Key Takeaways
- Losing your phone is a login problem, not a wallet problem. Your balance stays with the exchange. What you lost is the device that proved your identity, so the account itself is usually recoverable.
- A backup you saved earlier is the fast lane. Backup codes, the original authenticator setup key, a synced passkey, or a second device can turn a multi-day lockout into a five minute fix.
- Without a backup, expect identity verification and a waiting period. Most large exchanges run a manual reset that commonly takes 24 to 72 hours and adds a temporary withdrawal hold afterwards.
First, Work Out What You Actually Lost
People panic because they assume the coins are gone. On a centralised exchange they are not. The exchange holds the assets in an account tied to your email address and verified identity. The phone was only carrying the second factor, so the first job is naming which piece of the login you lost.
| What was on the phone | What it means | Typical fix |
|---|---|---|
| Authenticator app codes (TOTP) | The 6-digit code generator is gone unless it was backed up or synced | Backup code, setup key, cloud sync, or a support reset |
| SMS verification number | The SIM is gone, and so is the code delivery | Replacement SIM from your carrier, or an ID-based reset |
| Passkey or biometric login | The passkey may still exist in your cloud keychain | Sign in on another device signed into the same cloud account |
| Exchange app push approval | Push 2FA only works on a device you are signed into | Use another 2FA method, or start account recovery |
| Email app access only | Your email password still works elsewhere | Sign in to email on a computer and continue normally |
If your email lived only on that phone, recover the email first. Almost every exchange reset begins with a message you need to open.
The First Hour: Protect the Account Before You Recover It
Treat a lost phone as a stolen phone until you know otherwise. Work in this order.
- Suspend the SIM with your mobile carrier. This blocks both the physical SIM and a port-out request made by someone else. If SMS is a login factor anywhere, an attacker who controls the number controls the codes.
- Remote lock or wipe the handset using Find My iPhone or Find My Device. A locked phone with an active authenticator app is still an open door if the screen lock is weak.
- Change your email password from a trusted computer. Then check for new forwarding rules, new recovery addresses, and unfamiliar app passwords. Email is the master key to nearly every exchange account.
- Use the exchange's freeze or lock feature only if you suspect theft. Coinbase offers an account lock, OKX a self-freeze, Bybit account deactivation, and Kraken a Global Settings Lock. Be aware that these also block security changes. OKX states that a self-frozen account cannot reset its authentication methods, and Kraken's Global Settings Lock removal defaults to 72 hours and cannot be sped up.
- Do not open five support tickets. Duplicates often push you back in the review queue.
Recovery Path A: You Saved a Backup
Check these before contacting anyone. Each one skips the manual review entirely.
- 2FA backup codes. The one-time codes shown during setup. Any unused code works once.
- The authenticator setup key. The alphanumeric string under the original QR code. Enter it into a fresh authenticator install and your codes return immediately.
- Cloud sync in your authenticator app. Google Authenticator has synced codes to a Google Account since April 2023. Sync is opt-in, not automatic, and reporting notes it is still not end-to-end encrypted, so a weak Google Account becomes a real risk.
- A synced passkey. Coinbase notes a passkey works from any device or browser with sync enabled, such as iCloud Keychain or Google Password Manager. A new phone on the same cloud account may simply work.
- A second device or password manager. Multi-device authenticator apps and password managers with built-in code generators mean the phone was never the only copy.
- Kraken's Master Key. A separately stored key that bypasses sign-in 2FA. Kraken is explicit that you cannot create one after losing your 2FA, which is why it has to be set up early.
If any of these work, log in and immediately delete the old 2FA method and register a new one. Reusing a backup that also sat on a lost phone is not a fix.
Recovery Path B: No Backup, So Prove Who You Are
This is the manual route, and every major platform has one. The shape is consistent.
- Start from the login screen on the official site or app. Enter your email and password, then choose the "cannot access my 2FA" option. Never start from a search result, a phone number, or a direct message.
- Reset your password first if needed. Coinbase requires a working password before recovery can begin.
- Submit identity evidence. Expect a government ID photo and a live selfie. Binance also asks for an unedited video in which you hold your ID and read a dated statement naming your account email and the method you want reset.
- Answer account history questions if asked. Binance may request your registration date and registration IP, both found in your original signup email. Providing them speeds up review.
- Wait and watch your email. Reviews are manual.
- Re-secure the account immediately after. Coinbase asks users to update their 2FA method within 24 hours of recovery.
What Recovery Looks Like on Major Exchanges
Processes change often. Use this as orientation and confirm on the platform's own help pages.
| Exchange | Self-service option | Manual reset requirements | Typical timing and holds |
|---|---|---|---|
| Binance (global) | Backup key, passkey, or alternative 2FA | Video statement holding ID, plus ID photo, optional security questions | Manual review, withdrawal restrictions after reset |
| Binance.US | "Authenticator Issues" flow at login | Email verification, reset reason, ID checks | Review commonly 48 to 72 hours, plus a 48-hour withdrawal hold |
| Coinbase | Passkey, security key, trusted contacts, other 2FA | ID upload and selfie on the recovery page | Up to 24 hours, sending disabled for 24 hours after |
| Kraken | Master Key bypass, or a saved backup code | Support request under "Issue with Two-Factor Authentication" | Manual review; Global Settings Lock removal defaults to 72 hours |
| OKX | "Reset security features" self-service, SMS login if available | Facial recognition, support contact from the login page | Withdrawals, transfers and P2P disabled 24 hours after reset |
| Bybit | Disable and re-link authenticator from inside the account | Support ticket with identity checks | Withdrawals and P2P disabled for 24 hours after disabling 2FA |
Note on hardware security keys. Coinbase states it cannot recover or replace a lost physical key. Hardware keys are strong because the secret never leaves the device, which is also why you should register two.
Why Your Withdrawals Get Frozen After a Reset
The waiting period is not the exchange being difficult. A 2FA reset is exactly what an attacker attempts after stealing an email password, so the hold gives the real owner time to see the alert emails and object. The freeze typically covers on-chain withdrawals, internal transfers, fiat withdrawals, card spending, and P2P selling. Deposits and trading usually continue.
SIM Swap: The Weak Link in Phone-Based Recovery
If SMS is your only 2FA, your exchange security is really your carrier's security. In a SIM swap, an attacker persuades the carrier to move your number to their device and collects your codes without ever touching your phone.
Regulators have responded. The United States Federal Communications Commission adopted rules in November 2023 requiring wireless providers to authenticate customers securely before a SIM change or port-out, and to notify them immediately when either is requested. The rules took effect in January 2024, with a compliance date of July 8, 2024. That helps, but it does not make SMS a good primary factor. Add a carrier port-out PIN and move your exchange logins to an authenticator app, a passkey, or a hardware key.
Recovery Scams Target People in Exactly This Moment
Search for exchange recovery help and you will find pages stuffed with fake toll-free numbers, on forums, on document hosts, even on book review sites. They exist because a locked-out user is a motivated user.
- No exchange has a support number that appears in a random search result or a social media reply.
- Support never asks for your password, a live 2FA code, or a wallet recovery phrase.
- Nobody can "restore" your authenticator for a fee. Paid recovery agents are usually advance-fee scams.
- Screen-sharing with a self-declared helper is how accounts get emptied.
- Start every recovery from the official domain or the app already installed on your device.
Set Things Up So the Next Lost Phone Is a Five Minute Problem
| Action | Why it matters | Where to keep it |
|---|---|---|
| Save backup codes at setup | Restores access with no waiting | Printed, or in an encrypted password manager |
| Save the authenticator setup key | Rebuilds the code generator anywhere | Offline, separate from your password |
| Register two 2FA methods | One failure never locks you out | Passkey plus authenticator app |
| Buy two hardware keys | The spare is the recovery plan | One on a keyring, one at home |
| Set a carrier port-out PIN | Blocks the common SIM swap | Carrier account settings |
| Keep email on a second device | Every reset starts with email | A laptop or tablet you control |
One Important Distinction
This guide covers custodial exchange accounts, where a company holds your assets and can verify your identity. A self-custody wallet has no support desk and no identity check. If the phone held a wallet and the recovery phrase was never written down, those funds are generally unrecoverable.
Frequently Asked Questions
Can I lose my crypto by losing my phone? On an exchange account, normally no. The assets sit with the exchange and are tied to your verified identity, so recovery is an access problem. On a self-custody wallet with no saved recovery phrase, yes, the loss can be permanent.
How long does a 2FA reset take? It varies by platform and by how clean your documents are. Coinbase describes its ID-based recovery as taking up to 24 hours. Binance.US describes 2FA reset reviews as commonly taking 48 to 72 hours. Blurry photos, mismatched names, and duplicate tickets all add delay.
Why can't I withdraw right after I get back in? Because a fresh 2FA reset is a classic account takeover pattern. Exchanges apply a hold of roughly 24 to 48 hours so a genuine owner has time to react before funds can move.
I lost my phone and my email was only on that phone. What now? Recover the email account first through your provider's own process, ideally from a computer. Nearly every exchange reset sends a verification link or code to that address, so it is the true starting point.
Is SMS 2FA good enough if I keep my phone safe? It is better than nothing and worse than everything else. SMS can be intercepted through SIM swap or port-out fraud without anyone touching your device. Use an authenticator app, a passkey, or a hardware key as your primary method and keep SMS as a fallback at most.
Related Terms
- TOTP (Time-based One-Time Password)
- the open standard behind 6-digit authenticator codes, defined in RFC 6238.
- Passkey
- a phishing-resistant login credential based on FIDO2 that replaces passwords and can sync through a cloud keychain.
- SIM swap
- fraud in which an attacker transfers your phone number to a device they control in order to intercept codes.
- Withdrawal hold
- a temporary block on moving funds, usually applied after a security setting changes.
- Custodial account
- an account where a third party holds the private keys and can restore your access after identity checks.
Sources
- Binance Support, "How to Reset Two-Factor Authentication (2FA)"
- Binance.US Help Center, "How to reset two-factor authentication"
- Coinbase Help, "Troubleshoot your 2-step verification" and "Account recovery for lost email or 2-step verification access"
- Kraken Support, "I can't sign in to my account", "What is a Master Key?", "I can't unlock my account settings"
- OKX Help, "How do I change my authenticator app?" and "What should I do if my phone number, email address or authenticator app is unavailable?"
- Bybit Help Center, "How to Disable Your Google Authenticator" and "How to Enhance the Security of Your Account"
- Federal Communications Commission, "Protecting Consumers from SIM Swap and Port-Out Fraud", Report and Order FCC 23-95, November 2023
- TechCrunch, "Google Authenticator can now sync 2FA codes to the cloud", April 2023
More Reading
- Authenticator Apps vs Hardware Keys vs SMS: Which 2FA Should You Use?
- a comparison of the three common second factors and the trade-offs of each.
- How to Spot a Crypto Support Scam
- the patterns behind fake helplines, impostor agents, and paid recovery services.
- Custodial vs Self-Custody: Who Actually Holds Your Crypto?
- why the recovery options above only exist on one side of that line.
Disclosure: Recommendations are educational and are not financial advice. Always verify a product on the vendor's official site before buying.
Not sure which problem you have?
Use the Fixing Crypto Mistakes hub to identify the transaction, wallet, network, or exchange issue before taking another action.
OPEN TROUBLESHOOTING HUB



