato now offers regulated cryptocurrency trading through Sygnum's B2B platform and...

Alphabet’s AI spending surge boosts Micron, memory stocks 2%+

Alphabet raised its 2026 capital expenditure forecast by $15 billion, signaling strong demand for...

Coinbase’s ‘Everything Exchange’ Coming to Canada

Coinbase Canada CEO Eric Richmond confirmed the company is building its "Everything Exchange" for...

Tesla Earnings Preview: Capex, Margins, Robotaxi in Focus

Gene Munster expects Tesla to guide 2026 capital spending above $25 billion, with 2027...

Worldcoin’s 100 Wallets Hold 90% of Supply: Grayscale Filing

Grayscale’s SEC filing for a Worldcoin ETF reveals that 100 wallets hold roughly 90%...

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading