The FIDO Alliance's semi-annual report released Thursday documented a figure that would have seemed optimistic three years ago: over 2 billion consumer accounts are now protected by passkeys, the cryptographic credential standard that replaces traditional passwords with a pair of public and private keys bound to a user's device and biometric. The number represents roughly one in four internet users globally and a 400 percent increase since the beginning of 2024.
The Tipping Point That Changed Everything
The passkey story is, unusually for a security standard, also a story about user experience winning. Earlier authentication improvements — hardware security keys, authenticator apps, SMS codes — each added friction while solving parts of the security problem. Passkeys added no friction. A user authenticates with the same fingerprint or face scan they use to unlock their phone, and the private key never leaves the device. There is no password to remember, no code to type, no way to phish a credential that was never transmitted.
The decisive moment came in late 2024 when Apple, Google, and Microsoft simultaneously enabled cross-device passkey sync through their respective credential managers — iCloud Keychain, Google Password Manager, and Windows Hello Cloud. Suddenly, a passkey created on a MacBook was available on an iPhone and vice versa. The last practical objection — "what happens if I lose my device?" — was answered without requiring users to understand the underlying cryptography.
Where 2 Billion Accounts Live
The 2 billion figure is heavily concentrated in consumer platforms with geopolitical scale user bases. Google reported in May that 1.1 billion Google accounts now have at least one passkey registered — approximately 40% of its active user base. Apple has not released equivalent figures but estimates from FIDO Alliance member data suggest iCloud Keychain holds roughly 600 million active passkeys. The remaining hundreds of millions are distributed across financial services, e-commerce platforms, and enterprise single sign-on systems.
Enterprise adoption has been slower but is accelerating sharply. A survey of 1,200 IT security leaders conducted by the Ponemon Institute in April found that 58% had begun or completed passkey rollouts for internal employee authentication — up from 22% in the same survey 18 months earlier. The driver cited most frequently was not improved security per se but reduced helpdesk costs: password reset requests represent, on average, 20 to 30 percent of enterprise helpdesk ticket volume.
"We eliminated our password reset workflow entirely. Not reduced — eliminated. The helpdesk hours we recovered in the first quarter paid for the entire passkey deployment." — CISO, Fortune 500 financial services company (anonymized)
What Passkeys Still Cannot Solve
The security picture is not uniformly positive. Passkeys are highly effective against phishing — an attacker who tricks a user into visiting a fake login page receives nothing of value because the private key never leaves the device and the authentication challenge is domain-bound. But passkeys do nothing to protect against compromised devices: if an attacker gains access to a device and can bypass or clone biometric authentication, they gain access to all passkeys stored on it.
Researchers at ETH Zurich published a paper in March demonstrating that several consumer-grade fingerprint sensors used in Android devices could be fooled by 3D-printed replicas in a controlled laboratory setting — a finding that has renewed calls for certified biometric hardware standards in devices used for passkey authentication.
The Long Tail Problem
Despite the milestone, 2 billion is a fraction of the accounts that still rely solely on passwords. Older platforms, especially in healthcare, government, and legacy enterprise environments, face migration challenges that have nothing to do with technology — outdated identity management systems, procurement cycles measured in years, and regulatory approval processes that require extensive testing before any authentication change can be deployed. Security advocates are careful to celebrate the progress while noting that the 2 billion figure represents the easy part. The harder half of the internet is still ahead.
💡 The Nexalytics Take
With 2 billion accounts using passkeys, the traditional password is finally dying. By using biometric scanning instead of typed text, phishing is practically eliminated, though compromised and stolen physical devices still pose a significant risk.