Sun. Oct 11th, 2026

How Passkeys Could Replace Passwords and OTPs in Banking

ByJohan Shamshad

October 10, 2026 #Passkeys

Passkeys can remove the two most phishable objects in digital banking – reusable passwords and manually entered one-time codes. But replacing login credentials is easier than replacing payment authorization, account recovery and fraud controls.

Research current to October 8, 2026

The thesis
Passkeys can plausibly replace passwords and many OTP challenges in retail banking because they use domain-bound public-key cryptography instead of secrets that customers type or relay. The hard part is not sign-in. It is preserving transaction-specific authorization, secure recovery and fraud controls when the customer is tricked into approving a real payment.

The Core Question: Replace Which Authentication?

Banking authentication is often discussed as though it were one step. It is not. A customer may authenticate when opening the app, reauthenticate before viewing sensitive information, approve a new beneficiary, confirm a high-value transfer, add a device, or recover an account after losing a phone. Passwords and one-time passcodes are used across these moments for different reasons.

That is why the claim that passkeys will “replace passwords and OTPs” needs to be split into two questions. First, can a bank use a passkey instead of a password plus an SMS or app code to establish that the legitimate customer is present? In many cases, yes – and several large banks already do. Second, can the same passkey replace every transaction-specific approval and recovery control? Not automatically.

The distinction matters because a passkey is an authentication credential. A bank still has to decide what action is being authorized, whether the payment details presented to the customer are authentic, whether a new device should be trusted, and whether a customer who has lost every authenticator should be allowed to bind a new one.

How a Passkey Actually Works

A passkey replaces a shared secret with a public-private key pair. During enrollment, the customer device creates a credential for the bank. The bank receives the public key; the private key remains under the control of the customer’s authenticator or credential provider. At sign-in, the bank sends a fresh cryptographic challenge. The authenticator signs that challenge with the private key after the user unlocks it with a local biometric, device PIN or similar mechanism.

The key retail point is what does not happen. The customer does not type a reusable bank password into the website, and the bank does not receive the fingerprint or face scan. Wells Fargo, Bank of America and other institutions describe passkeys as using the same device unlock mechanism the customer already uses, while the biometric or PIN remains local to the device.

NIST’s current Digital Identity Guidelines classify properly configured passkey-style cryptographic authentication as phishing-resistant because the credential is bound to the legitimate relying party. NIST explicitly says manually entered out-of-band and OTP authenticators are not phishing-resistant: a fake site can capture the code and relay it to the real service in real time.

Figure 1. Password + OTP exposes reusable or relayable authentication values; a passkey signs a fresh challenge without sending the private key to the bank.

Why Password Plus OTP Is Still Structurally Phishable

Two-factor authentication improved banking security because stealing a password was no longer enough. But the most common second factors did not remove the underlying shared-secret problem. A password can be phished, reused or leaked. An SMS or app OTP can be socially engineered, intercepted, or entered into a lookalike page and immediately relayed.

Under PSD2, the European Banking Authority has treated an SMS OTP as evidence of a possession factor when the bank can reliably associate the SIM or device with the customer. That makes SMS OTP legally usable in a strong-customer-authentication design, but legal compliance and phishing resistance are different properties. NIST’s current guidance is explicit that manual OTP entry is not phishing-resistant.

FIDO’s 2026 consumer survey suggests the usability barrier has also fallen. It reported roughly 5 billion passkeys in active use globally, 90% consumer awareness across the surveyed markets and 75% of respondents having enabled passkeys on at least some accounts. Banking no longer has to introduce an unfamiliar interaction; consumers increasingly encounter the same device-level ceremony in mainstream services.

Banks Have Already Started Replacing the Login

The transition is no longer theoretical, but implementations differ materially. The table below shows why “supports passkeys” is not the same as “passwords and OTPs are gone.”

 

 

Institution What the passkey replaces What still remains
Bank of America Passkey sign-in on verified devices Higher-value transfers can still trigger Secured Transfer or security-key controls.
Chase Passkey sign-in using face, fingerprint or device passcode Chase still offers extra sign-in security and one-time-code options.
Wells Fargo Passkey sign-in across supported devices Advanced Access / two-step verification may still be used for sensitive actions and transactions.
U.S. Bank Passwordless passkey sign-in on the website Rollout is gradual; U.S. Bank says passkeys are not yet available in its mobile app.
Banesco Passkey used to authenticate and confirm interbank transfers Moves passkeys beyond login into transaction approval; legacy dynamic-code methods still exist for some channels/actions.

This pattern is important. Banks are first removing the password from the easiest and most frequent authentication event – login – while keeping separate controls around higher-risk actions. That is a rational migration path: it reduces password exposure without immediately redesigning every payment and recovery workflow.

Banesco Shows the Next Stage: Passkeys for Transactions

Banesco Banco Universal provides a useful example of what a more complete migration can look like. The bank’s own documentation says its ‘Llave Banesco’ passkey is used to validate identity when customers make transfers to other banks. The customer confirms with the device’s fingerprint, face recognition or unlock PIN rather than receiving a code to type.

A May 2026 FIDO Alliance case study reports that 2.2 million Banesco users – about 92% of active users – regularly authenticate with passkeys, with 12 million passwordless transactions processed in the year and 8.3 million high-value transactions completed using passkeys. Those figures do not prove that passkeys eliminated fraud, but they do show that passkeys can operate at bank scale and in higher-value workflows rather than remaining a login convenience.

Figure 2. Banesco case-study scale. The high-value count may overlap with the broader passwordless transaction count, so the categories are not added together.

Authentication and Payment Authorization Are Different Problems

A passkey can prove that the holder of a registered credential is present. A payment system must answer a second question: what exactly did that person approve? This is where the banking use case becomes harder than ordinary website login.

European strong-customer-authentication rules illustrate the issue clearly. The PSD2 regulatory technical standards require strong customer authentication to use two or more elements from knowledge, possession and inherence. For remote electronic payments, the authentication must also be dynamically linked to the transaction: the payer must be shown the amount and payee, and the resulting authentication code or cryptographic assertion must be specific to those details.

A passkey can participate in that structure, but the word ‘passkey’ does not itself make a flow compliant. EBA guidance says public/private-key mechanisms can evidence possession when the key is uniquely bound to the user and device, while platform biometrics can function as inherence when the security conditions are met. The bank still has to maintain independence between factors and bind the customer’s approval to the transaction being authorized.

This is why the most credible end state is not simply ‘Face ID replaces the OTP.’ It is a cryptographic approval flow in which the customer sees the exact payment, locally unlocks the authenticator, and the bank receives evidence that is bound to the correct service and, where required, to the transaction context.

Figure 3. A bank can remove passwords from sign-in while still requiring transaction-specific authorization for money movement.

Visa and Mastercard Are Extending the Same Idea to Checkout

Card networks are pursuing a parallel model in e-commerce. Visa Payment Passkey is a FIDO-based authentication system intended to replace passwords and SMS one-time codes for card-not-present authentication. Mastercard Payment Passkeys similarly let a cardholder approve online purchases with the device’s fingerprint, face scan or PIN.

These products matter to banks because they show how passkeys can be embedded inside a transaction flow rather than used only to enter an account. They also reinforce the distinction between authentication and the underlying payment rails. The passkey does not settle money. It produces trusted authentication evidence that the issuer, network and merchant can use inside an authorization decision.

The Economics: OTPs Are Cheap Until the Bank Is Huge

Security is the primary reason to move away from OTPs, but the operating economics can reinforce the decision. SMS and voice codes have per-message costs, delivery failures create support contacts, and telecom dependence introduces latency and roaming problems. Passkeys require integration, lifecycle management and fraud engineering, but successful authentications do not require the bank to send a new secret every time.

Because bank messaging contracts vary widely, it is better to model the economics than to pretend there is one industry price. At an illustrative direct delivery cost of 1 to 5 cents per OTP, 12 million authentication events would cost about $120,000 to $600,000 a year in message transport alone. A bank with 5 million active digital users authenticating four times a month would create 240 million events, implying $2.4 million to $12 million at the same unit-cost range.

Those figures are not forecasts and exclude implementation costs, push notifications, support, fraud losses and negotiated carrier pricing. Their purpose is to show the scale effect: a control that costs only pennies can become a multimillion-dollar operating line when it sits in front of every login and transfer.

Figure 4. Illustrative direct messaging cost only. The model uses 1, 3 and 5 cents per OTP; actual bank pricing and channel mix vary.

The Hardest Problem Moves to Enrollment and Recovery

Removing passwords does not remove account takeover; it changes where attackers concentrate. If the private key cannot be phished from the customer, the most valuable targets become passkey enrollment, device binding, cloud credential recovery and bank account recovery.

Synced passkeys improve usability because a customer can recover credentials through an Apple, Google or other credential ecosystem and use them on multiple devices. NIST’s current guidelines accept syncable authenticators for use up to Authentication Assurance Level 2, while excluding them from AAL3 because their private keys must be exportable for synchronization. NIST also flags sync-fabric recovery as a potential weakness and recommends strong controls around adding new authenticators and notifying users of recovery activity.

For retail banking, that creates an architectural choice. A synced passkey may be appropriate for ordinary account access because recovery is easier and customers change phones frequently. A bank may prefer a device-bound passkey, hardware key, or additional bank-controlled step for especially sensitive business payments, high-value wires or administrator functions. The right answer depends on the risk tier, not on whether the bank wants a ‘passwordless’ marketing label.

Recovery deserves special attention because it can quietly reintroduce the weakness passkeys were meant to remove. A bank that uses phishing-resistant passkeys for daily access but lets an attacker reset the account with a weak SMS code and a few biographical questions has only moved the attack to a less visible endpoint.

Passkeys Do Not Stop Authorized-Push-Payment Scams

The biggest analytical mistake would be to treat passkeys as an all-purpose fraud solution. They are strongest against credential theft, phishing, replay and some forms of account takeover. They are much less effective when the legitimate customer is manipulated into approving a payment.

The ECB and EBA reported that payment fraud in the European Economic Area rose from €3.5 billion in 2023 to €4.2 billion in 2024, a 20% increase, even though strong customer authentication continued to reduce the fraud types it was designed to address. The joint report said manipulation of the payer accounted for more than half of the value of fraudulent credit transfers.

That is the boundary of passkey security. If a scammer convinces a customer that a transfer is necessary, the customer can use a perfectly valid passkey to authorize the wrong transaction. Banks still need confirmation-of-payee checks, behavioral and device risk signals, scam warnings, transaction limits, cooling-off periods where appropriate, and intervention for anomalous payments.

Threat Passkey effect Why
Credential phishing Strong No password or OTP is typed into a lookalike site; relying-party binding blocks simple relay.
Credential stuffing Strong No reusable password database credential exists for the attacker to reuse.
SIM swap / SMS interception Strong if OTP removed Authentication no longer depends on possession of a phone number.
Stolen unlocked device Mixed Security depends on device lock, local biometric/PIN, authenticator policy and bank risk controls.
Malicious passkey enrollment Weak unless controlled Bank must protect the process for adding a new authenticator.
Account recovery attack Weak unless controlled Recovery can become the new bypass if it falls back to weak evidence.
Customer tricked into real transfer Limited The legitimate user can still authenticate a fraudulent payment they were persuaded to make.

What Would Prove the Passwordless Thesis Wrong?

The first failure case is permanent fallback. If banks add passkeys but keep passwords and SMS OTP available to every customer indefinitely, attackers will simply target the weaker recovery or fallback channel. Security improves only when the old credential ceases to be a practical path into the account.

The second is weak enrollment. A phishing-resistant credential is not useful if an attacker can add their own passkey after passing an easily manipulated support flow. Banks need strong authentication for new-device binding, visible authenticator inventories, immediate alerts and rapid revocation.

The third is fraud migration. As account takeover becomes harder, criminals may devote even more effort to impersonation and authorized-push-payment scams. The EBA/ECB data already show why this matters. Passkeys can reduce one large attack surface while leaving the economics of social engineering largely intact.

The fourth is excessive dependence on consumer cloud accounts. Synced passkeys are convenient, but banks need to understand how Apple, Google and other sync ecosystems recover credentials and how that risk interacts with the bank’s own assurance requirements. High-risk banking may remain a mixed environment of synced passkeys, device-bound credentials, hardware keys and transaction-specific controls.

What Retail Customers Should Look For

Question Why it matters
Passkey available for sign-in? Removes the routine password from the most common attack path.
Can the old password be disabled? A weak fallback can preserve the phishing surface even after passkey enrollment.
How are transfers approved? A secure login does not guarantee that new payees or high-value transfers are transaction-bound.
How are new devices added? Malicious enrollment is one of the most important post-passkey attack paths.
What happens after phone loss? Recovery should use strong evidence and notify the customer immediately.
Can you view and revoke passkeys? Customers need a clear inventory of trusted authenticators and devices.

Bottom Line

Passkeys are capable of replacing the password-and-OTP combination for a large share of retail banking authentication because they remove the reusable secret and bind authentication to the legitimate service. The transition is already visible at Bank of America, Chase, Wells Fargo, U.S. Bank and other institutions, while Banesco demonstrates that the same model can move into transaction approval at scale.

But the end state is not ‘one biometric click secures everything.’ Banking needs more structure than ordinary website login. High-risk payments must still be tied to the correct amount and beneficiary; new-device enrollment must be protected; recovery must not become a backdoor; and fraud systems must detect situations where the real customer is being manipulated.

The real value of passkeys, therefore, is not that they make banks passwordless. It is that they allow banks to stop treating a phishable shared secret as the foundation of digital trust. The strongest future architecture is likely to be passkey-first access, cryptographically bound transaction approval, risk-based step-up controls and hardened recovery – with passwords and manually entered OTPs pushed to the margins rather than sitting at the center of the banking experience.

Methodology

The article distinguishes account authentication from transaction authorization. Bank implementation claims are based on current official support/security pages where available and on the FIDO Alliance Banesco case study for reported adoption metrics.

The OTP cost model is illustrative. It assumes a direct delivery cost of $0.01, $0.03 or $0.05 per authentication message and models 12 million annual events and 240 million annual events (5 million active users x 4 events per month). It does not include support costs, fraud losses, integration costs, negotiated carrier rates or non-SMS channels.

The 20% increase in EEA payment fraud is derived from the ECB/EBA reported totals of €3.5 billion in 2023 and €4.2 billion in 2024. The analysis does not assume that passkeys would have prevented all or most of that fraud; the same report explicitly shows the growing importance of payer-manipulation fraud.

Sources

1. NIST SP 800-63B-4 – Authentication and Authenticator Management
Phishing resistance, recovery and assurance.

2. NIST – Syncable Authenticators
Cloud-synced key security and recovery trade-offs.

3. FIDO Alliance – Passkeys
Core passkey properties and password/OTP replacement.

4. FIDO Alliance – Displace Password + OTP Authentication with Passkeys
Migration guidance for phishable MFA.

5. FIDO Alliance – State of Passkeys 2026
2026 adoption and awareness survey.

6. European Commission – Delegated Regulation (EU) 2018/389
PSD2 SCA and dynamic-linking rules.

7. EBA – Opinion on the Elements of Strong Customer Authentication
Knowledge, possession and inherence guidance.

8. EBA Q&A 2018_4039 – SMS OTP as Authentication Factor
SMS OTP treatment as a possession element.

9. EBA Q&A 2019_4532 – Cryptographic Validation and Possession
Device-bound keys as possession evidence.

10. EBA Q&A 2019_4651 – Platform Biometrics for SCA
Use of device biometrics in SCA.

11. ECB/EBA – 2025 Report on Payment Fraud
2024 fraud totals and payer-manipulation trend.

12. Bank of America – Passkey FAQs
Current passkey sign-in design.

13. Bank of America – Additional Security Features
Separate higher-risk transfer controls.

14. Chase – Security Tools and Passkeys
Passkeys plus extra sign-in options.

15. Wells Fargo – Passkey Questions
Storage, cross-device and stolen-device guidance.

16. Wells Fargo – Two-Step Verification
Continued OTP step-up for some actions.

17. U.S. Bank – Passkey
Gradual website passkey rollout.

18. Banesco – Llave Banesco
Passkey confirmation of interbank transfers.

19. FIDO Alliance – Banesco Case Study
2.2M users and reported transaction volumes.

20. Visa – Visa Payment Passkey
FIDO payment authentication replacing OTPs.

21. Mastercard – Payment Passkeys
Passkey approval for online purchases.

 

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape. You can reach out to him via his social media accounts:

Linkedin: https://www.linkedin.com/in/johan-shamshad-742851262/

X: https://x.com/Yasmine_FX

Investing: https://www.investing.com/members/contributors/279781574

Leave a Reply

Your email address will not be published. Required fields are marked *