Here is a link to the security research that describes how a Google Titan Security Key can be cloned. These hardware keys have been in use since about 2018. The side-channel attack targets the keys secure element (the NXP A700X chip) by observing local electromagnetic radiations during ECDSA signatures (the core cryptographic operation of the FIDO U2F protocol). From those observations an attacker can then clone a legitimate key.