Security
Changed Phone? How to Move 2FA, Use Backup Codes and Recover
Your authenticator secret lives on the old handset and does not ride along with a cloud backup. Learn the correct migration order, how to store backup codes, and what to do when the device is already gone.

Changing phones is more sensitive for a crypto account than most people expect, because your two-factor authentication secret lives on the old device and does not automatically ride along with a cloud backup — particularly with authenticator apps like Google Authenticator. If you discover you cannot log into your exchange only after factory-resetting the old handset, the problem becomes a very different one.
This guide covers the correct migration order, what backup codes are for, and the recovery sequence when the device is already gone.
First, identify which kind of 2FA you use
| Type | What happens when you change phones | Security consideration |
|---|---|---|
| Authenticator app (TOTP) | The secret lives in the app; you must migrate or re-enrol | Independent of mobile networks, widely considered robust |
| SMS codes | Only affected if the number changes | Exposed to SIM-swap attacks |
| Email verification | Unaffected by the handset | Only as strong as the mailbox itself |
| Hardware security key | A physical device, unrelated to the phone | Usually strongest, but needs a planned backup |
| Platform built-in authenticator | Depends on the platform's design; may bind to a device | Check that platform's migration notes |
Almost all the trouble sits in the first row. Only TOTP authenticators require deliberate action before you switch, and the other types carry far less handset-change risk.
The correct order before you switch
1. Start while the old phone is still in your hands
This is the whole game. Do not reset the old device first, and do not pull the SIM yet. Every security step should be completed while the old device still works and still generates codes.
2. Inventory which accounts use 2FA
Not just exchanges. Email, cloud storage, password managers and social accounts usually live in the same authenticator — and email is typically the root credential for recovering everything else, so handle it first.
3. Export or transfer the authenticator
Most mainstream authenticator apps offer a transfer or export function, generally by generating a QR code on the old phone for the new one to scan. During that process:
- Do it strictly between your own two devices, and let no one photograph or screenshot that QR code.
- After the transfer, test a login on the new phone and confirm the codes work.
- Do not delete anything on the old device until that test passes.
4. Obtain and store backup codes properly
Platforms typically issue a set of one-time backup codes. Store them offline — on paper or in an encrypted file — never in the same phone's photo roll or a chat thread, which is the equivalent of keeping the lock and the key in one box.
5. Update devices and security settings on the platform
Once logged in, review the device management list and remove devices you no longer use. Note that changing security settings usually triggers a withdrawal holding period; that is normal protection, and our guide on restricted accounts explains what to expect.
6. Only then reset the old phone
Factory-reset the old device after every account logs in correctly on the new one and your backup codes are safely stored.
If you already switched or lost the device
Work through this order without skipping steps:
- Try your backup codes first. If you saved them, this is the fastest path.
- Check whether your authenticator has a cloud backup. Some apps support account sync and can restore on a new device.
- Confirm you still control the email address and phone number. These are the basis for most platforms' 2FA reset.
- Follow the platform's official 2FA reset flow. It normally requires identity verification and comes with a multi-day withdrawal lock.
- Submit only through the support entry in the official app or site. This is the step scammers target hardest.
Any third party claiming they can "quickly remove your 2FA" is running a scam. Platform staff do not DM you, do not charge fees, and never ask for your password, backup codes, seed phrase or remote access. The social-engineering patterns match those in our P2P scam checklist.
FAQ
SMS 2FA or an authenticator app — which is better?
Authenticator apps are generally more robust, because SMS is exposed to SIM-swap attacks. Where a platform allows it, most security guidance suggests enabling an authenticator and treating SMS as a fallback rather than the primary method.
Can I keep the authenticator on two phones at once?
Technically this is often possible, but it widens your exposure. If you do, both devices must have screen locks and both must be devices you personally retain long-term.
I am changing my number but keeping the phone — anything to do?
Yes. If you use SMS 2FA or rely on the number for account recovery, a decommissioned number can be reassigned to someone else, so update your platform details before it lapses.
Can backup codes be regenerated after being used?
Most platforms can issue a fresh set and invalidate the old ones. Remember to update your offline copy after regenerating.
Why can I not withdraw immediately after resetting 2FA?
It is anti-theft design. Changing 2FA is typically the first move in an account takeover, so platforms impose an observation window. Plan ahead rather than dealing with this when you urgently need to withdraw.
Official sources and verification note
2FA migration and reset flows, and lock-out durations, change with platform versions and region. Information here was verified on 2026-08-22 (UTC+8); follow the instructions the platform shows you at the time. This is operational education, not investment advice. Not intended for residents of mainland China.