Until today, anyone who signed in with your email address and password was offered the chance to create a passkey on their own device. A passkey is a full way of signing in, not an extra check — so if your password had ever been guessed or reused from somewhere else, whoever had it could have given themselves a second, separate way in. Changing your password would not have removed it.
That offer is gone. New ways of signing in are now set up only from Security in your dashboard, where you are already signed in. Passkeys you already have are unaffected and still work — “Use a passkey” is still on the sign-in page.
We have no evidence of this being used against any account. It was a gap in how the sign-in page was set up rather than something that had gone wrong, and we found it while working through the sign-in screen.