Offizielles MASTR Logo MASTR
Menü

Namen, Identität und Web-Inhalte

Passkeys and crypto wallets: easier login, a new recovery map

The origin-bound credential, the account’s authority and the backup system need separate inspection.

Aktualisiert am 30. September 2026 · MASTR Labs

Artikeltexte und technische Grafiken sind auf Englisch. Die Navigation ist in 7 Sprachen verfügbar.

Fachartikel
  1. What a passkey changes
  2. Login is not the same as spending authority
  3. Device-bound or synchronised?
  4. Questions worth answering before funding
  5. Konkretes Beispiel
  6. Quellen und Originale

What a passkey changes

WebAuthn lets a relying party authenticate a user with a public-key credential scoped to that party. The authenticator signs a challenge; the server verifies it using the registered public key. The credential is not a shared password that a lookalike website can simply collect and reuse. Origin and relying-party checks are central to that protection. They do not validate the economic meaning of every action a signed-in application proposes. 1

Login is not the same as spending authority

A passkey might only log you into a portfolio service. In another product, it may authorise actions for a smart account or help unlock locally stored wallet material. Those architectures have different failure modes. Ask exactly which signature the chain accepts, which component translates the authentication result and which alternative keys or guardians can change account control.

Device-bound or synchronised?

Some credentials are tied to a device; others can be backed up and synchronised through a credential provider. The provider’s account recovery process then becomes relevant to regaining access. A wallet can also have its own recovery route independently of the passkey. ‘No seed phrase’ describes an interface choice, not the absence of a recovery dependency. WebAuthn exposes backup-related properties, but the complete product design still matters. 1

Questions worth answering before funding

Identify the relying-party domain, the device or sync provider, the smart-account address if applicable, and every route that can install a new signer. Confirm whether access survives a lost phone, a disabled cloud account and disappearance of the wallet website. Keep the distinction between authentication and authorisation visible: successfully proving who controls a credential does not establish that a requested transfer is sensible.

Map authentication to actual authority
Erklärende Grafik. In voller Grösse öffnen. Credits ↗ A convenient login does not describe the entire custody model.

Konkretes Beispiel

A passkey signs you into a dashboard, while a hardware wallet still signs transactions. Losing the passkey blocks the dashboard until account recovery; it does not automatically remove control of the hardware wallet. A passkey-controlled smart account can have a different outcome. The product architecture decides.

Quellen und Originale

  1. W3C: Web Authentication Level 3
  2. ERC-4337: account abstraction

Weiterlesen

Namen, Identität und Web-Inhalte →

MASTR

Unabhängige Recherche unterstützen

Die Untersuchungen, Originalbelege und Anleitungen hier sind frei zugänglich. Freiwillige Spenden finanzieren die Recherche mit und helfen, die MASTR-Tools weiterhin anzubieten.

Wallet öffnen