According to the sentense below in this page, "Security Key by Yubico" does NOT have a serial number.
Serial numbers are unique across all models of YubiKeys, with the exception of Security Keys, which do not have serial numbers.
However, in Yubico Demonstration Site, the same "Yubico" can register security key in only 1 key.
So, I consider that "Yubico" has some mechanism to identify each "Yubiko" without using serial number.
Then, how does the authenticator in webserver identify each key without a serial number?
 
                        
The answer is found within the U2F protocol (public-key credentials & attestation metadata):
Public-Key Credentials
Check out an overview of the U2F protocol to learn more.
Attestation & Metadata
Each Yubico device has an attestation certificate that has been signed by Yubico's root CA. A website can validate that a YubiKey is genuine by checking it against the root CA. That attestation certificate has metadata that can identify the model of the authenticator. This attestation certificate follows the U2F privacy requirements and does not have any metadata that can be used to individually identify a particular security key.
Learn more about Yubico U2F attestation and metadata.