What to do if you lose your phone: recovering 2FA codes, passkeys and passwords
SHORT ANSWER
What happens to my authenticator codes, passkeys and passwords if I lose my phone?
Anything stored only on that phone is gone unless you made an encrypted backup. HostSpica cannot recover it for you, because it never has your data or keys. With a backup and its passphrase you can restore 2FA accounts and Vault entries on a new phone. Device-bound passkeys cannot be restored; sign in another way and create new ones.
Key takeaways
- Recovery is something you set up before the phone is lost. Afterwards it is mostly too late.
- A HostSpica backup restores 2FA accounts and Vault entries, not passkeys.
- We cannot reset your backup passphrase or open your data, by design.
- The first hour matters most: lock the phone, secure your email and key accounts, and use recovery codes.
Prepare now, in five minutes
- Make an encrypted backup. In HostSpica Identity open Settings and choose Back up everything. Use a long passphrase and save the file somewhere that is not on the phone.
- Store the passphrase separately from the file, for example in a password manager or on paper in a safe place. We cannot recover it.
- Save recovery codes for every important account (email, banking, cloud storage) offline.
- Have a second sign-in method on important sites, for example an authenticator app on a second device, or a passkey on another device.
- Turn on Find My Device (Google) so you can lock or erase a lost phone.
The first hour after losing it
- Lock the phone remotely with Find My Device, or use your phone's remote lock. A phone locked with a screen lock keeps your data encrypted, and HostSpica asks for your fingerprint, face or screen lock each time it opens.
- Secure your email account first, because most other accounts reset through it. Sign in on another device, check recent activity and change the password.
- Move your phone number to a new SIM through your carrier and add a PIN for the account, so nobody else can take it over.
- Sign in to your key accounts with recovery codes or another method, then remove the lost phone from their trusted devices.
Restoring HostSpica on a new phone
- Install HostSpica Identity from Google Play and open it.
- Open Settings and choose Restore from backup, pick your backup file and enter the passphrase.
- 2FA accounts and Vault entries come back. Entries already on the phone are skipped, so restoring twice does not duplicate anything.
- Check a few codes against their sites before you trust the restore.
Passkeys are different
HostSpica passkeys are device-bound: their private keys live in the phone's secure hardware and cannot be exported, so no backup can contain them. After a loss, sign in to each site another way, delete the lost passkey in the site's security settings, and create a new one on the new phone. Passkeys synced by a cloud account, such as Google Password Manager, come back through that account instead.
Frequently asked questions
Can someone use my codes if they find my phone?
Not without unlocking it. The phone's screen lock protects it, and HostSpica asks for fingerprint, face or screen lock when it opens. Someone who knows your phone's PIN can get further, so choose a PIN nobody else knows.
I have a backup but forgot the passphrase. Can HostSpica help?
No. The passphrase is never stored, and the backup cannot be opened without it.
Should I keep the backup file on the same phone?
No. A backup on the lost phone is lost with it. Keep a copy elsewhere.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED