Guides

Lost Your 2FA Device for a Crypto Exchange? What to Do Next

Lost a phone or authenticator app and cannot sign in to Coinbase, Kraken, or Binance? Follow the safe recovery order without falling for fake support or making account access less secure.

Published September 16, 2026Updated September 16, 2026

Losing the phone that holds your exchange authenticator is stressful, especially when you need to check a balance or make a withdrawal. But it is not a reason to hand over a code to a stranger, rush into a fake recovery page, or turn off account security when you get back in.

The practical goal is simple: recover access through the official exchange flow, then rebuild your login setup so one lost device cannot lock you out again.

Short answer

SituationSafest next move
You still have another approved sign-in or 2FA methodSign in through the official site or app, add a replacement factor, then remove the lost one.
You saved a backup code or a separate recovery factorUse it only on the exchange's real sign-in page, then replace the lost factor immediately.
You have no working 2FA methodStart the exchange's official account-recovery or reset flow; expect identity checks and a withdrawal delay.
The phone may have been stolen or your account activity looks unfamiliarTreat it as a possible compromise: use the official recovery path, secure your email, and do not approve new devices or withdrawals.

First: work out whether this is a device-loss problem or an account-takeover problem

A lost or broken phone is different from a phone that was stolen, remotely accessed, or lost alongside an unlocked email account.

Pause and treat the situation as higher risk if you see an unfamiliar device-confirmation email, a password-reset message you did not request, changed account details, or a withdrawal you did not initiate. Do not use a link in that message. Open the exchange app you already have installed, or type the official domain yourself.

If you only lost a phone and your email, password, and another approved sign-in method are still safe, recovery may be straightforward. If the phone and the recovery email are both exposed, secure the email account first. Exchange recovery often relies on it.

For the wider containment order, read Crypto Exchange Account Security Checklist and Unexpected Coinbase Device Confirmation Email? What to Do First.

Recover access only through the official route

Do not search for a support phone number. Do not respond to a direct message. Do not share an authenticator code, password, or wallet recovery phrase with anyone claiming they can speed up the process.

The major exchanges have different procedures, but the pattern is consistent: prove account ownership, complete the official recovery flow, then accept that withdrawals may be paused while the change is processed.

Coinbase: use account recovery or update 2-step verification while signed in

Coinbase directs users without access to their 2-step method to its account-recovery process. Its help documentation says recovery can require identity verification, can take up to 24 hours, and can leave sending unavailable for 24 hours after completion.

If you are still signed in, Coinbase provides a Lost access to your 2-step verification? path in security settings. Use that first rather than signing out or deleting a working session. Coinbase also distinguishes normal recovery from a compromised account; if you cannot access recovery because the account is locked, use the official help route from its site.

Kraken: use the backup you prepared, or its sign-in recovery route

Kraken's official lost-phone guidance gives three options for lost sign-in 2FA: a Master Key already configured on the account, a 2FA backup code recorded during initial setup, or a support request for sign-in troubleshooting.

The important limitation is easy to miss: Kraken says you cannot add a Master Key after you have already lost sign-in 2FA. That makes a preconfigured, separately stored recovery method valuable, but it is not a shortcut you can create during the emergency.

If you do regain access using an old 2FA backup from the lost phone, replace that sign-in factor straight away. A backup tied to a missing device is no longer a clean security boundary.

Binance: start the reset from the real login flow

Binance's 2FA reset instructions begin at its official login page. After entering the account credentials, users select the unavailable verification method and follow the reset and security-verification prompts. Binance says withdrawals, internal transfers, P2P selling, and payment services can be disabled for up to 48 hours after a 2FA reset.

That hold is a protection, not proof that recovery failed. Do not try to bypass it through someone who contacts you claiming to be support.

What not to do while you are locked out

A recovery problem makes rushed decisions feel reasonable. Avoid these ones:

  • Do not give anyone a six-digit code. A real exchange agent does not need it to prove you own the account.
  • Do not install a remote-access app. A support impersonator can use it to take over email, browser sessions, and wallet extensions.
  • Do not enter a hardware-wallet seed phrase to recover an exchange account. An exchange login never requires it.
  • Do not weaken security just to restore access faster. Replace the lost factor; do not leave the account with a password and SMS alone.
  • Do not trust search ads or unsolicited calls. Start from the app, bookmarked official site, or a domain you type yourself.

A fake support approach can turn an inconvenient lockout into a permanent loss. See Crypto Support Call Scam for the common pressure tactics.

After you are back in: rebuild a two-path setup

Getting in is only half the job. The next goal is to avoid a single-phone failure without creating an easy attack path.

A sensible setup for a funded exchange account is:

  1. use a passkey or authenticator app as the primary sign-in method;
  2. add a second, separate approved method if the exchange supports it;
  3. store recovery codes or a recovery key offline and separately from the everyday phone;
  4. secure the email account used for recovery with its own strong sign-in method;
  5. enable withdrawal allowlisting or equivalent address-book protection;
  6. test the backup method before you need it.

A second path should not simply be another copy on the same lost phone. It should be a factor you can reach if that phone, its number, or its cloud account becomes unavailable.

For the login choice itself, see Passkeys vs Authenticator Apps for Crypto Exchanges. For the withdrawal layer, see Should You Use Exchange Withdrawal Allowlisting?.

Move long-term holdings only after the account is secure

Do not make a panicked withdrawal to an address you have not verified. Once recovery is complete and the account is secure, decide whether funds you do not plan to trade belong on the exchange at all.

For longer-term holdings, a hardware wallet removes exchange-account access from the custody chain, but it adds a different responsibility: protecting and testing your wallet backup. If self-custody is the better fit, use How to Move Crypto From an Exchange to a Hardware Wallet and then compare Tangem, Ledger, and Trezor based on the recovery model you will actually maintain.

Bottom line

A lost 2FA device is recoverable more often than people think, but the safe route is never a random support number or a hurried security downgrade.

Use the exchange's real recovery flow, expect a verification and withdrawal delay, secure the email account behind it, and rebuild two separate sign-in paths before you rely on the account again.

Explore more

Guides worth reading next