What to do if…
you lose a physical security key used for two-factor sign-in
Short answer
If the key might be lost outside your control, use another sign-in method to remove it from each account it protects. If it was for work or school, contact your official IT or security team now.
Do not do these things
- Don’t wait to remove the key if it may have been lost in a public place, vehicle, office, airport, gym, hotel, or shared space.
- Don’t turn off multi-factor protection entirely as the quick fix; remove the lost key and keep another second step active where you can.
- Don’t keep guessing or retrying logins if the service warns about lockouts or too many attempts.
- Don’t share backup codes, recovery codes, QR codes, screenshots, or security prompts with anyone who contacts you first.
- Don’t buy or register a replacement key from an untrusted seller because you feel rushed.
- Don’t use a password reset link or support number sent by an unexpected text, email, or chat message.
What to do now
-
Decide whether to treat it as lost or stolen.
If it was lost outside your home or in any shared place, treat it as lost or stolen for now. You can still keep looking, but securing accounts comes first. -
List the accounts the key could unlock.
Start with your primary email, password manager, work or school sign-in, banking and finance accounts, cloud storage, developer accounts, and any account that can reset other accounts. -
Start with your primary email and password manager.
Sign in using any other method already enabled, such as a backup security key, authenticator app, recovery code, trusted device, or provider-approved recovery route. -
Remove the missing key from the account.
Open the account’s security settings and look for wording such as “2-Step Verification,” “Security key,” “Passkeys,” “Security info,” “Two-factor authentication,” or “Sign-in methods.” Remove the entry for the missing physical key. -
Keep or add another second step before you move on.
If the account lets you add or confirm another second step, use one you control now. A backup security key or authenticator app is usually safer than relying only on SMS, but use the provider’s available options if you need immediate access. -
Check recent sign-ins for the high-impact accounts.
Look for unfamiliar devices, locations, sessions, or new sign-in methods. Use the service’s “sign out of all devices” or “revoke sessions” option if anything looks wrong, or if the key was lost with an unlocked device. -
Change passwords only where it helps.
Change the password for an account if the key was lost with a written password, recovery code, unlocked device, password manager access, or anything else that could help someone sign in. Use a strong, unique password. -
Repeat for the rest of the accounts on your list.
Work through the highest-impact accounts first: email, password manager, financial accounts, cloud storage, workplace sign-in, and accounts used for recovery. -
For a work or school key, use official internal help channels.
Ask IT or security to remove the lost security key or passkey credential, review recent sign-ins, and tell you the approved replacement process. Use your organization’s help portal, intranet, or known phone number, not contact details from an unexpected message. -
If you are fully locked out, use the provider’s official recovery page.
Look for wording such as “Try another way,” “Can’t use your security key,” “Account recovery,” or “Contact support.” Some providers may delay recovery checks, especially when two-factor protection is involved.
What can wait
- Ordering and enrolling a replacement key can wait until the missing key is removed from the most important accounts.
- Building the perfect setup with extra keys and cleaner recovery storage can wait.
- Auditing every low-impact account can wait until email, password manager, finance, cloud, and work or school access are secured.
- Deciding whether the incident formally counts as theft can wait; removing the key and protecting access is the immediate task.
Important reassurance
A missing security key is serious, but it is usually manageable. Once a key or passkey credential is removed from an account, that physical key generally should no longer be accepted by that service.
Scope note
These are first steps to stabilize access and reduce immediate account risk. Later decisions, such as incident reporting, workplace requirements, replacement hardware, or a better recovery setup, may need help from the provider, your IT team, or another specialist.
Important note
This is general information, not legal, financial, professional IT, cybersecurity, or other professional advice. Exact steps vary by provider, account type, and organization, so follow the official recovery and security guidance for each service.
Additional Resources
- Google — Sign in if you lost your security key
- Google — Stop using a security key
- Microsoft — Set up a security key as your verification method
- Microsoft — Removing a sign-in verification method
- Microsoft — Microsoft account security info & verification codes
- 1Password — Use your security key as a second factor for your 1Password account
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.