Your password works. The six-digit code is on a phone you don't have.
Two-factor did its job - just against you. The account is fine, the password is right, and the login screen wants a code from a phone that's lost, dead, or in someone else's pocket. Before you fight the recovery form, exhaust the doors that are still open.
Try every other door first
- Backup codes. Every major service handed you eight or ten one-time codes the day you switched 2FA on. If you printed them or saved them anywhere a browser can reach, this is over in a minute. Check old email, your downloads folder on another machine, the drawer at home someone can look in.
- A device that's still signed in. A laptop, a tablet, a browser session at home - an already-authenticated session usually won't be asked for the code, and from inside the account you can mint new backup codes and enrol a new factor.
- The authenticator may have synced. Google Authenticator can back its codes to your Google account; Authy restores to a new device with your number and its backup password; iCloud Keychain carries verification codes to any Apple device you own. Install the app on a borrowed or new device and check before assuming the codes died with the phone.
- “Try another way.” The small link under the code prompt. Services often hold a second path they don't advertise - a secondary email, a passkey on another device, a prompt to an old phone still associated with the account.
- SMS codes: rescue the number, not the phone. If your second factor is texts, the number is the key and the number is portable. The physical SIM works in any cheap handset; an eSIM can be reissued by your carrier, usually with ID. Once the number rings again, the codes flow again.
If every door is shut: account recovery
Now it's the slow lane - deliberately slow, because the same form is how an attacker would get in. Expect identity questions and a waiting period measured in days, not minutes.
- Start from a machine and place the service knows. Your home network, your usual laptop, your usual country. Recovery systems score familiarity; a request from a hotel lobby abroad looks exactly like the attack they're built to stop.
- Answer with old truths. Account creation date, previous passwords, addresses you've emailed - approximate answers to many questions beat perfect answers to two.
- Some accounts have no back door at all. Game accounts, crypto exchanges, and some privacy-first email providers treat a lost second factor as final unless you hold their recovery code. For those, what you saved in advance isn't a convenience - it's the only key that exists.
What each service does when your second factor is gone
Same question, twenty-two answers. Whether a service handed you backup codes, what path stays open once the phone is gone, and how long it takes. The rows marked Hard wall have no back door at all - lose the codes and the account is gone, which is exactly why they're worth saving in advance.
| Service | Backup codes | Path without your phone | Expected time |
|---|---|---|---|
| Yes | Sign in and choose another verification method - a backup code, a hardware key or passkey, another signed-in phone, or an alternate second number. With none of those, run account recovery and answer identity questions. Source | minutes if a second factor survives, otherwise 3-5 business days for account recovery | |
| Apple ID | No | Use your recovery key (if you set one) or a recovery contact to regain access immediately. Otherwise start account recovery, which imposes a mandatory waiting period Apple Support cannot shorten. Source | immediate with a recovery key, otherwise several days to weeks of account-recovery waiting |
| Microsoft Hard wall | Yes | Use your one-time recovery code or another registered security method. If you know your password but have lost every method, replace your security info and wait 30 days; otherwise submit the account recovery form. Source | 30-day wait to replace security info, or ~24 hours for the recovery form to be reviewed |
| No | If you added an email during setup, request a reset link to disable the two-step PIN. With no email on file you must wait 7 days of inactivity before you can re-register the number and reset the PIN. Source | minutes with a recovery email, otherwise a 7-day wait | |
| Signal | No | Signal never stores your PIN and cannot reset it. With Registration Lock on and a forgotten PIN, you must wait out 7 days of account inactivity, after which the old PIN and its data are cleared and you can register fresh. Source | 7-day inactivity wait if Registration Lock is on |
| Telegram | No | If you set a recovery email, request a recovery code by email to remove the 2FA password. With no email you can reset the password, which starts a 7-day server-side timer before the reset (or account deletion) completes. Source | minutes with a recovery email, otherwise a 7-day reset timer |
| Yes | Enter one of the backup codes generated when you enabled 2FA. Without codes, tap through the login-help flow to confirm your identity (including a video selfie or ID) so support can restore access. Source | minutes with a backup code, otherwise 1-2 days for identity review | |
| Yes | Enter one of your 10 recovery login codes, or approve the login from a device already signed in. Without either, use the login-help flow to confirm identity (government ID, security questions, or trusted contacts). Source | minutes with a recovery code, otherwise 1-2 business days for identity review | |
| X/Twitter | Yes | Log in and enter your backup code (one is generated with 2FA). If you are logged out with no active backup code, your only route is the 2FA-problem support form; there is no automated reset. Source | minutes with a backup code, otherwise indefinite while support reviews the form |
| TikTok | No | Use "Recover your account" and, if you cannot access your email or phone, ask connected friends to verify you or submit the identity form to reset your authentication method. Source | hours to a few days depending on friend verification or identity review |
| Snapchat Hard wall | Yes | Log in with the Recovery Code you saved when you enabled 2FA. Snapchat explicitly does not offer support for lost Recovery Codes, so without it the 2FA-protected account cannot be recovered. Source | minutes with a recovery code, otherwise unrecoverable |
| Discord Hard wall | Yes | Enter one of your saved backup codes to log in. Discord states that without backup codes it cannot remove MFA or issue new codes, so a logged-out account with no codes cannot be recovered. Source | minutes with a backup code, otherwise unrecoverable |
| Steam | No | Use "I deleted or lost my Steam Guard Mobile Authenticator" in Help. If you still control the account's email or phone, self-service removes the authenticator; a trade/market hold then applies. Otherwise open a Steam Support ticket. Source | minutes to remove the authenticator, but a multi-day trade/market hold follows |
| PlayStation Network | Yes | Choose "Trouble Receiving Code?" and sign in with one of your 10 backup codes. Without backup codes you must contact PlayStation Support to verify identity and restore access. Source | minutes with a backup code, otherwise the length of a support case |
| PayPal | No | PayPal has no backup codes. If you cannot receive the security code, contact PayPal via Contact Us to verify identity and regain access, then update your mobile number. Source | the length of a support case, typically same day to a few days |
| Wise | No | Choose "Try another way" for an alternative such as a WhatsApp code, or "I don't have any of these" to confirm identity with a selfie if you are eligible. If you are not eligible for selfie verification, contact Wise to change the number. Source | minutes with a selfie, otherwise the length of a support case |
| Revolut | No | Download the app on a new device, enter your number and select "I haven't received a code yet" to reach a support agent who issues a verification code. You then confirm identity with a selfie and follow prompts to log out other devices, freeze cards and change your passcode. Source | minutes to hours once the support agent verifies you and the selfie clears |
| Coinbase | No | If you saved the authenticator secret seed you can restore codes on a new device. Otherwise select "Update your 2FA" to start account recovery with an ID and live photo upload; once access is restored, sends are disabled for 24 hours. Source | up to 48 hours for recovery, plus a 24-hour hold on sending funds |
| Binance | No | Log in with your password, mark the lost 2FA methods and request a reset, completing any additional identity verification the support team asks for. Withdrawals, P2P selling, internal transfers and payments are disabled for up to 48 hours after a reset. Source | hours to a day for review, plus a 48-hour withdrawal hold after reset |
| Amazon | No | Use Two-Step Verification Account Recovery and upload an identity document. Amazon reviews it and emails you once two-step verification is disabled, after which you sign in with your password. Source | 1-2 days for document review |
| Dropbox | Yes | Click "Having trouble getting a code?" and enter an emergency backup code from setup, or use a recovery email or backup phone. Without any of these you must contact Dropbox support to restore access. Source | minutes with a backup code, otherwise the length of a support case |
| GitHub Hard wall | Yes | Enter one of your saved recovery codes, or recover via another configured factor (SSH key, PAT, verified device, or passkey). GitHub states that with 2FA on and no recovery factor, support cannot restore the account. Source | minutes with a recovery code or factor, otherwise unrecoverable |
Last verified: 2026-07-21
So this never happens again
Every escape route above was built beforethe phone went missing: a printed code, a second factor, a synced authenticator, a session left signed in. The fix takes one evening - download backup codes for the accounts that matter, register a second factor where you can, and put the codes somewhere that isn't the phone.
Paper in a drawer works until you're a continent away from the drawer. The other place worth having is a page any borrowed browser can open - encrypted, unlocked with your name and a PIN, holding your backup codes, key numbers, and the plan. Set it up once, and the next time a login screen asks for a code from a phone that's gone, it's a detour instead of a disaster.
Don't just read it - build yours before you need it.
Your numbers, your banks, your plan - on a page you can open from any borrowed browser. Encrypted with a PIN only you know.