What Should You Do If a Security Key Used for Important Accounts Is Lost?

Losing a hardware security key (such as a FIDO2/U2F key from YubiKey, Feitian, Google Titan, or a passkey stored on a physical token) can feel alarming—especially when it protects email, banking, password managers, crypto, or work accounts. The good news: if you move quickly and follow a structured plan, you can prevent unauthorized access and regain control without locking yourself out.

First: Understand the Risk Profile

Security keys are designed to be phishing-resistant and hard to misuse. If someone finds your key, they typically still need your account’s username and password (or your device and screen unlock) to do harm. However, risks increase if an attacker already knows your login or has access to a trusted device. That’s why prompt action is important.

When the Risk Is Lower

  • The key is lost at home and likely not accessible to strangers.
  • You still possess at least one backup factor (another key, authenticator app, or recovery codes).
  • Your accounts require your password plus the key, and your password is strong and unique.

When the Risk Is Higher

  • The key was lost in public or may have been stolen with intent.
  • Your email or password manager is protected by that key and your master password may be guessable or reused.
  • You use the same password across services, or you recently experienced a data breach or phishing attempt.

Immediate Actions (Within the First Hour)

  1. Try to sign in using a backup factor. Use another registered security key, an authenticator app (TOTP), a built-in platform passkey (e.g., Face ID/Touch ID/Windows Hello), or printed recovery codes. Do this first for your primary email and password manager; these accounts control access to everything else.
  2. If you suspect theft, change your account passwords now. Start with the email that receives password resets, your password manager, banking and brokerage accounts, and any work SSO account. Use strong, unique passwords generated by a password manager.
  3. Review recent sign-ins and security alerts. Check security pages for suspicious activity, new devices, or login attempts. Sign out of all sessions if supported.
  4. Temporarily increase friction. For high-risk accounts, enable additional verification steps if available (e.g., require prompt approval, step-up authentication, or administrative approval flows on business accounts).

Secure Each Critical Account

Work through your most sensitive accounts in priority order: email, password manager, financial accounts, cloud storage, crypto exchanges/wallets, social media recovery handles, and work SSO/MFA.

1) Email and Password Manager

  • Regain access with your alternate factor or recovery codes.
  • Rotate your password to a new, unique one and confirm no unauthorized mail forwarding, filters, connected apps, or recovery addresses were added.
  • Re-register MFA: remove the lost key from the account’s MFA list and add at least two fresh methods (e.g., two physical keys plus an authenticator app). Store new recovery codes securely.

2) Banking, Brokerage, and Crypto

  • Log in with backup factors and update passwords.
  • Remove the lost key from your MFA devices list when you’re signed in.
  • Turn on alerts for new payees, transfers, withdrawals, trading, and login attempts.
  • Consider a temporary card lock or transaction limits if theft is suspected.

3) Work Accounts (SSO, Email, Admin Portals)

  • Notify IT/security immediately per policy.
  • Revoke the lost key in your enterprise identity provider (Okta, Azure AD/Entra, Google Workspace) and register new factors.
  • Confirm device compliance and re-approve trusted devices if required.

If You’re Currently Locked Out

If your only factor was the lost key and you can’t sign in, take these steps carefully so you don’t remove your last recovery path.

  1. Locate recovery codes you may have saved or printed earlier. Many services provide one-time codes precisely for this scenario.
  2. Try a registered backup factor like an authenticator app on a previous phone, a platform passkey on a laptop/phone, or a second key stored separately.
  3. Use account recovery workflows (identity verification via email, SMS, support tickets, or ID checks). Follow instructions exactly; multiple failed attempts can delay recovery.
  4. Do not delete the key from account settings from another connected service unless the platform specifically instructs you to. You generally need to be signed in to safely manage factors.
  5. Escalate to support with proof of identity if self-service fails. Be ready with IDs, prior billing info, device details, and any recovery email addresses.

When to Revoke the Lost Key

As soon as you’re back in each account, remove the lost key from the registered security keys list. This prevents anyone who might find it from using it as a second factor.

  • Revoke immediately if the key was stolen or lost in public.
  • Revoke after recovery if you needed the key to get back in; timing matters to avoid lockouts.

Replace and Rebuild Resilience

Aim for redundancy so a single lost key doesn’t create an emergency again.

  • Buy two replacement keys from reputable vendors. Register both on every critical account.
  • Store keys separately (e.g., one daily-carry, one in a secure home location or safe). Label them uniquely in each account’s settings.
  • Keep multiple backup factors: two physical keys, one authenticator app, platform passkeys on primary devices, and recovery codes stored offline.
  • Update your recovery plan: note where recovery codes are stored, how to contact support, and which device holds platform passkeys.

Strengthen the Rest of Your Setup

Losing a key is a reminder to close other gaps that could enable account takeover.

  • Use a password manager and rotate any reused or weak passwords.
  • Enable phishing-resistant MFA wherever available (FIDO2/passkeys). Avoid SMS codes as your only factor.
  • Secure your email recovery channels: verify recovery email/phone, remove outdated options, and review forwarding rules.
  • Lock down your SIM with a carrier PIN to reduce SIM-swap risk that could bypass some recovery flows.
  • Audit third-party app access and remove anything you don’t recognize or no longer use.
  • Turn on security alerts across accounts for new device sign-ins and changes to MFA or recovery info.

What If Someone Finds and Tries to Use Your Key?

A found key alone rarely grants access. Most platforms still require your password or a recognized device. However, if the finder also has your password (via breach, reuse, or phishing), they could attempt sign-in on sites where the key is enrolled.

  • Rotate passwords immediately for accounts that used the key, starting with email and password manager.
  • Revoke the lost key from all accounts after you regain access.
  • Watch for new device prompts, denial-of-service attempts, or repeated 2FA requests.

Handling Passkeys on Phones and Laptops

Some “security keys” are actually passkeys stored on your phone or computer using Face ID/Touch ID/Windows Hello. If you lost the device rather than a USB/NFC key:

  • Use the device’s find/erase tools (Find My iPhone, Find My Device) and ensure the screen lock is strong.
  • Remove the device’s passkeys from your account’s security settings after you erase or mark the device as lost.
  • Add new passkeys on replacement devices, and keep at least one hardware key as a portable backup.

Documentation to Prepare for Future Recovery

Prepare a simple, private checklist you can follow under stress:

  • Priority accounts list with URLs for security pages.
  • Registered MFA methods per account and which one is primary.
  • Where recovery codes are stored (e.g., printed and sealed, or in a secure, offline vault).
  • Support contacts and procedures for your bank, broker, email provider, employer, and phone carrier.
  • Serial numbers or labels of physical keys (do not store keys and the list together).

Common Mistakes to Avoid

  • Relying on a single key with no backup factor or recovery codes.
  • Deleting the lost key too early and locking yourself out before you’ve regained access.
  • Using SMS as the only backup, which can be defeated via SIM swapping.
  • Ignoring email security, even though it controls password resets across accounts.
  • Not monitoring for changes to recovery options, new devices, or app authorizations.

Monitor for Identity and Financial Misuse

If the key was lost alongside other personal items or after a phishing attempt, watch for broader identity risks. Keep an eye on credit, new-account openings, and unusual financial activity. Monitoring won’t stop fraud by itself, but it can alert you early so you can respond quickly with freezes, disputes, or reports.

After you’ve completed the steps above, you can optionally evaluate a consolidated monitoring tool that watches your credit and identity signals. If you want a single place to review alerts and changes, consider SmartCredit for privacy, credit monitoring, and identity protection as a next step.

Quick Reference: Step-by-Step Checklist

  1. Sign in with a backup factor to your email and password manager; rotate passwords.
  2. Review recent logins, revoke suspicious sessions, and enable security alerts.
  3. For each critical account: remove the lost key once you’re back in, then register at least two new factors.
  4. If locked out: locate recovery codes, try alternative factors, and use official recovery/support flows.
  5. Purchase two replacement keys; store them separately and label them in each account.
  6. Harden recovery: verify recovery email/phone, protect your SIM, and maintain printed recovery codes offline.
  7. Audit third-party app access and trusted devices; remove anything you don’t recognize.
  8. Monitor for financial or identity misuse and respond promptly to alerts.

Conclusion

Losing a security key doesn’t have to become an account takeover or a permanent lockout. Move fast to log in with backups, rotate passwords, review activity, and remove the lost key from each account once you’re safely back in. Then rebuild with redundancy—two physical keys, an authenticator app, platform passkeys, and printed recovery codes—so a single mishap never puts your most important accounts at risk again. Finally, keep monitoring for unusual changes to catch problems early and stay in control of your identity and privacy.

Good to Know

If your only second factor was the lost key and you can’t sign in, do not delete the key from account settings until you’re back in; removing it from outside your account won’t help and may cut off remaining recovery paths.