Passkeys promise stronger security by replacing passwords with public key cryptography, binding credentials to legitimate services, and keeping private keys off servers. That security proposition remains largely true, but the threat landscape has shifted rapidly. Researchers now document at least 39 publicly known attack methods, research techniques, and exploitation scenarios