Connect with us

NEWS

Spotify Builds Passkey Login Years After a 380-Million-Record Breach

Spotify’s Android app hides passkey setup code, surfacing months after a public tracker named it among major apps still missing passkey login.

Published

on

Spotify’s Android app is quietly holding code for passkey login, an APK teardown found, months after a new watchdog site publicly listed the company among the internet’s biggest passkey holdouts. Android Authority reporter Tushar Mehta found an internal setting for passkey authentication, plus code built to start registering one. Neither function works in the live app yet.

The find lands on top of real history. A 2020 credential-stuffing attack hijacked an estimated 300,000 to 350,000 Spotify accounts, and the company still sits among the one in four major services that have not added passkeys at all.

Code Buried in the App Points to a New Sign-In Option

Spotify currently offers five ways to sign in: email address, phone number, Apple ID, Google account, or Facebook account. A passkey is not one of them. Passkeys are a passwordless method that swaps a typed password for a device’s fingerprint scanner, face scan, or screen lock.

Mehta’s teardown of the Android app found two specific pieces of evidence. One is an internal setting that would switch on passkey authentication. The other is code that appears designed to walk a user through registering a passkey with their Spotify account.

Android Authority was careful about how far the discovery goes. An APK teardown surfaces features still under construction inside an app’s code, but that code carries no guarantee of a public release. Spotify could change or drop the feature before it ever reaches a real login screen.

The gap was already conspicuous. Android Authority called it surprising that a service Spotify’s size had not adopted passkeys, given how quickly the login method has spread elsewhere. The teardown code suggests that gap is starting to close.

A Public List That Puts Spotify Next to Netflix and Instagram

A new site called whynopasskeys.com launched in June to track which major companies have added passkey login and which have not. Spotify made the wrong list. TechCrunch reported that one in four major apps still lack passkeys, with Spotify named alongside Netflix and Instagram.

The site runs entirely on public pressure.

A list is a surprisingly effective motivator. Nobody wants to be on the list.

Helme, the developer behind whynopasskeys.com, told TechCrunch. Apple, Google, and Microsoft already appear on the good side of that same list, all three offering passkeys across their major services.

Service Category Passkey Login Status
Spotify Music streaming In development, not yet live
Instagram Social media No native passkey support
Netflix Video streaming No native passkey support
Samsung Accounts and devices No native passkey support
Apple Devices and services Passkeys supported
Google Web services Passkeys supported
Microsoft Software and services Passkeys supported

Identity and device companies got there first. Entertainment and social apps are still catching up.

The Breach That Still Shadows Spotify’s Password Login

Spotify’s password problem has a paper trail. In 2020, researchers uncovered an unsecured database exposing 380 million records, and the leaked credentials were used to hijack an estimated 300,000 to 350,000 Spotify accounts through credential stuffing, according to ESET’s WeLiveSecurity.

The exposed data went beyond simple logins. Records included usernames, passwords, email addresses, and countries of residence, giving attackers everything needed to try those same combinations on other services too.

Credential stuffing works because people reuse passwords. Attackers take logins leaked from one breach and run them against a different company’s sign-in page, betting some users typed the same password twice. Security researchers describe it as a login hygiene problem more than a single hack, since reusing the same password across many services is what keeps the attack profitable.

Smaller leaks tied to Spotify accounts have surfaced periodically since then, though comprehensive recent breach statistics are hard to verify.

Account hijacking fights cost other companies too. Microsoft recently lost a hacked Xbox account case with twelve lawyers in a Brazilian court.

The Rest of the Internet Already Moved to Passkeys

While Spotify’s passkey code sat unfinished, the rest of the internet kept moving. FIDO Alliance, the industry group that maintains the technical standard passkeys run on, measured exactly how far the shift has gone in a December 2024 report.

  • 15 billion+ online accounts can now sign in with a passkey, more than double last year’s total, per FIDO Alliance
  • 45% of Tokyu Corporation’s TOKYU ID users have already switched to a passkey
  • 12 times faster sign-in speed for a passkey versus a password paired with an emailed one-time code

Tokyu Corporation runs transit and retail services in Japan. It is one of the companies FIDO Alliance cites as evidence the format works at consumer scale.

Password backups are struggling elsewhere too. SMS one-time codes, the fallback most services lean on, have been missing texts and timing out for Australian mortgage brokers relying on SMS authentication, a failure pattern that shows exactly why the passkey standard exists.

What Spotify Still Hasn’t Confirmed

Two things are solid. Several more are still open.

What we know:

  • Spotify’s Android app hides passkey setup code found in Android Authority’s teardown.
  • Spotify currently supports only email, phone, Apple ID, Google, and Facebook logins, and a passkey is not among them.

What is unconfirmed:

  • Whether Spotify has responded to requests for comment on its missing passkey support.
  • Any timeline, rollout region, or platform scope for a public passkey feature.
  • Whether the code ships at all, since Spotify could change or abandon the feature before release.

TechCrunch said it contacted Spotify for comment on the shame list and did not report a response either way. Spotify has not issued a public statement addressing either the list or the teardown. For now, the sign-in screen looks exactly like it did after the 2020 breach: a password field, and nothing else.

Frequently Asked Questions

When Will Spotify Launch Passkey Login?

There is no confirmed date. The passkey setting and registration code Android Authority found are unreleased and unfinished, and Spotify has not announced a rollout plan or commented publicly on its plans. Companies that add passkeys usually keep the old password option active as a fallback, so a launch would likely arrive as an additional choice on the login screen, not a replacement for existing options.

What Is a Passkey, and How Is It Different From a Password?

A passkey is a cryptographic credential tied to a specific device, unlocked with a fingerprint, face scan, or screen lock instead of typed characters. Because the credential never leaves the device as plain text, passkeys resist the phishing and credential-stuffing attacks that rely on stolen passwords working across multiple sites. The approach follows the FIDO2 and WebAuthn standards FIDO Alliance maintains.

Which Major Companies Still Do Not Offer Passkeys?

Spotify shares the list with Netflix, Instagram, Samsung, and others. Digital Trends counted seven of the top 25 most-visited sites still missing native passkey support when it reviewed the whynopasskeys.com tracker in June 2026.

Did the 2020 Breach Mean Spotify’s Own Systems Were Hacked?

Researchers linked the exposed database to credential-stuffing attacks that exploit reused passwords, meaning attackers used logins leaked from other, unrelated breaches to get into Spotify accounts. Spotify’s own servers were not identified as the source of that leak. Security researchers generally recommend unique passwords or a password manager as the strongest defense against this specific attack style.

Does Spotify Offer a Passwordless Option Right Now?

Signing in with an Apple ID or Google account can already inherit whatever passkey protection exists on those platforms, since both companies let users secure their own accounts with a passkey before ever reaching Spotify’s login screen. Spotify itself has no native passkey option live for any user yet.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending