Skip to main content

Lost or Stolen Device

The First Hour, in the Right Order

Your accounts matter more than the hardware. Revoke the device's access on every service first, then worry about the object. A lost Seedkeeper is protected by its PIN in the meantime, and once its registrations are removed it becomes an inert piece of plastic or ceramic.

First: How Bad Is It?

A stolen device alone is not access. Every applet is behind a PIN, verified inside the secure element, with a lockout after a handful of wrong attempts. Nobody is brute-forcing it, and nobody is extracting keys from the chip.

That buys you time to act properly rather than panic. It does not mean doing nothing.

The Order That Matters

Do these in sequence. The instinct is to start with the hardware, and it is the wrong end.

1. Sign In With Your Backup Device

If you registered a second device, use it now. You keep normal access to everything while you clean up, which removes all the time pressure from the rest of this list.

No backup device? Skip to step 2 and use your fallback methods - password, recovery codes, or the service's own recovery process.

2. Revoke the Lost Device Everywhere

This is the step that actually protects you, and it happens on each service, not on the hardware.

For every account where the lost device was registered:

  • Remove the passkey from the account's security settings
  • Remove the OTP method if that device generated the codes
  • Terminate active sessions, which often survive a credential removal

Work down your important accounts first: email, then anything financial, then everything else. See Passkey Recovery Strategy.

If you kept a note of which services the device was registered on, this is the moment it pays off. If not, work from your password manager or your inbox for registration confirmations.

3. Change What the Device Could Reveal

Passwords and secure notes on the device are behind the password manager PIN, so they are not exposed by the loss itself. Change anything you consider sensitive anyway if the circumstances of the loss worry you - a targeted theft is different from leaving it in a taxi.

Seed phrases deserve their own judgement. If the device held one and you have any doubt, move the funds to a new wallet - see Common Seed Phrase Mistakes.

4. Then Deal With the Hardware

Report it if it was stolen. Order a replacement. Update your inventory if you are managing devices for an organisation - see Employee Onboarding and Offboarding.

If You Had No Backup Device

Harder, but not hopeless. Work service by service, using each one's recovery process:

  • Sign in with your password where the account still has one
  • Use recovery codes if you saved them when enabling two-factor authentication
  • Use the service's account recovery as a last resort, which typically runs through your email

That last point explains why securing your mailbox first matters so much: it is the recovery path for everything else, and it is the account you most need working right now.

Once you are back in each account, remove the lost device's registrations and register the replacement - two devices this time.

Restoring Your Data

Passwords, notes and seed phrases come back from a Backup device onto a new one - see Backup & Recovery.

Passkeys do not transfer. A hardware-bound passkey exists only on the device that created it, so a replacement means registering fresh passkeys with each service - see Lost Passkey Access.

OTP codes return only from the original QR codes if you saved them - see Lost OTP Access.

If It Turns Up Later

Do not put it back into service as though nothing happened. You do not know where it has been, and its registrations are gone anyway.

Reset it and treat it as a blank device - see Resetting Your Seedkeeper. It then makes a perfectly good backup for the replacement you just set up.

Making the Next One Painless

Everything above is easier with one thing in place: a second registered device.

With one, a loss is an afternoon of tidying up. Without one, it is a recovery process on every account you own, starting with the ones you need most urgently.

The other half is knowing where the device was registered. A short list - service, device, date - turns step 2 from a memory exercise into a checklist. See Passkey Backup Strategy.

One device is a single point of failure

A backup Seedkeeper takes ten minutes to set up and removes the one real risk of hardware security: losing the only device that holds your credentials. Card, ring, or one of each - they pair in any combination.


Add a backup device

FAQ

What should I do first if my Seedkeeper is stolen?

Revoke its access on your services, starting with your email account. The hardware is protected by its PIN, so the urgent work is on the account side, not the physical one.

Can someone use my stolen Seedkeeper?

Not without the PIN, which is verified inside the secure element and locks out after a handful of wrong attempts. Possession alone is not access.

Does deleting a passkey from the device revoke it?

You would need the device to do that, which you no longer have. Revocation happens on each service, in its security settings, and works whether or not you hold the hardware.

I had no backup device - what now?

Work service by service using each one's recovery process: password, recovery codes, or account recovery through your email. Secure the mailbox first, since it is the reset path for the rest.

My device turned up after I replaced it. Can I reuse it?

Reset it first and treat it as blank. Its registrations are gone anyway, and it then makes a good backup for the replacement.

Still stuck?

If none of the above resolved it, open a support ticket and tell us what you tried - the steps you followed and what happened instead. We read every one, and a clear description usually gets you a straight answer rather than a round of questions.

Open a support ticket