2FA Setup

What to Do If You Run Out of Binance 2FA Backup Codes? Emergency Response

How to use and securely store your 8 Binance 2FA backup codes, how to regenerate them, and the emergency process when you run out of all codes.

When enabling 2FA, Binance provides 8 one-time backup codes. This article explains how to use them and how to store them. Download entry: Binance Website, mobile Binance Official App. If you haven't installed the iOS app, see the iOS install guide.

I. What Are Backup Codes?

When you enable Google Authenticator, Binance displays eight 6-digit backup codes. Each code can only be used once. When your Authenticator is not around or becomes invalid, a backup code can replace the verification code to log in.

II. Storage Methods

Recommended

  • Print them on paper
  • Label them and place them in a safe
  • Do not store them on the same device as your Authenticator

Not Recommended

  • Taking a screenshot and saving it to the phone's gallery (which syncs to iCloud / Google Photos)
  • Copying them into a notes app (unless encrypted)
  • Emailing them to yourself (if the email is compromised, they are exposed)

Compromise Solutions

  • Encrypted ZIP file + strong password
  • Or printing them out + keeping them in a small box inside a drawer

III. How to Use Backup Codes

When logging in, if your Authenticator says "Unavailable / Unbound / Incorrect Time":

  1. Select "Use backup code" on the login page
  2. Enter one 6-digit code
  3. The used code becomes invalid immediately

IV. What to Do When They Run Out

After all 8 codes are used, there is no mechanism to generate more automatically. You must:

Method 1: Regenerate While the Authenticator Still Works

If your Authenticator is still functional:

  1. Account Security → Reset 2FA
  2. Rebind the Authenticator (the same one or a new one)
  3. You will be shown 8 new backup codes again

However, resetting 2FA triggers a 24-hour lock—during which you cannot withdraw funds.

Method 2: Contact Support for the "Lost 2FA" Process

If your Authenticator is invalid and the backup codes are exhausted:

  1. Submit an "Unable to use 2FA" ticket
  2. Provide proof of identity
  3. Wait 24-72 hours for review
  4. After support resets it, bind a new Authenticator

V. Security Risks of Backup Codes

The 8 codes themselves are targets for attacks:

Risk 1: Leakage

If stored in the cloud and stolen → attackers can bypass your Authenticator.

Risk 2: Forced Disclosure

In scenarios of physical threat. It is advised to keep the storage location unknown to all family members.

Risk 3: Forgetting the Location

If placed in a safe and you forget the password / lose the key → unusable in an emergency.

VI. Best Practices

1. Save Immediately When Enabling 2FA

Do not "save it for later"—you will likely forget, and cry when the Authenticator fails.

2. Multiple Backups

Have at least two copies in different physical locations.

3. Regular Updates

When rebinding 2FA, you get new backup codes; discard the old ones.

4. Pair with a Hardware Key

A YubiKey is a more reliable fallback. Backup codes + YubiKey provide double protection against Authenticator failure.

VII. When to Use Backup Codes

Recommended Usage

  • Forgot your Authenticator device during a business trip
  • The Authenticator device is temporarily broken
  • The Authenticator time is desynchronized

Not Recommended Usage

  • To save effort in daily use (each time you use a code, you lose one)
  • If used frequently, replenish new codes as soon as possible

VIII. Emergency Response Plan

In the worst-case scenario where you have no backup codes + Authenticator is invalid + cannot receive SMS:

  1. Go through the full identity verification process with support
  2. Provide: ID card / KYC video / historical login evidence
  3. Wait 5-15 business days
  4. After support completes the reset, all 2FA will be reset

During this period, your account assets are safe (attackers cannot log in either), but you cannot use them either.

FAQ

Q1: Can backup codes be reset? Yes. Rebinding the Authenticator will display 8 new ones.

Q2: What do backup codes look like? Usually 6-digit numbers, each independent.

Q3: Do all backup codes expire? Unused backup codes remain valid indefinitely. They only expire when you reset 2FA.

Q4: Can a backup code be used multiple times? No. Each one is strictly for one-time use.

Further Reading

Keep going

After this article, head back to the topic index and pick up the next piece in the same category.

Topics

Related security guides

2FA: Google Authenticator, SMS, or Hardware Key? 2026-04-21 How to Bind Google Authenticator for Binance 2FA? Where to Back Up the Setup Key 2026-04-18 What to do if you can't receive Binance SMS verification codes? Carrier blocking and roaming 2026-01-31 What to Do When Binance 2FA Codes Are Always Wrong? Time Sync is the Culprit 2026-01-28