OpenAI launches Advanced Account Security for ChatGPT with hardware keys and Yubico partnership

Reviewed byNidhi Govil

8 Sources

Share

OpenAI has rolled out Advanced Account Security, an opt-in feature that replaces passwords with hardware security keys and passkeys to protect ChatGPT accounts from phishing attacks. Through a Yubico partnership, users can purchase co-branded YubiKeys for $68. The feature targets high-risk users like journalists and officials but comes with strict trade-offs—lose your keys, and OpenAI cannot help recover your account.

OpenAI Introduces Advanced Account Security to Protect ChatGPT Accounts

OpenAI has launched Advanced Account Security, an opt-in feature designed to drastically reduce unauthorized access to ChatGPT and Codex accounts

1

. The security upgrade arrives as cybercriminals increasingly target chatbot users, with over 100,000 stolen ChatGPT credentials identified circulating on dark web marketplaces in 2024

4

. The feature disables password login entirely and requires users to authenticate with hardware security keys, passkeys, or a combination of both

2

. This move positions OpenAI alongside tech giants like Google, which has offered its Advanced Protection program for nearly a decade.

Source: Decrypt

Source: Decrypt

Hardware Security Keys and the Yubico Partnership

As part of the rollout, digital security provider Yubico announced a partnership with OpenAI to offer two co-branded products: the YubiKey C NFC and the YubiKey C Nano

1

. These FIDO2-compliant hardware tokens are bundled together for $68, less than half the $126 retail price

4

.

Source: TechCrunch

Source: TechCrunch

The YubiKey C Nano is designed to remain plugged into a laptop for low-friction daily authentication, while the NFC-enabled key works with mobile devices

3

. Each credential generates a unique cryptographic key pair that never leaves the device, making it impossible to steal through remote digital hacks

3

. "Ultimately, our intent is to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide," Yubico CEO Jerrod Chong said in a press release

1

.

Source: PC Magazine

Source: PC Magazine

Designed for High-Risk Users but Available to Everyone

OpenAI has suggested that Advanced Account Security is particularly suited for journalists, elected officials, political dissidents, researchers, and security-conscious individuals whose work involves politically charged or sensitive material

1

. The feature is available to all users, including those on the free tier

4

. Members of OpenAI's Trusted Access for Cyber program will be required to enable Advanced Account Security beginning June 1 or submit an alternative attestation that they implement phishing-resistant authentication through enterprise single sign-on

2

. The architecture borrows from zero-trust principles that protect classified government systems and cryptocurrency wallets, now applied to a consumer chatbot

4

.

Strict Trade-Offs: No Account Recovery from OpenAI Support

The feature comes with significant trade-offs centered on account recovery. Once enabled, users can no longer recover accounts through email or SMS codes, which are common targets for phishing attacks and social engineering

2

. OpenAI's support team loses access and control over recovery options entirely, preventing attackers from targeting support portals

2

. If users lose their hardware security keys or passkeys, OpenAI cannot help recover access—conversations could be lost for good

1

. The enrollment process requires at least two credentials: two hardware security keys, two passkeys, or one of each

3

. Users can also enroll with two software-based passkeys, but one must be synced to the cloud via Google Password Manager or Apple's iCloud Keychain

3

. OpenAI issues backup recovery keys during setup—strings of digits meant to be stored safely for self-service account recovery

3

.

Additional Protections: Session Management and Data Privacy

Advanced Account Security enforces shorter sign-in windows and sessions before requiring re-authentication, reducing the window of exposure if a device or active session is compromised

2

. Users receive alerts anytime someone logs into the account and can review and terminate active ChatGPT and Codex sessions from their dashboard

2

. Enabling the feature automatically opts users out of model training, meaning their conversations will not be used to improve future versions of ChatGPT

2

. This links the highest level of account protection to the highest level of data privacy, creating a tier of users whose interactions are both cryptographically secured and contractually excluded from OpenAI's training pipeline

4

.

Why This Matters: Rising Threats and Sensitive Information

ChatGPT's vulnerability is distinctive because of what accounts contain: medical symptoms, legal exposure, relationship problems, business strategies, code with proprietary logic, and conversations with an AI system that remembers context across sessions

4

. An estimated 46% of all successful cyberattacks on small and medium businesses in 2026 will originate from credential reuse, according to industry research

4

. The feature works by making accounts resistant to phishing messages, password guessing, and SIM swap attacks—the most common methods used by cybercriminals to crack online accounts

3

. OpenAI says the launch is not a response to a hacking incident but intended to preempt future threats as ChatGPT and Codex gain wide-scale adoption

3

. The security upgrade follows OpenAI's broader cybersecurity strategy announced earlier this month and arrives weeks after Anthropic announced a new cybersecurity model called Mythos

1

.

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved