Reviewed guide | 2026-09-27
Moving Passkeys and Authenticator Apps to a New Phone Without Losing Exchange Access
A practical order of operations for replacing a phone or authenticator app so you keep logging in to Binance, OKX, Bybit and Bitget. Covers backup codes, multiple enrolled devices, test logins and what to record before you wipe the old handset.
Multiple exchanges | the reader's region | the reader's funding currency | fees, access and account safety
Replacing a phone is routine until the old handset is the only place your passkey or one-time codes live. If you wipe it first, sign-in can stall at the exact moment you need to confirm a withdrawal or change a security setting. The safe approach is to add the new device while the old one still works, prove that the new one can sign in, and only then retire the old one. Because passkeys and authenticator apps behave differently, treat them as two separate migrations that happen in the same window. This guide sets out an order of operations you can follow on Binance, OKX, Bybit and Bitget, with checkpoints that tell you when to stop instead of pushing forward. Always confirm the exact menu names and steps in each exchange's help centre, since interfaces change and the wording differs between platforms and app versions.
Before you touch anything: inventory what proves who you are
Start by listing every method that can get you into each exchange account: password, passkey stored on the phone or in a password manager, authenticator app codes, SMS or email codes, and any printed backup or recovery codes. Write the list down somewhere offline, not in a note on the phone you are about to replace. For each method, note which device or app currently holds it and whether a second copy exists.
Then check whether each account already has a second factor enrolled that does not depend on the old phone. Many exchanges let you register more than one authenticator entry or more than one passkey, and a second enrolled device is the single most useful thing you can have during a migration. Look in the security section of the account settings on each platform and record what you find, including anything labelled as a backup or recovery code that you have not yet stored.
Set a stop condition for yourself now: if an account has exactly one factor and that factor lives only on the phone you are replacing, do not start the migration until you have read that exchange's help centre article on resetting or recovering that factor. Resetting a lost factor is usually slower and involves more checks than adding a new device while the old one still works.
Migrate the authenticator app first, one account at a time
If your codes come from an authenticator app, deal with it before passkeys, because it is the method most likely to be the only way into an account. The reliable pattern is to open the security settings for one exchange, choose to add a new authenticator, and scan the setup code with the app on the new phone while the old phone is still switched on and still generating codes. Confirm the new entry works by entering a freshly generated code when the platform asks you to verify the addition.
Do this for a single account, then stop and test it. Log out and log back in using a code from the new phone, and if the platform requires a code to confirm a security change, complete one small change and reverse it. Only when that test passes should you repeat the process for the next exchange. Migrating all accounts in one sitting makes it hard to tell which step failed if a code is rejected.
A common mistake is deleting the old authenticator entry before the new one is confirmed. Keep the old phone powered on, offline if you prefer, and keep the old entry in place until you have logged in successfully from the new device at least once. Another mistake is scanning a setup code into an app that is not backed up anywhere, which simply recreates the original problem; check the app's own documentation for how it stores or exports entries and decide whether that fits your situation. When in doubt about a specific step, the help centre for that exchange is the only place that describes its current flow.
Move passkeys with the platform's own add-a-device flow
Passkeys are tied to the device or account that created them, so the goal is not to copy one but to enrol a new one and then remove the old. Sign in on the new phone, open the security settings, and look for the option to add a passkey or security key. The platform will hand the creation step to your phone's credential manager, which may ask for a screen lock, a fingerprint or a face check. Complete that, then confirm the new passkey appears in the account's list of registered methods.
Before removing the old passkey, verify the new one actually works. Log out completely, sign back in, and choose the passkey option rather than a password or code. If the sign-in succeeds, you have proof that the new credential is enrolled and usable. If the platform asks for a second factor during this test, that is a good sign, not a problem; it means more than one method is protecting the account.
Only after a successful passkey sign-in should you remove the old device's passkey from the account. Do not delete it from the phone's credential manager first, because the account may still list it and you lose the ability to test. If the add-a-device option is missing, or the platform asks you to reset security instead, pause and read the verification and security articles in that exchange's help centre before proceeding. Interface details such as where the option sits and what it is called vary between Binance, OKX, Bybit and Bitget and change over time, so treat any screenshot or tutorial older than your app version as a hint, not an instruction.
Keep the old phone alive until every account passes a full test
Once each account has a working new factor, run a full test on every platform before you wipe, sell or trade in the old phone. A full test means: sign in from the new device, open the security settings and confirm the list of enrolled methods matches what you expect, and complete one reversible action that requires confirmation, such as toggling a notification preference and switching it back. Record the date, the account, which methods are enrolled and which device holds each one.
Watch for the settings that can quietly lock you out later. Withdrawal address lists, API keys and trusted-device lists may be tied to the old device or session, and some platforms require re-confirmation after a security change. Skim those pages and note anything that says a change takes effect after a delay, so you are not surprised by a temporary restriction on the day you need to move funds. The help centre article on security settings for each exchange is the right place to confirm current behaviour.
Keep the old phone switched off but not erased for a few days after the migration. If a login fails on the new device, you can switch the old one back on and use its still-enrolled factor to get in and fix the problem. Erase it only when every account has passed a sign-in test from the new phone and you have stored your recovery codes somewhere separate from both devices. If any account still has a single factor after all of this, treat that as unfinished work rather than a completed migration.
Risk boundary: DeFi Protocols Hub
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat. A referral link only records attribution; it does not guarantee access, pricing, rewards, approval or investment results. Availability can differ by residence, legal entity and product, so no regional access is assumed from language or branding alone.
Scenario checkpoint
- List every login method per account and note which device or app holds each one, offline.
- Enrol a second factor on each exchange so no account depends on a single device.
- Add the new authenticator entry and confirm it with a fresh code before deleting the old one.
- Enrol a new passkey, sign in with it successfully, then remove the old passkey from the account.
- Test sign-in and one reversible action on every account from the new phone.
- Store recovery codes away from both phones and keep the old handset powered off but unerased for a few days.
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat.