MagicEndpoint owl logo

MagicEndpoint · End-to-end cryptography

The most secure login is
no login at all.

The global industry gives the warning on AI-enabled attacks.
WinMagic gives the fix. Let us tell you how ↓

Your endpoint holds a key that exists only while you are there. It proves who you are on every connection. No password, no prompt, and no token for anyone to steal.

1 in 4 malicious breaches is already AI-enabled
+56% in one year
$6M average cost per AI-enabled breach
Source: IBM, July 2026
Why now

What is the biggest cybersecurity threat right now?

AI-enabled attacks. AI makes attacks faster, cheaper and far more convincing, and breach data already shows it.

The industry's warning

More than a thousand technology, security and financial organizations signed one letter urging the industry to act immediately: AI-enabled attacks will become far more widespread and sophisticated in the coming months, the window to strengthen defenses is limited, and the status quo will not be enough.

How do you fight AI attacks?

The industry's recommendation is more tooling. That will not cut it, because the flaw is in the tools. Cryptography is used everywhere in security, but in pieces. Online, cryptography is the best defense, and humans cannot do cryptography. So the endpoint does it for you, on every connection.

01Adversary-in-the-middle

The mother of all attacks.

What is an adversary-in-the-middle attack?

It is the one attack that defeats every login method in use today without breaking any of them. It lets the real person complete the real login, and takes what comes out of it.

A relay passes the real login through and keeps the result The person real user, real device The relay passes every byte The service real identity provider THE REAL LOGIN The attacker holds a legitimate session LOGIN PASSED the result

It breaks nothing. No vulnerability to patch. Both ends see a login that worked, because one did. A zero-day needs a flaw nobody has found yet. This one needs no flaw at all.

It beats every method. Password, one-time code, push, passkey. It takes the result, so the factor does not matter.

It leaves no signal. The attacker ends up holding a legitimate session.

AI removed its one cost. A lure convincing enough to fool a careful person is now close to free.

Proofpoint reported in December 2024 that almost half of all accounts taken over had MFA configured.

Why it is the hardest attack to stop

Why is adversary-in-the-middle the hardest attack to stop?

Because nothing in the exchange is false. A relay does not steal an identity. It steals the result of a real login, so a stronger way of proving who you are does not help.

The real person signed in. The real identity provider approved it. Neither of those says who is holding the token a second later.

Avoid it

Do passkeys and FIDO2 stop adversary-in-the-middle attacks?

Passkeys avoid the attack. They do not solve it. Passkeys, built on FIDO2, are what most phishing-resistant MFA rests on today: the browser checks that the site is the real one, and where that check holds, the relay is refused. But the check rests on many parts that all have to stay correct (the browser, names, certificates, enrolment, recovery), it is not there outside the browser, and the login still ends in a token that works for whoever holds it.

Solve it

How do you stop adversary-in-the-middle attacks?

Make the login produce a key that exists only on your endpoint and cannot be copied off it. Relay every byte and the attacker still holds nothing usable, because the part that matters never left the machine. That is what MagicEndpoint does.

02The solution

What is the best defense against AI cyberattacks?

End-to-end cryptography, starting at the login: a login that produces a key, with the party you are about to talk to.

Nothing in use for online access today does it. Passwords, multi-factor and passkeys all end in a verdict that the login succeeded, and something agreed separately protects what follows. That seam is what AI-enabled attacks exploit. We published this flaw in 2024, before AI made it urgent.

The private key stays on the endpoint; the service holds only the public key

How does mutual TLS secure a login?

In mutual TLS, both sides prove who they are in one handshake, and that same handshake produces the key that protects everything they say next. Machines have worked this way for decades. It never reached people, because it asked them to carry cards and handle certificates. What was missing was a key that could stand for a person. The endpoint provides it.

That is the whole picture

You and your endpoint one key, held in hardware
The service takes your identity from the connection
The handshake is the login. The connection is the session. No token and nothing handed across a gap, so there is nothing left for a relay to take.
03Available now

How do you strengthen login against AI attacks without replacing Entra ID, Okta or Ping?

Three moves, one for each part of online access. None of them waits for an application rewrite or a new standard.

A verified user on the endpoint, signed in with no user action
The login Closed

Close it

MagicEndpoint signs you in from the endpoint's hardware to the identity provider you already run.

  • No password
  • No one-time code
  • No approval to tap
  • No application changes
A typical session lasts hours on one token; with MagicEndpoint sessions last minutes and renew with no user action
The session Partly closed

Shorten it, then bind it

Re-authentication needs no user action, so sessions can expire in minutes and nobody notices. Where Chrome offers device-bound sessions, turn them on too.

The handoff between the identity provider and the application is an open gap that can be narrowed but not yet closed
The transition Open

Narrow it, and test it

Nobody has closed this gap yet. Single-use, short-lived assertions and strict redirect validation narrow it. That is the part we want the world to test.

Session hijacking and token theft

What is session hijacking or token theft, and how do we stop it?

Session hijacking is when an attacker steals the session token or cookie a service issues after login and uses it from their own machine. The token works for whoever holds it, so no password or MFA is needed.

  1. 1
    Shorten sessions See the session card above.
  2. 2
    Bind the token to the device Where the browser supports it.
  3. 3
    Issue no token at all Carry identity in the connection itself. This step needs service providers, which is why we are asking them to build it with us.
04No user action

How do you stop AI phishing and deepfake attacks?

Remove the prompt. AI makes a convincing fake page, email, deepfake voice or video almost free, and every other login keeps a human decision inside it for the fake to target. MagicEndpoint has none, so there is nothing to put in front of anyone.

A typical login

Sign in
Password •••••••• can be phished
One-time code 4 8 2  1 9 7 can be relayed
Approve sign-in? Approve can be faked

MagicEndpoint

MagicEndpoint
MagicEndpoint signed-in screen
Signed in

No password, no code, no prompt. The key never leaves this device.

No lure Nothing for a fake page to imitate
No credential No password or shared secret to harvest
No anonymous attacker Bots and scanners stop at the handshake
No stolen result The key cannot leave the endpoint

What it does not do

  • A real-time relay, present at the moment a session is registered, is not removed.
  • An endpoint that is already compromised is inside the boundary the design rests on.
  • The decision moves to enrolment, where the key is bound to the person once, under controlled conditions.
  • Your weakest enabled login sets the level. Check that no other method reaches the same resources.

We do not call it AI-proof or unphishable.

05An open invitation

How can researchers and developers work with WinMagic on MagicEndpoint?

Three ways, all in the open: attack it, build the session side, or take it through the standards. No company closes this alone.

Attack it

We are preparing an open test of the authentication exchange. The scope, rules and written safe harbour will be published before it opens, and we will publish what comes back, including anything that succeeds. Register interest now.

Build the session side

Speak mutual TLS with the endpoint and login and session become one connection. The reference code is public; partners get further source.

Take it through the standards

A W3C proposal in March 2026, IETF drafts on workload identity and OAuth, and comments on the record with MITRE. Nothing proprietary.

What is MagicEndpoint?

MagicEndpoint is WinMagic's zero-trust passwordless authentication with no user action, built on end-to-end cryptography: a login that produces a key. It authenticates from the endpoint's hardware to the identity provider you already run. There is no password in the exchange, no one-time code, no approval to tap and no application changes.

What is AI phishing and how do I recognize it?

AI phishing uses generative AI to produce convincing fake emails, login pages, deepfake voices and video at scale, personalized and free of the mistakes people were trained to spot. Warning signs still include unexpected urgency, a link asking you to sign in or approve something, and a sender or domain name that is slightly off. But recognition alone is losing. The durable fix is a login with nothing to recognize: with passwordless, no-user-action login such as MagicEndpoint, there is no prompt for a fake to imitate.

What does an AI-enabled breach cost?

IBM's July 2026 study found that AI-enabled breaches cost organizations about $6 million on average, roughly $1 million more than the global average breach cost of $4.99 million. One in four malicious breaches was AI-enabled, up 56% in a year.

What is an adversary-in-the-middle attack?

An adversary-in-the-middle attack relays between the user and the real service. It lets the real person complete the real login and takes what comes out of it. It breaks nothing, beats every login method at once and leaves no signal, because both ends see a login that worked. AI removed its one cost: a lure convincing enough that a careful person proceeds.

Why is adversary-in-the-middle called the mother of all attacks?

Because it needs nothing to be wrong. Every other attack on a login needs a weakness: a guessed or stolen password, a phished code, a tired user tapping approve. Even a zero-day needs a flaw, and once the flaw is found, it can be patched. Adversary-in-the-middle needs no flaw at all, so there is nothing to patch, today or later. It works against a correctly configured system used by a careful person, it beats every login method at once, and AI has made the lure it needs almost free.

Is MFA enough to stop AI attacks?

Not on its own. The attack AI has made cheapest, adversary-in-the-middle, lets the real person pass MFA and then takes the result of the login. A relay does not steal an identity, it steals a result, so a stronger way of proving who you are does not help. Proofpoint reported in December 2024 that almost half of all accounts taken over had MFA configured.

What is end-to-end cryptography for login?

A login has to produce a key, with the party you are about to talk to. Passwords, multi-factor and passkeys all end in a verdict, a statement that the login succeeded, and then something agreed separately protects everything that follows. With end-to-end cryptography the login and the key that protects what follows are the same act, so there is no seam for a relay to use.

What is mutual TLS (mTLS)?

Mutual TLS is TLS in which both sides prove who they are with a key, not only the server. It has authenticated machines to each other for decades, and the same handshake produces the key that protects the connection. It never reached people because it asked them to carry cards and handle certificates. MagicEndpoint holds the key in the endpoint's hardware, so mutual TLS can stand for a verified person, with no user action.

What is passwordless authentication?

Passwordless authentication signs a user in without a password, usually with a key held on a device. Many passwordless methods still ask the user to approve a prompt or complete a ceremony, which an AI-generated fake can imitate. MagicEndpoint is passwordless with no user action at all: the endpoint proves its key on every connection.

Do passkeys and FIDO2 stop adversary-in-the-middle attacks?

Passkeys avoid the attack. They do not solve it. Passkeys, built on FIDO2, are what most phishing-resistant MFA rests on today: the browser checks that the site is the real one, and where that check holds, the relay is refused. But the login still ends in a token that works for whoever holds it, and outside the browser there is no check at all. Solving it means the login produces a key that never leaves your endpoint, so a relayed login is worth nothing. That is what MagicEndpoint does.

How do you stop adversary-in-the-middle attacks?

Make the login produce a key that exists only on your endpoint and cannot be copied off it. A relay can pass every byte and the attacker still holds nothing usable, because the part that matters never left the machine. This is end-to-end cryptography for login, and it is what MagicEndpoint does.

Does MagicEndpoint work beyond the browser?

It is designed to. Passkeys' protection against a relay is computed by the browser from the name of the site, so paths without a browser, such as desktop apps, RDP and SSH, are often left on a password. MagicEndpoint's key and policy live on the endpoint, not in the browser, and the same presence and policy conditions apply to those paths through the mechanism that fits each one, for example a per-service key for SSH. Check with WinMagic which protocols your deployment covers.

Does MagicEndpoint work with Microsoft Entra ID, Okta and Ping?

Yes. MagicEndpoint authenticates from the endpoint's hardware into the identity provider you already run, and it has been tested with Microsoft Entra ID, Okta and Ping. You do not replace your identity provider, and no application changes are needed.

What is session hijacking or token theft, and how do you stop it?

Session hijacking is when an attacker steals the session token or cookie a service issues after login and uses it from their own machine. The token works for whoever holds it, so no password or MFA is needed. Stop it in three steps: shorten sessions, which MagicEndpoint makes painless because re-authentication needs no user action; bind tokens to the device where the browser and identity provider support it; and carry identity in the connection itself, so no token is issued at all.

What can I deploy today?

Close the login with MagicEndpoint. Make sessions short, which becomes practical because re-authentication needs no user action, and bind them where the browser can, such as Google's device-bound sessions in Chrome. Narrow the transition between the identity provider and the application with single-use, short-lived assertions and strict audience and redirect validation.

What happens if the identity provider is down?

The policy engine is on the endpoint. Access keeps working through an outage and stops the moment posture degrades, so no break-glass account on a weaker method is needed.

What happens if a user loses a device?

The user keeps working from their other enrolled device. If a user loses their phone, their manager can approve sign-in to the computer at pre-boot or Windows login, confirming from the manager's own phone with a PIN or biometrics, so the user is not left waiting on a helpdesk ticket. If the computer is lost, it will not export its sign-in key, and where pre-boot authentication is deployed, its disk stays encrypted until someone authenticates at pre-boot. Talk to us about which recovery options fit your policy.

What does MagicEndpoint not protect against?

An attacker relaying in real time, present at the moment a session is registered, is not removed. An endpoint that is already compromised is inside the boundary the design rests on. The human decision does not vanish, it moves to enrolment, where the key is bound to the person once under controlled conditions, so enrolment is where the care goes. And if another, weaker login method still reaches the same resources, that method sets the security level. WinMagic does not call MagicEndpoint AI-proof or unphishable.

Can researchers test MagicEndpoint?

WinMagic is preparing an open test of the authentication exchange. The scope, rules and written safe harbour will be published before it opens, and WinMagic will publish what comes back, including anything that succeeds. The reference implementation of the key and the handshake is already public at github.com/WinMagic/LIT. Register interest at research@winmagic.com.

Where this goes

Stop asking people to spot better fakes. Let the endpoint do the cryptography.

1 Today Secure the login
2 Now Bind or shorten the session
3 Next Carry identity into the transaction

Each step is worth having on its own, and the first one is running in production already.

Read the research

keyboard_arrow_up