We cracked the face-2FA engine behind 150+ banks — forged tokens pass validation
One facial-biometrics vendor quietly sits behind the 2FA selfie wall of more than 150 banks in 30+ countries. We reversed their public engine, and the results are uncomfortable: every captured 2FA token is decryptable, a
One facial-biometrics vendor quietly sits behind the 2FA selfie wall of more than 150 banks in 30+ countries. We reversed their public engine, and the results are uncomfortable: every captured 2FA token is decryptable, and tokens we mint offline validate as legit.
The setup
When a bank's online login asks you to take a selfie, it's usually not the bank doing the heavy lifting. A single vendor ships a small widget that runs entirely in the browser: it captures your face, produces an encrypted token, and hands it to the bank's backend.
Because the widget is a publicly served wasm engine, anyone can download it. We did.
What we found (teaser — full spec on request)
- The token is a pair. Every 2FA attempt posts two encrypted blobs — a selfie image and a face-template image. We broke the self-keying scheme: the key is derivable from data already sitting in the clear, seeded from a time value. Both blobs decrypt to the exact bytes the server saw (a JPEG selfie and a PNG template).
- Forged blobs read as legit. Because the key is derivable, we can mint fresh, structurally-valid token pairs that the server accepts. No camera, no face, no live user — just a well-formed encrypted blob.
- Per-tenant isolation is dead. The engine ships a license whitelist of 46-character keys embedded in the public wasm — including the vendor's own key and the keys of at least eight other corporate clients. Every tenant runs the same licensed engine.
- The anti-fraud check has a master off-switch. The current-generation "environment security" module is a case-sensitive keyword blocklist with a single bypass string shipped in the clear.
The headline deployment
One of the biggest deployments — Interbank (Peru), on a 2020-era build — has the entire 2FA barrier bypassable headlessly: no browser, no camera, no face, roughly 1-in-100 per attempt. And every biometric token recorded since the integration went live is decryptable.
Upgrading is not a free pass. The vendor's current 6.x line still embeds the license whitelist in a public wasm and still accepts a still (non-living) selfie at enrollment. A version bump alone doesn't close the door.
What we're selling
The full specification, a headless engine that reproduces the flow against a live tenant, and per-bank recon. We're selling to the vendor, to its bank clients, or to a single operator who wants first refusal.
Proof, scope, and a decryptable sample of your bank's token are available on request.
Contact: [email protected]
— El Peruano Loko, independent security research
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.