DEV Community

El Peruano Loko
El Peruano Loko

Posted on

We cracked the face-2FA engine behind 150+ banks — forged tokens pass validation

One facial-biometrics vendor quietly sits behind the 2FA selfie wall of more than 150 banks in 30+ countries. We reversed their public engine, and the results are uncomfortable: every captured 2FA token is decryptable, and tokens we mint offline validate as legit.

The setup

When a bank's online login asks you to take a selfie, it's usually not the bank doing the heavy lifting. A single vendor ships a small widget that runs entirely in the browser: it captures your face, produces an encrypted token, and hands it to the bank's backend.

Because the widget is a publicly served wasm engine, anyone can download it. We did.

What we found (teaser — full spec on request)

  • The token is a pair. Every 2FA attempt posts two encrypted blobs — a selfie image and a face-template image. We broke the self-keying scheme: the key is derivable from data already sitting in the clear, seeded from a time value. Both blobs decrypt to the exact bytes the server saw (a JPEG selfie and a PNG template).
  • Forged blobs read as legit. Because the key is derivable, we can mint fresh, structurally-valid token pairs that the server accepts. No camera, no face, no live user — just a well-formed encrypted blob.
  • Per-tenant isolation is dead. The engine ships a license whitelist of 46-character keys embedded in the public wasm — including the vendor's own key and the keys of at least eight other corporate clients. Every tenant runs the same licensed engine.
  • The anti-fraud check has a master off-switch. The current-generation "environment security" module is a case-sensitive keyword blocklist with a single bypass string shipped in the clear.

The headline deployment

One of the biggest deployments — Interbank (Peru), on a 2020-era build — has the entire 2FA barrier bypassable headlessly: no browser, no camera, no face, roughly 1-in-100 per attempt. And every biometric token recorded since the integration went live is decryptable.

Upgrading is not a free pass. The vendor's current 6.x line still embeds the license whitelist in a public wasm and still accepts a still (non-living) selfie at enrollment. A version bump alone doesn't close the door.

What we're selling

The full specification, a headless engine that reproduces the flow against a live tenant, and per-bank recon. We're selling to the vendor, to its bank clients, or to a single operator who wants first refusal.

Proof, scope, and a decryptable sample of your bank's token are available on request.

Contact: elperuanoloko@proton.me
— El Peruano Loko, independent security research

Top comments (0)