Bitcoin rally takes a breather ahead of key U.S. employment data: Crypto Week Ahead
Capital B Buys 13 BTC, Bitcoin Treasury Hits 3,538 BTC
Analysis: Bitcoin shorts pay to bet on further declines, futures positions near yearly lows
Bitcoin bears pay to bet on further declines as futures positions near yearly lows
Circle co-founder Sean Neville has stepped down from stablecoin issuer's board,
617 $BTC (51,109,319 USD) transferred from Coinbase Institutional to unknown wallet...
Capital B acquired 13 bitcoin:native for $1.1 million, bringing its total holdings to
Scammers steal $2M in ETH as fake GIWA network fools DYORSWAP
Strategy Inc. Surpasses First Abu Dhabi Bank in Market Capitalization Amid Bitcoin Investments
What Crypto Is Actually Building While Prices Rise
106,335,859 $USDT (106,394,450 USD) transferred from #OKEX to unknown wallet...
$84,000 Fulcrum: Why Bitcoin is Refusing to Break
Bitcoin Braces for a Volatile Week as Key U.S. Economic Data Looms
Bitcoin Rally Wobbles as Macro Risks Overshadow ETF Demand
Bitcoin drops under $83K as liquidity hunting keeps bulls from targeting yearly open
799 $BTC (66,381,984 USD) transferred from unknown wallet to Coinbase Institutional...
Gate.io's Traditional Finance Desk Achieves $17 Billion in September Trading Volume
Bitget has resumed phased withdrawals after its $387.5 million exploit, with 6,878
XRP ETFs Hoard 1.18 Billion XRP as Ripple Readies a 1 Billion Unlock
736 $BTC (61,072,188 USD) transferred from unknown wallet to Coinbase Institutional...
'It's Really Not Just a Blockchain Anymore': Buterin's 2030 Ethereum Vision
XRP Breaches the $1.50 Wall: Is $2 in the Bag?
Circle’s CFO and a Co-Founder Depart, With $1.05M Exit Package for the CFO
Stablecoin payments firm RedotPay says it received a "clean" audit opinion from a Big
bitget ANNOUNCES IT “HAS BEGUN THE PHASED RESUMPTION OF WITHDRAWALS FOLLOWING THE SECURITY...
MEXC responds to user's ~$340,000 asset theft, has set up a special task force to provide solutions
Separately, @ai_9684xtpa reported that 2,042.28 BTC, worth about $169 million, has been transferred...
Bitget Reopens BTC Withdrawals After September 24 Security IncidentBitget said it has begun a...
Bitcoin ETFs Experience $2.4 Billion Inflow in Record Week
Bitwise Advances Spot NEAR ETF Toward NYSE Arca Listing, Sending NEAR to a One-Year HighRead...
Money supply across the US, eurozone, China and Japan hit a record...
Bitget starts phased withdrawal resumption following $388 million exploit
Xie Jiayin Responds to Bitget's First Security Incident in 8 Years: Hackers Exploited a Vulnerability in a Third-Party Security Product, Independent Review Launched with Security Firms
Bitcoin ETFs draw $2.4B in biggest inflow week since October 2025
Crypto ETF Flows: Bitcoin, Ether and Solana Funds Add $308M…
Donald Trump Oval Office Speech Today at 2 PM: What to Expect
Bitget has opened BTC withdrawal services as scheduled
The CLARITY Act failed because Democrats opposed President Trump more than they...
Upbit crypto exchange reported a weekly volume of $11.7 billion in week ended Sept.
California Governor Gavin Newsom Signs Law Banning Public…
Quant rises after The Clearing House selects it for On Chain Money Initiative and UK banks...
Bitcoin Price Crashes to $82,780 as Gold and Silver Lose $550B in Hours
4 Major Events to Watch for Bitcoin and Crypto Markets This Week
RedotPay Delays US IPO to 2027 Following Financial Audit and Legal Challenges
XRP Ledger’s Batch Upgrade Slips From September 29 to…
Crypto Sentiment Flipped“F&G has moved from around 30 to 74 in a relatively short period, while...
RedotPay completes financial audit as it presses ahead with U.S. IPO plans
BitMine's MAVAN Emerges as Key Revenue Driver with $357 Million Projection
A newly created wallet "0x80Fa" just withdrew 10,390 $QNT($2.87M) from...
THORChain Rejects Bitget’s Call to Block Attacker Funds After $387.5M HackTHORChain responded to...
Fake GIWA Chain Drained 766 ETH After 1,335 Addresses Bridged Into It
BlackRock Says AI Agents Could Become Crypto’s Next Demand Engine
616 $BTC (51,101,051 USD) transferred from Coinbase Institutional to unknown wallet...
Bitget hacker is swapping ETH for BTC via THORChain
Strategy to Hold Online Special Shareholders' Meeting on October 28
The #Bitget hacker, who stole $351.6M, is now swapping $ETH for $BTC through...
Vitalik Buterin Says Hegota Will Be Ethereum's Last 'Normal' Fork
The CLARITY Act failed because Democrats opposed President Trump more...
South Korea Considers Lifting Crypto Market-Making Ban to…
Hangzhou Yushu Robotics Increases Registered Capital to 25.1 Million Yuan
Aave Founder Envisions Expansion of Collateral Assets to Include Renewable Energy and Technology
799 $BTC (66,509,492 USD) transferred from unknown wallet to Coinbase Institutional...
Apple, Nvidia and Tesla Tokenized Stocks Can Now Back USDC Loans on Aave
NEAR Price Climbs as Bitwise ETF Gets Green Light: $155 Target Sparks Fresh Rally
Binance Wallet Removes Native Gas Token Requirement With…
THORChain Rejects Bitget CEO’s Request to Block $387.5M Hacker Wallets
Bitcoin Price Today: BTC Slips to $83,200 After a Quiet Weekend
Unitree's Hangzhou robotics subsidiary increases registered capital 250-fold, from 100,000 yuan to 25.1 million yuan
Orca API: 14 keyless endpoints, no candles, no trade feed
Passkeys vs. Passwords and 2FA: a New Era of Crypto Wallet Security
For users of digital services — especially crypto services — it is important to ensure strong account protection while keeping access convenient. The system should prevent credential forgery, work across different devices, and not complicate everyday use of the service.
At the same time, one of the main vulnerabilities of accounts and wallets is still tied to passwords — users have to create, remember, and store a secret combination themselves, and access to the service depends on it.
This model has a fundamental flaw — the password is known to both the user and the system that must verify it at login. That means it can be stolen via phishing, obtained after a database leak, or coaxed out through social engineering. The result can be an account takeover, and in the case of crypto services — also the risk of losing funds.
Passkey technology offers a different approach — instead of a shared secret, it uses cryptographic keys. The user does not need to send a password to the service on every login.
How Passkey Technology Works


Passkey is based on asymmetric cryptography. The system verifies not knowledge of a shared secret, but possession of the corresponding private key. A separate key pair — public and private — is created for each service. The public key is sent to the service and allows it to verify a cryptographic signature. The private key remains inaccessible to the service — depending on the implementation, it is stored on a single device or synchronized across the user’s devices in encrypted form.
- key generation and usage are managed by the system authentication mechanism or a credential manager. The storage method depends on the platform — the passkey may remain on a single device or be synchronized via secure storage;
- the website or app does not receive the private key — all cryptographic operations are performed on the authenticator or credential manager side after user confirmation;
- using a passkey is usually confirmed directly on the device using a PIN, device unlock password, or biometrics. SMS, one-time codes, and other two-factor authentication methods can be applied separately by the service — for example, when adding a passkey, restoring access, or confirming specific actions;
- sign-in uses a “challenge — response” scheme — the service generates a one-time challenge, which the authenticator signs with the private key. The service then verifies the signature using the public key.
The private key is not transmitted anywhere during this verification. For each sign-in, the service creates a new challenge that is signed on the user’s device — so intercepting a previously obtained signature by itself does not allow it to be reused for authorization.
Another important feature of passkeys is that credentials are bound to a specific service via the Relying Party identifier (RP ID). The browser and authenticator also verify the origin of the request — thanks to this, credentials created for a legitimate site cannot be arbitrarily requested from another domain, including a phishing one.
What standards are behind passkey
The technology is based on the FIDO2 standard, which includes two core components:
- WebAuthn — a web standard for creating and using cryptographic credentials via browsers and apps. It is developed by the World Wide Web Consortium (W3C). On August 25, 2026, WebAuthn Level 3 received W3C Recommendation status;
- CTAP — a protocol for client interaction with external authenticators. These include, for example, physical security keys connected via USB, NFC, or Bluetooth.
Together, WebAuthn and CTAP form the foundation of FIDO2. The former standardizes the use of cryptographic keys in browsers and apps, while the latter covers how the client interacts with external authenticators. Thanks to these standards, passkey can be used across different browsers, operating systems, and apps. At the same time, the exact process of creating a key and signing in depends on the platform and the service itself.
How to enable passkey in apps
In most services, you can enable passkey in your account security settings. Typically, you need to complete a few steps:
1. Open your account settings.
2. Go to the “Security” or “Sign-in and authentication” section.
3. Select passkey or the access keys section.
4. Confirm key creation using Face ID, Touch ID, or your device PIN.
After you set up passkey, the service may use it for passwordless sign-in or as one of the ways to verify your identity — the exact flow depends on the implementation.
How keys are used and stored also varies by platform. In the Apple ecosystem, they can be synced via iCloud Keychain, while Google Password Manager lets you store passkey and move them between compatible devices and platforms. Crypto apps and exchanges may use this technology to sign in to an account, add an extra user check, or confirm specific actions.
When setting it up, it is also important to plan a backup access recovery method — you will need it if the user loses their device, replaces it, or loses access to the account used to sync the keys.
How passkeys are stored and what limitations the technology has
The likelihood of losing access when using a passkey largely depends on how the key is stored. Syncable keys can be restored via a credential manager, while keys created for a single device only remain tied to the corresponding authenticator.
In practice, there are several ways to store keys and restore access:
- hardware keys. These are physical authenticators that support USB, NFC, or Bluetooth. The passkey remains tied to a specific device — losing it can result in loss of access if the user has not added another passkey or a backup recovery method in advance
- cloud sync. Passkeys can be stored in encrypted form in credential managers, including Apple iCloud Keychain and Google Password Manager. After confirming access to the account, such keys become available on the user’s other compatible devices
- backup access methods. Some services allow you to create multiple passkeys on different devices or authenticators — and may also provide a separate account recovery mechanism.
So, a passkey on its own does not eliminate the risk of losing access — a lot depends on the type of key, how it is stored, and the recovery rules set by the specific service.
How passkeys differ from other security methods
Modern security mechanisms solve different tasks — some verify the user’s identity, others protect cryptographic keys or define rules for managing a blockchain account. That’s why it’s not always correct to directly pit them against each other.
2FA and MFA
Two-factor and multi-factor authentication involve using several independent verification methods. This can be a combination of a password, a device, biometrics, a one-time code, or a cryptographic key.
Advantages:
- to gain access, an attacker must compromise multiple factors
- most common variants of this protection are supported by many services and devices.
Disadvantages:
- SMS and one-time codes remain vulnerable to phishing and attacks where an attacker intercepts data at the moment of login
- the reliability of the protection depends on the specific combination of factors
- 2FA and MFA regulate access to an account, but on their own they do not define the mechanism of ownership of cryptocurrency assets.
MPC (Multi-Party Computation)
MPC makes it possible to distribute control over a cryptographic operation among multiple participants or separate parts of a secret — this approach can be used to sign transactions without storing the full key in one place.
Advantages:
- there is no single point whose compromise automatically reveals the entire key
- the technology makes it possible to sign transactions without reconstructing the full private key on a single device.
Disadvantages:
- implementation requires more complex cryptographic and technical infrastructure
- for the scheme to work, interaction must be ensured between its participants or individual components.
Account abstraction
Account abstraction (Account Abstraction) makes it possible to define programmable rules for authorization and managing a blockchain account.
Advantages:
- allows you to flexibly configure wallet management rules
- can support different signing and access recovery mechanisms.
Disadvantages:
- capabilities depend on the specific network, the account implementation, and smart contract logic
- the technology itself does not define a specific user authentication method and makes the wallet architecture more complex.
All these mechanisms operate at different layers. Passkey lets you cryptographically verify a user’s identity, 2FA and MFA define verification rules using multiple factors, MPC distributes control over keys or the signing operation, and Account Abstraction lets you program rules for managing a blockchain account. That’s why these technologies may not compete, but rather complement each other.
How these technologies complement each other
Different security mechanisms can be combined within a single system — each one will be responsible for a separate task:
- passkey verifies the user’s identity using a cryptographic key that is stored on the device or synced via a secure credential manager
- MPC distributes control over the private key or signing across multiple components, eliminating a single point where the full secret is stored
- Account Abstraction lets you define wallet operating rules, including signing and access recovery conditions
- 2FA and a PIN code can be used as an additional check when recovering an account, adding a new device, or performing certain operations.
Together, these technologies can form the foundation of a more flexible crypto wallet architecture. Passkey simplifies login and reduces reliance on passwords, Account Abstraction enables programmable account management rules, and MPC distributes control over keys or signing. In such a system, each mechanism handles its own part of the process — and security does not necessarily come at the cost of making everyday use more complicated.
How passkeys are used today
In crypto services, what a passkey is used for depends on the architecture of the specific product. On centralized platforms, the technology is typically used to log in to an account and confirm individual actions. In programmable wallets, such as Safe, WebAuthn credentials can also be involved in authorizing onchain operations.
That said, a passkey does not replace the blockchain’s underlying cryptographic model. In one service, it may be responsible only for granting a user access to an account — in another, it can become part of the signing or authorization mechanism inside a programmable wallet.
The technology is already used not only in experimental products — it is supported by major consumer ecosystems.
Apple and Google support passkeys as a passwordless login method with local, on-device confirmation. According to the FIDO Alliance, as of May 2026, there were around 5 billion active passkeys worldwide. In addition, 75% of respondents in the organization’s global survey said they had enabled the technology for at least one account.
In the crypto industry, passkeys are also used to log in to accounts and work with programmable wallets.
In the Trustee Plus wallet, before enabling a passkey, you need to turn on two-step verification via email or Google Authenticator. After that, the access key can be used as a separate method for everyday logins — the user confirms authorization using Face ID, Touch ID, or the device PIN. Overall protection, however, depends not only on the passkey, but also on the security of backup login methods and account recovery.
This approach makes it possible to stop entering a password all the time while also improving login resilience against phishing. However, the final security of a crypto wallet is still determined by the service’s overall architecture — including key storage, transaction confirmation, and access recovery mechanisms.
Сообщение Passkeys vs. Passwords and 2FA: a New Era of Crypto Wallet Security появились сначала на INCRYPTED.
Source: Incrypted