OpenAI launches Advanced Account Security for ChatGPT with hardware keys and passwordless login

Reviewed byNidhi Govil

10 Sources

Share

OpenAI introduced Advanced Account Security for ChatGPT and Codex accounts, replacing passwords with hardware security keys and passkeys. Through a Yubico partnership, users can purchase co-branded YubiKeys for $68. The opt-in security feature targets journalists, dissidents, and researchers but remains available to all users seeking enhanced protection against phishing attacks.

OpenAI Introduces Advanced Account Security for High-Risk ChatGPT Users

OpenAI launched Advanced Account Security on Thursday, marking a shift in how the company approaches account protection for ChatGPT and Codex users

1

. The opt-in security feature eliminates traditional password-based login entirely, requiring users to authenticate with hardware security keys or passkeys instead

2

. While designed for journalists, political dissidents, elected officials, and researchers who handle sensitive information, the feature is accessible to any ChatGPT user seeking enhanced account protection

3

.

Source: TweakTown

Source: TweakTown

The company emphasizes that ChatGPT accounts increasingly hold deeply personal and professional context, sitting at the center of connected tools and workflows

2

. For high-risk users, the stakes are particularly elevated, as conversations may include confidential work projects, medical symptoms, legal exposure, and business strategies

5

.

Yubico Partnership Delivers Discounted Hardware Security Keys

As part of the security rollout, OpenAI partnered with Yubico to offer co-branded YubiKeys at a significant discount

1

. Users can purchase a bundle containing the YubiKey C NFC and YubiKey C Nano for $68, almost half off the usual retail price of $126

3

. The partnership aims to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide, according to Yubico CEO Jerrod Chong

1

.

Source: TechCrunch

Source: TechCrunch

Hardware security keys are physical USB devices containing unique cryptographic identifiers that allow only the person possessing them to log into connected accounts

1

. The YubiKey C Nano is designed to stay plugged into a laptop for simple, low-friction daily authentication

4

. While Yubico's products are featured, other FIDO2-compliant hardware tokens are also supported

5

.

Source: PC Magazine

Source: PC Magazine

Passwordless Login and Stronger Account Recovery Methods

Advanced Account Security replaces every conventional login mechanism with cryptographic authentication

5

. Users must register two separate credentials, choosing from passkeys stored on their device, hardware security keys, or a combination of both

2

. Each credential generates a unique cryptographic key pair that never leaves the device, meaning there's no password to steal, no one-time code to intercept, and no recovery email that attackers can compromise through social engineering

5

.

The feature disables email and SMS authentication routes for account recovery, forcing users to rely on backup passkeys, security keys, or recovery keys instead

2

. During enrollment, OpenAI automatically generates recovery keys that users must copy or download and store in a safe place

3

. This design makes accounts resistant to phishing messages, password guessing, and SIM swap attacks

4

.

However, the security comes with significant trade-offs. OpenAI's support team cannot restore access to accounts protected by Advanced Account Security if users lose both credentials and their recovery keys

2

. The company has made this design choice explicit: if all authentication methods are lost, the account becomes permanently unrecoverable

5

.

Additional Protections Address Cybersecurity Threats

The feature includes several secondary safeguards beyond passwordless authentication. Sign-in sessions are shortened to reduce the window of exposure if a device or active session is compromised

4

. Users receive alerts for every new login and can review and manage all active ChatGPT and Codex sessions from their account dashboard

2

.

Advanced Account Security automatically opts users out of AI model training by default, meaning conversations won't be used to improve future versions of ChatGPT

3

. This links the highest level of account protection to the highest level of data privacy, creating a tier of users whose interactions are both cryptographically secured and contractually excluded from OpenAI's training pipeline

5

.

The security upgrade addresses growing threats in the AI space. In 2024, cybersecurity firm Group-IB identified more than 100,000 stolen ChatGPT credentials circulating on dark web marketplaces, harvested from devices compromised by information-stealing malware

5

. Industry research suggests that 46 percent of all successful cyberattacks on small and medium businesses in 2026 will originate from credential reuse

5

. The architecture borrows from zero-trust principles that protect classified government systems and cryptocurrency wallets, now applied to a consumer chatbot

5

.

Members of OpenAI's Trusted Access for Cyber program will be required to enable Advanced Account Security beginning June 1 or submit an alternative attestation implementing phishing-resistant authentication through enterprise single sign-on

2

. OpenAI expects to extend the feature to additional audiences, including enterprise environments, where stronger account security matters just as much

3

.

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved