FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.8T -1.7%24h Vol $117.2B +70%Fear & Greed 74/100Alts Index 51/100
BTC.D 58.8% -0.1%Stable.D 9.4% +0.2%ETH.D 11.4% 0%Others.D 20.4% -0.1%
Q$0.0498+37.46%•BTW$1.148+23.58%•BP$1.510+20.63%•HBAR$0.1126+18.71%•QNT$204.93+15.49%•GRT$0.0318+13.84%•MARSCOIN$0.1466+13%•XDC$0.0340+11.13%•PUMP$0.00480225+8.67%•CASHCAT$0.1916+6.91%•
AI$0.2205-17.26%•PONS$0.5328-13.12%•FARTCOIN$0.1702-12.65%•USELESS$0.2528-12.39%•JTO$0.5558-12.38%•UNI$8.881-11.78%•BR$0.9088-11.77%•AR$4.259-11.5%•SENT$0.0209-10.74%•RAY$2.001-10.65%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Passkeys vs. Passwords and 2FA: a New Era of Crypto Wallet Security

      For users of digital services — especially crypto services — it is important to ensure strong account protection while keeping access convenient. The system should prevent credential forgery, work across different devices, and not complicate everyday use of the service.

      At the same time, one of the main vulnerabilities of accounts and wallets is still tied to passwords — users have to create, remember, and store a secret combination themselves, and access to the service depends on it.

      This model has a fundamental flaw — the password is known to both the user and the system that must verify it at login. That means it can be stolen via phishing, obtained after a database leak, or coaxed out through social engineering. The result can be an account takeover, and in the case of crypto services — also the risk of losing funds.

      Passkey technology offers a different approach — instead of a shared secret, it uses cryptographic keys. The user does not need to send a password to the service on every login.

      How Passkey Technology Works

      Passkey is based on asymmetric cryptography. The system verifies not knowledge of a shared secret, but possession of the corresponding private key. A separate key pair — public and private — is created for each service. The public key is sent to the service and allows it to verify a cryptographic signature. The private key remains inaccessible to the service — depending on the implementation, it is stored on a single device or synchronized across the user’s devices in encrypted form.

      • key generation and usage are managed by the system authentication mechanism or a credential manager. The storage method depends on the platform — the passkey may remain on a single device or be synchronized via secure storage;
      • the website or app does not receive the private key — all cryptographic operations are performed on the authenticator or credential manager side after user confirmation;
      • using a passkey is usually confirmed directly on the device using a PIN, device unlock password, or biometrics. SMS, one-time codes, and other two-factor authentication methods can be applied separately by the service — for example, when adding a passkey, restoring access, or confirming specific actions;
      • sign-in uses a “challenge — response” scheme — the service generates a one-time challenge, which the authenticator signs with the private key. The service then verifies the signature using the public key.

      The private key is not transmitted anywhere during this verification. For each sign-in, the service creates a new challenge that is signed on the user’s device — so intercepting a previously obtained signature by itself does not allow it to be reused for authorization.

      Another important feature of passkeys is that credentials are bound to a specific service via the Relying Party identifier (RP ID). The browser and authenticator also verify the origin of the request — thanks to this, credentials created for a legitimate site cannot be arbitrarily requested from another domain, including a phishing one.

      What standards are behind passkey

      The technology is based on the FIDO2 standard, which includes two core components:

      • WebAuthn — a web standard for creating and using cryptographic credentials via browsers and apps. It is developed by the World Wide Web Consortium (W3C). On August 25, 2026, WebAuthn Level 3 received W3C Recommendation status;
      • CTAP — a protocol for client interaction with external authenticators. These include, for example, physical security keys connected via USB, NFC, or Bluetooth.

      Together, WebAuthn and CTAP form the foundation of FIDO2. The former standardizes the use of cryptographic keys in browsers and apps, while the latter covers how the client interacts with external authenticators. Thanks to these standards, passkey can be used across different browsers, operating systems, and apps. At the same time, the exact process of creating a key and signing in depends on the platform and the service itself.

      How to enable passkey in apps

      In most services, you can enable passkey in your account security settings. Typically, you need to complete a few steps:

      1. Open your account settings.

      2. Go to the “Security” or “Sign-in and authentication” section.

      3. Select passkey or the access keys section.

      4. Confirm key creation using Face ID, Touch ID, or your device PIN.

      After you set up passkey, the service may use it for passwordless sign-in or as one of the ways to verify your identity — the exact flow depends on the implementation.

      How keys are used and stored also varies by platform. In the Apple ecosystem, they can be synced via iCloud Keychain, while Google Password Manager lets you store passkey and move them between compatible devices and platforms. Crypto apps and exchanges may use this technology to sign in to an account, add an extra user check, or confirm specific actions.

      When setting it up, it is also important to plan a backup access recovery method — you will need it if the user loses their device, replaces it, or loses access to the account used to sync the keys.

      How passkeys are stored and what limitations the technology has

      The likelihood of losing access when using a passkey largely depends on how the key is stored. Syncable keys can be restored via a credential manager, while keys created for a single device only remain tied to the corresponding authenticator.

      In practice, there are several ways to store keys and restore access:

      • hardware keys. These are physical authenticators that support USB, NFC, or Bluetooth. The passkey remains tied to a specific device — losing it can result in loss of access if the user has not added another passkey or a backup recovery method in advance
      • cloud sync. Passkeys can be stored in encrypted form in credential managers, including Apple iCloud Keychain and Google Password Manager. After confirming access to the account, such keys become available on the user’s other compatible devices
      • backup access methods. Some services allow you to create multiple passkeys on different devices or authenticators — and may also provide a separate account recovery mechanism.

      So, a passkey on its own does not eliminate the risk of losing access — a lot depends on the type of key, how it is stored, and the recovery rules set by the specific service.

      How passkeys differ from other security methods

      Modern security mechanisms solve different tasks — some verify the user’s identity, others protect cryptographic keys or define rules for managing a blockchain account. That’s why it’s not always correct to directly pit them against each other.

      2FA and MFA

      Two-factor and multi-factor authentication involve using several independent verification methods. This can be a combination of a password, a device, biometrics, a one-time code, or a cryptographic key.

      Advantages:

      • to gain access, an attacker must compromise multiple factors
      • most common variants of this protection are supported by many services and devices.

      Disadvantages:

      • SMS and one-time codes remain vulnerable to phishing and attacks where an attacker intercepts data at the moment of login
      • the reliability of the protection depends on the specific combination of factors
      • 2FA and MFA regulate access to an account, but on their own they do not define the mechanism of ownership of cryptocurrency assets.

      MPC (Multi-Party Computation)

      MPC makes it possible to distribute control over a cryptographic operation among multiple participants or separate parts of a secret — this approach can be used to sign transactions without storing the full key in one place.

      Advantages:

      • there is no single point whose compromise automatically reveals the entire key
      • the technology makes it possible to sign transactions without reconstructing the full private key on a single device.

      Disadvantages:

      • implementation requires more complex cryptographic and technical infrastructure
      • for the scheme to work, interaction must be ensured between its participants or individual components.

      Account abstraction

      Account abstraction (Account Abstraction) makes it possible to define programmable rules for authorization and managing a blockchain account.

      Advantages:

      • allows you to flexibly configure wallet management rules
      • can support different signing and access recovery mechanisms.

      Disadvantages:

      • capabilities depend on the specific network, the account implementation, and smart contract logic
      • the technology itself does not define a specific user authentication method and makes the wallet architecture more complex.

      All these mechanisms operate at different layers. Passkey lets you cryptographically verify a user’s identity, 2FA and MFA define verification rules using multiple factors, MPC distributes control over keys or the signing operation, and Account Abstraction lets you program rules for managing a blockchain account. That’s why these technologies may not compete, but rather complement each other.

      How these technologies complement each other

      Different security mechanisms can be combined within a single system — each one will be responsible for a separate task:

      • passkey verifies the user’s identity using a cryptographic key that is stored on the device or synced via a secure credential manager
      • MPC distributes control over the private key or signing across multiple components, eliminating a single point where the full secret is stored
      • Account Abstraction lets you define wallet operating rules, including signing and access recovery conditions
      • 2FA and a PIN code can be used as an additional check when recovering an account, adding a new device, or performing certain operations.

      Together, these technologies can form the foundation of a more flexible crypto wallet architecture. Passkey simplifies login and reduces reliance on passwords, Account Abstraction enables programmable account management rules, and MPC distributes control over keys or signing. In such a system, each mechanism handles its own part of the process — and security does not necessarily come at the cost of making everyday use more complicated.

      How passkeys are used today

      In crypto services, what a passkey is used for depends on the architecture of the specific product. On centralized platforms, the technology is typically used to log in to an account and confirm individual actions. In programmable wallets, such as Safe, WebAuthn credentials can also be involved in authorizing onchain operations.

      That said, a passkey does not replace the blockchain’s underlying cryptographic model. In one service, it may be responsible only for granting a user access to an account — in another, it can become part of the signing or authorization mechanism inside a programmable wallet.

      The technology is already used not only in experimental products — it is supported by major consumer ecosystems.

      Apple and Google support passkeys as a passwordless login method with local, on-device confirmation. According to the FIDO Alliance, as of May 2026, there were around 5 billion active passkeys worldwide. In addition, 75% of respondents in the organization’s global survey said they had enabled the technology for at least one account.

      In the crypto industry, passkeys are also used to log in to accounts and work with programmable wallets.

      In the Trustee Plus wallet, before enabling a passkey, you need to turn on two-step verification via email or Google Authenticator. After that, the access key can be used as a separate method for everyday logins — the user confirms authorization using Face ID, Touch ID, or the device PIN. Overall protection, however, depends not only on the passkey, but also on the security of backup login methods and account recovery.

      This approach makes it possible to stop entering a password all the time while also improving login resilience against phishing. However, the final security of a crypto wallet is still determined by the service’s overall architecture — including key storage, transaction confirmation, and access recovery mechanisms.

      Сообщение Passkeys vs. Passwords and 2FA: a New Era of Crypto Wallet Security появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud