Reviewed guide | 2026-09-28
Moving Passkeys and Authenticator Codes Between Phones Safely
A practical order of operations for handing over passkeys and authenticator codes when you change phones, so you keep access to your exchange account instead of locking yourself out.
Multiple exchanges | Bangladesh | BDT | fees, access and account safety
Changing phones is one of the few routine events that can quietly cost you access to an exchange account. Passkeys live in the secure storage of the old device, and authenticator codes live in an app that may or may not back itself up. If you wipe, sell or lose the old phone before the new one is fully working, recovery can turn into a slow support ticket with identity checks. This guide walks through a handover order that keeps at least one working login method at every step: prepare the new phone, add it while the old one still works, test it, and only then remove the old device. The exact menus differ between exchanges and app versions, so treat every screen name here as something to confirm in the official help centre before you tap.
Before you touch the old phone: build your access inventory
Start by listing every method that can currently get you into the account: password, passkey, authenticator app codes, SMS codes, email codes, and any backup codes you saved when you first set up two-factor authentication. Write this list on paper, not in a note on the phone you are about to retire. For each method, note where it physically lives and whether it depends on the old device. A passkey stored only on the old phone and an authenticator app with no export are both single points of failure during a handover.
Next, confirm which of those methods you can still use today. Log in from a browser on a computer and open the security settings page. If a method is listed but you cannot actually complete it, that is the first thing to fix, and it is easier to fix while the old phone still works. Check the official help centre for that exchange to see how each method is described and which ones can be added or removed without contacting support.
Finally, decide your target end state. Most people want the new phone to hold the passkey and the authenticator codes, with the old phone removed entirely. Write down that target and the date you plan to reach it. If anything goes wrong mid-way, you will know exactly which step you were on and what still works.
Move the authenticator app before the passkey
Authenticator codes are usually the easier of the two to move, so handle them first. If your authenticator app supports exporting accounts, use its official export or transfer feature and follow the app's own instructions. If it does not support export, do not delete anything yet. Instead, go to the exchange security page and add a second authenticator entry by scanning a new QR code with the app on the new phone, keeping the old entry active. Both phones will then generate valid codes until you remove the old one.
When the exchange shows the setup QR code, it normally also shows a long setup key or secret. Record that key on paper and store it separately from both phones. This is the detail people most often skip, and it is the one that makes a future re-setup possible without a support ticket. Do not photograph it and leave it in the gallery of a phone you are about to sell.
Test the new authenticator immediately. Log out, log back in, and complete a two-factor prompt using a code from the new phone only. If the code is rejected, check the clock on the new phone is set to automatic network time, because a drifting clock is the most common cause of invalid codes. Only after a successful login should you remove the old authenticator entry from the exchange security page.
Add the passkey on the new phone, then test it
Passkeys are tied to the device and to the account or keychain that created them, so they generally cannot be copied by hand. The reliable route is to add a new passkey from the new phone while the old one is still registered. On the new phone, sign in to the exchange, open the security settings, and choose to add a passkey. The phone will ask you to confirm with its screen lock, fingerprint or face unlock. Complete that prompt and give the passkey a name that identifies the device, so you can tell the entries apart later.
Once the new passkey appears in the list, test it in a fresh browser session. Sign out completely, then sign in and choose the passkey option, selecting the entry for the new phone. If the browser offers a passkey from the old device instead, cancel and retry, choosing the correct entry. A passkey that has never completed a real login is not yet a working backup, no matter how healthy it looks in the settings list.
Keep the old passkey registered until the new one has passed this test at least twice, ideally on different days. If the new phone is lost or reset in between, the old passkey is still your way in. Only then remove the old device's passkey from the security page, and confirm the list now shows only the entries you intend to keep.
If something breaks, stop and use your recorded details
If the new phone cannot add a passkey, or the authenticator codes are rejected, stop removing anything. Do not delete the old passkey, do not wipe the old phone, and do not reset two-factor authentication in a hurry. Go back to the access inventory you wrote down and confirm which method still works, then use that working method to review the security page calmly.
When you contact support, you will usually be asked to prove you control the account and the contact details on file. Have your account email, the approximate date you opened the account, your recorded setup keys, and any backup codes ready. Support staff will explain what they need; you do not need to guess. Never send a passkey, an authenticator code or a setup secret to anyone who contacts you first, even if they claim to be from the exchange.
A common mistake is to sell or factory-reset the old phone as soon as the new one is set up. Keep the old phone powered off but intact until you have logged in successfully from the new device several times, and until you have confirmed the old entries are removed from the exchange. Another common mistake is storing the setup key only in a cloud note that syncs to the phone being replaced. Paper in a safe place, or a password manager you already trust, is a better home for it.
Risk boundary: Bangladesh Crypto Guide
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat. A referral link only records attribution; it does not guarantee access, pricing, rewards, approval or investment results. Availability can differ by residence, legal entity and product, so no regional access is assumed from language or branding alone.
Scenario checkpoint
- Write down every current login method and where it lives before changing anything.
- Export or re-add authenticator codes so both phones work, and record the setup key on paper.
- Add a passkey from the new phone and complete at least two real logins with it.
- Keep the old passkey and old authenticator entry active until the new ones pass testing.
- Remove the old entries only after successful tests, then confirm the security page shows what you expect.
- Keep the old phone intact and powered off until you are confident, and never share codes or setup keys with anyone who contacts you.
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat.