What Happens to Passkeys If You Lose Your Phone?

Losing a phone does not automatically mean losing every account protected by a passkey. If the passkey is synchronized through Google Password Manager, iCloud Keychain, or another compatible password manager, it can usually become available on another trusted device after you securely restore access to that credential manager. If it is a device-bound passkey stored only on the missing phone, you must sign in with another approved method, remove the lost passkey, and create a replacement.
The urgent priorities are to lock or erase the missing phone, protect the Apple or Google account that synchronizes your credentials, and revoke passkeys or sessions associated with the lost device. Do not erase a device until you understand whether it contains your only sign-in and recovery method.
Quick answer: what happens to your passkeys?
- Synced passkey: It can be restored through the same credential manager on another device after account verification.
- Device-bound passkey: It stays on the lost device and does not automatically transfer. Use another passkey, security key, password, recovery code, or the service’s account-recovery process.
- Hardware security key: A passkey stored on a lost physical key remains tied to that key. Remove it from each important account and register a replacement.
- Stolen but locked phone: The passkey is normally protected by the phone’s screen lock and secure hardware. Your fingerprint or face is used locally to authorize access; the biometric itself is not sent to the website.
The outcome depends less on “passkeys” as a whole and more on where each passkey was stored and whether you prepared another route into the account.
Why this question matters now
Passkeys are moving from an optional feature to a mainstream sign-in method. The FIDO Alliance said on May 7, 2026 that it estimated five billion passkeys were in use worldwide.
Microsoft also began making passkeys the default authentication experience for eligible Microsoft Entra ID users on September 1, 2026. Users who rely on SMS or voice authentication can be prompted to register one during multifactor sign-in. Microsoft plans to retire its own SMS and voice delivery for Entra on February 1, 2027, although organizations can configure alternative telecom providers. Those dates come from Microsoft’s current Entra guidance.
That shift improves resistance to phishing, but it also makes recovery planning important. A passkey is easier and safer to use than a password only when you know whether it is synced, device-bound, or backed by another recovery method.
First: identify which type of passkey you use
Synced passkeys
A synced passkey is encrypted and synchronized by a credential manager. Common examples include iCloud Keychain and Google Password Manager. If one phone disappears, another authorized device in the same ecosystem may already have the credential or may receive it after you complete the provider’s secure recovery process.
Google says saved passwords and passkeys can be viewed and managed in Google Password Manager on Android, in Chrome, or at passwords.google.com. Apple says passkeys saved to iCloud Keychain are available across approved Apple devices.
Device-bound passkeys
A device-bound passkey is kept on one authenticator, such as a particular phone, a Windows Hello installation, an enterprise authenticator, or a FIDO2 hardware security key. It is intentionally not synchronized to another device.
Device-bound credentials can be the right choice for high-security or managed work accounts, but they need redundancy. If the device is gone and no alternative was registered, the account provider or company administrator must verify your identity and reset access.
What to do immediately after losing a phone with passkeys
1. Use a device-finding service
For Android, open Google Find Hub from another device. Select the missing phone and use the available option to locate, secure, or erase it. Google’s lost Android device instructions explain the prerequisites and actions.
For an iPhone, open Find Devices on iCloud.com or the Find My app on another Apple device. Mark the iPhone as lost. Lost Mode locks the device and lets you show contact information on its screen.
If the phone might simply be nearby, lock it before erasing it. A remote erase protects the data but can make recovery more complicated if that phone is your only trusted device or the only place where a device-bound passkey exists.
2. Protect the credential-manager account
Secure the Google, Apple, Microsoft, or third-party password-manager account that holds synced passkeys. From a trusted device:
- Review recently signed-in devices and unfamiliar sessions.
- Change the account password if someone may know it.
- Confirm that your recovery email and trusted phone number are still under your control.
- Remove the lost phone from trusted-device lists when the provider recommends doing so.
- Watch for unexpected recovery prompts, sign-in notifications, or SIM-transfer messages.
A strong screen lock protects the private key on the phone, but securing the cloud account prevents an attacker from attempting to synchronize credentials to a device they control.
3. Sign in from another trusted device
Try a computer, tablet, spare phone, hardware security key, or second passkey that you registered previously. Many sites also offer “Try another way,” which may reveal a password, recovery code, authenticator, verified email, or administrator-assisted route.
Avoid repeatedly guessing recovery details. Too many failed attempts can trigger delays or additional verification. Use the provider’s official website rather than a link sent in a text or email.
4. Remove the lost passkey from important accounts
After regaining access, open the security settings for high-value accounts first: primary email, Apple or Google account, password manager, banking, cloud storage, social networks, and work accounts.
For a Google Account:
- Open your Google Account.
- Select Security & sign-in.
- Under “How you sign in to Google,” choose Passkeys and security keys.
- Select the passkey associated with the lost device.
- Tap or click Remove.
These steps are documented in Google’s passkey guide. Removing a passkey from one account does not remove credentials registered separately with other websites, so repeat the audit for each important service.
If the account belongs to an employer or school, contact the help desk promptly. Administrators can revoke authentication methods and sessions without waiting for consumer account recovery.
5. Create a new passkey before removing your last working method
Once you have a replacement phone or computer, register a new passkey and test it in a private browser window. Only then remove credentials that no longer apply. Microsoft gives the same sequence in its passkey troubleshooting guidance: set up the new passkey first, then delete obsolete ones.
How passkey recovery works on Android and Google Password Manager
Passkeys saved in Google Password Manager can be available across compatible devices signed in to the same Google Account. Access still requires security checks, such as your device screen lock or the Google Password Manager PIN, depending on the device and encryption setup.
On a working Android device, open Settings → Google → Password Manager, or visit Google Password Manager in Chrome, to review saved credentials. Google’s cross-device password and passkey guide confirms that passkeys saved to the account can be managed on Android, Chrome, and passwords.google.com.
If no trusted device is available, recover the Google Account through Google’s official account-recovery process. A synchronized passkey cannot help until you can securely access the account that protects it.
How passkey recovery works on iPhone and iCloud Keychain
Apple synchronizes iCloud Keychain passkeys across approved Apple devices. If you lose one iPhone but still have a signed-in Mac, iPad, or another iPhone, the passkeys may already be available there.
If every Apple device is lost or unavailable, recovery depends on your Apple Account security setup. Apple says an account recovery contact can help recover iCloud Keychain when all devices are lost or stolen. You can prepare this at Settings → [your name] → Sign-In & Security → Recovery Contacts. See Apple’s iCloud Keychain recovery instructions.
Be careful with an Apple Account recovery key. Apple warns that enabling the 28-character recovery key disables its standard account-recovery process. If you lose both trusted access and the recovery key, you can be permanently locked out. Keep the key offline and somewhere other than iCloud, the Passwords app, Notes, Photos, or iCloud Drive.
What if the lost phone held your only device-bound passkey?
You cannot copy a device-bound private key out of a phone you no longer possess. The practical options are:
- Use a second registered passkey or hardware key.
- Select another sign-in method offered by the service.
- Use a recovery code stored somewhere safe.
- Complete the service’s identity-verification process.
- For work or school accounts, ask the administrator to reset your authentication methods.
The FIDO Alliance notes in its passkey FAQ that if the old device or security key is unavailable, account-recovery steps can be used. The exact fallback is controlled by each service, not by the passkey standard.
If a website offers no recovery route and the missing device held the only credential, access may be unrecoverable. This is why a second method should be added before removing the password from a critical account.
How to prepare before a phone is lost
Register more than one secure sign-in method
For primary email, cloud storage, financial accounts, and password managers, maintain at least two independent routes. Examples include a synced passkey plus a hardware security key, or two passkeys stored in different trusted ecosystems.
Do not keep every recovery method on the same phone. A screenshot of backup codes stored only in that phone’s gallery is not a real backup.
Update account-recovery details
Review recovery email addresses, trusted phone numbers, recovery contacts, and emergency access at least twice a year. Remove old work numbers and addresses you no longer control.
Store recovery codes offline
Print them, keep them in a secure physical location, or store them in an encrypted vault that can be accessed independently of the phone. Never share recovery codes with someone claiming to be technical support.
Label passkeys clearly
When a service lets you name credentials, use labels such as “Pixel 11,” “iPhone,” “Home Mac,” or “YubiKey backup.” Clear labels make it much easier to revoke only the lost credential during an emergency.
Test recovery while everything still works
Open a private browser window and verify that a second method can sign you in. Do not remove the working session or primary passkey during the test. The goal is to confirm redundancy, not simulate a lockout.
If you also rely on time-based verification codes, our guide explains how to transfer Google Authenticator without losing codes. For a missing or compromised social-media device, follow the steps to log out of Facebook on every device and secure the account. Travelers should also review how to assess public Wi-Fi before connecting.
Frequently asked questions
Can someone use my passkeys if they steal my phone?
Not normally without unlocking the phone. Passkeys are protected by the device’s authentication, such as a PIN, pattern, fingerprint, or face check. Risk increases if the thief knows the screen-lock code, the phone was already unlocked, or account recovery details are compromised. Mark the device lost and revoke its credentials promptly.
Are passkeys backed up automatically?
Only synced passkeys are designed to move through a compatible credential manager. Device-bound passkeys and hardware-key credentials do not automatically appear elsewhere. Check the provider and storage location rather than assuming every passkey is backed up.
Will changing my account password invalidate a passkey?
Not necessarily. Passwords, sessions, and passkeys are separate credentials. Use the account’s security dashboard to remove the missing passkey and sign out the lost device explicitly.
Should I remotely erase the phone immediately?
Erase it quickly if theft is likely or sensitive unlocked data is at risk, but first confirm that you have another recovery method when circumstances allow. Locking the device is often the safest immediate step while you assess whether it holds the only device-bound credential.
Is a passkey safer than an SMS code?
A properly implemented passkey is resistant to ordinary phishing because it is bound to the legitimate website or app and does not reveal a reusable secret. SMS codes can be phished, intercepted, or affected by SIM-swap fraud. Recovery still needs careful planning in either system.
The bottom line
If your phone disappears, secure the device first, protect the credential-manager account, sign in with another trusted method, revoke the lost passkeys, and register replacements. Synced passkeys usually provide redundancy across devices; device-bound passkeys require a second credential or formal account recovery. Set up that backup route now, before an emergency tests it for you.


