Reviewed guide | 2026-09-27
Moving Passkeys and Authenticator Codes to a New Phone Safely
A step-by-step order for migrating passkeys and authenticator codes to a new phone without locking yourself out of your exchange account, written for readers in Turkey. Includes what to check before wiping the old device, what to record, and when to stop.
Multiple exchanges | Turkey | TRY | fees, access and account safety
Changing phones is the moment most people discover how fragile their login setup really is. A passkey lives in a device keychain, an authenticator app holds time-based codes, and both can disappear the moment the old handset is reset, sold or lost. The mistake is treating the move as a copy-and-paste job. In practice it is a sequence: confirm what you can still log in with, add the new device alongside the old one, verify it works, and only then remove the old one. This guide walks through that order for an exchange account, using the help centre and account settings as your reference points rather than memory or screenshots from a forum. It applies whether you use a passkey, an authenticator app, or both in combination, and it assumes you are doing this calmly at home rather than in a panic after a phone has already died.
Before you touch the new phone: map your current setup
Start by writing down, on paper, exactly which methods currently unlock your exchange account. Open the security or account settings area and list every factor you see: password, passkey, authenticator app, SMS, email confirmation, withdrawal whitelist. Do not guess from memory, because the point of this exercise is to find the factor you forgot you enabled. Note which of those factors live on the old phone and which live somewhere else, such as a hardware key or a password manager on a laptop.
Next, confirm you can still perform a login on the old device right now, today, before anything changes. If the old phone is already broken or the authenticator app has been deleted, stop and go to the help centre rather than improvising, because the recovery path is different and usually slower. If login works, you have a working reference point, and that is what makes the rest of the migration reversible.
Finally, check whether your account has any pending state that a security change could interrupt: an open withdrawal, a pending verification review, a recently changed password. Security changes sometimes trigger a temporary hold on certain actions, so it is better to finish or cancel outstanding tasks first. Record the date and time you checked, so if something behaves unexpectedly later you can describe the sequence precisely to support.
Add the new phone as an additional device, not a replacement
The core principle is overlap. You want a window where both the old and the new phone can authenticate the same account, so that a failure on one side never leaves you with zero working factors. In the security settings, add the new device's passkey or authenticator entry while the old one is still active. Depending on the platform, adding a passkey may mean scanning a code shown on screen with the new phone's camera, or confirming through the device's own credential prompt.
When the exchange shows you a setup key or a recovery code for the authenticator, treat that string as the single most important thing in this whole process. Write it down on paper, store it separately from the phone, and do not photograph it and leave it in the same gallery you are about to migrate. A passkey and an authenticator entry are not the same thing: a passkey is bound to a device or a synced keychain, while an authenticator entry is generated from a shared secret. If you only add a passkey and later switch ecosystems, you may find the passkey does not follow you.
Expect the interface wording to differ between platforms and app versions. Labels such as security keys, two-factor authentication or login methods may group these features differently, so read the surrounding text rather than searching for one exact phrase. If a step asks you to confirm an email or enter a code from the old device, that is a good sign, because it means the old factor is still doing its job as a safety net.
Verify the new device before removing anything
Log out completely, then log back in using only the new phone. Do not accept a session that was already open, because an existing session can mask a broken factor. A full logout and login is the only honest test. If the login completes, immediately test one more sensitive action that your account allows, such as viewing the withdrawal address management page or initiating a small internal transfer, to confirm the new factor is accepted for more than just the initial sign-in.
Now test the old phone again. It should still work, and that is intentional. If the old device has already stopped working at this stage, you have lost your fallback while the new setup is still unproven, which is the exact situation this order is designed to avoid.
Record what you observed: the time of the successful login on the new phone, the time you confirmed the old phone still worked, and any prompt or error text that appeared along the way. Screenshots of error messages are useful, but keep them out of shared albums and cloud galleries. If anything fails repeatedly, stop adding or removing factors and contact support through the help centre with your timeline. Repeated failed attempts can themselves trigger protective restrictions, so a pause is cheaper than persistence.
Remove the old device, then re-check the recovery path
Only after the new phone has passed both tests should you remove the old device's passkey or authenticator entry from the account. Remove one factor at a time and re-test login in between, rather than deleting everything in a single sweep. If you hold multiple authenticator entries, deleting them all at once removes your ability to notice which one was actually in use.
Once the old device is removed, reset or sell it only after you have signed out of the exchange app, removed any saved credentials from its keychain, and cleared the authenticator app's data. A factory reset is the final step, not the first. Selling or handing on a phone that still holds a live authenticator secret is equivalent to handing over a spare key.
Finish by re-checking the account's recovery information: the email address and phone number on file, the backup codes you stored, and whether your withdrawal whitelist still reflects the addresses you expect. Update anything stale now, while you are still paying attention. Then store your written recovery material somewhere you would still have access to if your home, your phone and your email were all unavailable at the same time. If any part of that sentence is impossible to satisfy, that is the gap worth fixing next.
Risk boundary: Turkey Crypto Guide
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat. A referral link only records attribution; it does not guarantee access, pricing, rewards, approval or investment results. Availability can differ by residence, legal entity and product, so no regional access is assumed from language or branding alone.
Scenario checkpoint
- Write down every login factor currently enabled on the account before changing anything, taken from the security settings rather than memory.
- Confirm a working login on the old phone today; if it already fails, contact the help centre instead of improvising.
- Add the new phone's passkey or authenticator entry while the old one is still active, so both work at once.
- Copy the authenticator setup or recovery key onto paper and store it apart from the phone.
- Log out fully and log back in using only the new phone, then test one sensitive account action.
- Remove the old device's factor one at a time, re-testing login between each removal, and reset the old phone last.
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat.