Most 2FA lockouts don't involve a hacker. They happen on trade-in day. You wipe the old phone, hand it over at the store, restore the new one from a backup, and then open your authenticator app to find it empty. The codes were never in the backup. They lived on the phone you just erased.
The fix is simple but unforgiving: move your authenticator before the old phone is wiped, and confirm the new phone works before you delete anything. This is the checklist for doing that in the right order, with the actual migration method for each major app, and the recovery path if your old phone is already gone.
Why your codes don't move on their own
Every TOTP code is generated from a secret key that a website handed to your phone once, when you scanned its setup QR code. That secret lives inside the authenticator app, and many apps deliberately keep it out of ordinary device backups because a backup is one more place a secret can leak from. Google Authenticator entries won't survive a phone-to-phone restore unless you use its export tool or its account sync. Microsoft Authenticator backs up to iCloud on iPhone and to your Microsoft account on Android, so an iPhone backup does nothing for a new Android phone.
Here's the reassuring part: the websites you log into have no idea which app generates your codes. They only know the shared secret. As long as the secret moves intact, you never have to touch a single account's security settings.
The safe order of operations
Do these steps in this exact order. The order is the entire point.
- Do not wipe, reset, or trade in the old phone yet. Keep it charged and able to unlock. Every step below assumes it still works.
- Take inventory. Open your authenticator and count the entries. Flag the ones that would hurt most to lose: your email account, password manager, banking, and work logins.
- Check your recovery codes. For those critical accounts, confirm you still have the one-time backup codes each service issued at setup. If you can't find them, generate fresh ones now, while logging in is still easy. Our guide to managing 2FA recovery codes covers where to keep them.
- Install an authenticator on the new phone. The same app, or a different one if you're switching. If you're choosing fresh, start with our authenticator app comparison.
- Migrate using the app's own method. Details per app below. Never retype secrets by hand if an export or sync path exists.
- Verify on the new phone. Not "the app shows codes" but real logins, covered in a moment.
- Only now wipe the old phone. A factory reset after verification, never before.
How migration actually works, app by app
Google Authenticator: QR export
Google Authenticator has a built-in transfer tool: open the menu, choose Transfer accounts, then Export accounts. It renders your selected accounts as one or more QR codes, roughly ten accounts per code, which you scan with the app on the new phone. The same export can be read by many third-party apps, not just Google Authenticator itself. We've written a full walkthrough of the process and its sharp edges in how to import Google Authenticator into another app. Google also offers sync through your Google Account; note that this sync historically hasn't end-to-end encrypted your secrets by default, so check Google's current documentation if that matters to you.
Authy: multi-device, not export
Authy has no export function at all. Instead, you enable Allow Multi-Device in its settings on the old phone, install Authy on the new phone, verify your phone number, and your tokens appear (you'll need your backups password if you set one). Once the new phone works, turn multi-device back off so a stranger can't add their own device later. Because enrollment hangs off your phone number, do this while you still control that number.
Synced apps: sign in and approve
Apps built around encrypted sync make migration the easy path rather than the exception. With Authenticator by Vidus6, for example, you install the app on the new phone and approve it from an existing trusted device; the vault then syncs end-to-end encrypted, with the encryption key never leaving your own hardware. This master-device model is exactly why step one of the checklist matters: the old phone is the approver, so it has to be alive when the new phone asks to join.
Steam, Battle.net, and other captive authenticators
Some codes don't live in your TOTP app at all. Steam Guard lives inside the Steam mobile app, and Battle.net's authenticator is built into the Battle.net mobile app. Those move with their own apps and their own sign-in flows, not with your authenticator. We cover the Steam case specifically in migrating your Steam authenticator.
Verify first, remove second
Seeing six digits tick over on the new phone is not verification. Two checks that actually mean something:
- Compare codes side by side. The same secret produces the same code at the same moment. If old phone and new phone show identical codes for an account, that entry migrated correctly.
- Do real logins. Sign out of three to five of your most important accounts and sign back in using only the new phone's codes. This catches the account you forgot to export far better than eyeballing a list.
Only after that should you delete entries from the old app or reset the phone. This isn't just tidiness. A traded-in phone with a live authenticator on it is a working second factor for whoever ends up holding it, and phones get resold with lock screens bypassed more often than anyone would like. Wipe it properly before it leaves your hands.
If the old phone is already gone
Lost, stolen, or wiped in optimism, the playbook changes from migration to recovery. Work through these in order:
- Recovery codes first. Any account where you saved backup codes can be reopened immediately: log in with a code, remove the old authenticator in security settings, and enroll the new phone.
- Hunt for live sessions. A laptop browser that's still signed in is a back door in the best sense. Go straight to that account's security settings, disable the old 2FA, and re-enroll.
- Use fallback methods. Some services let you verify by email or SMS. Take the win, then replace SMS with app-based codes once you're back in.
- Account recovery, last. Identity-verified support recovery can take days and doesn't always succeed. Start with your primary email account, because it anchors password resets everywhere else.
For the full playbook, including how to prepare so this never happens again, see avoiding account lockout.
FAQ
Will restoring my new phone from a backup move my codes?
Usually not, and you shouldn't count on it. Many authenticator apps exclude secrets from device backups, and cross-platform moves (iPhone to Android or back) break even the apps that do back up. Treat the authenticator as its own migration, separate from the phone restore.
Do I need to reconfigure 2FA on each website?
No. The websites only store the shared secret, and migration moves that secret unchanged. You only touch a site's security settings if a secret failed to transfer and you need to re-enroll from scratch.
How long should I keep the old phone before wiping it?
At minimum, until you've done real logins on your critical accounts from the new phone. If you can spare it, keeping the old phone in a drawer for a week of normal life catches the rarely-used account you didn't think to test.
The one-line version
Migrate, verify, then wipe, in that order and no other. Every authenticator horror story starts with someone doing it backwards. Ten careful minutes before trade-in day beats a week of account recovery forms after it.



