Getting started

No-KYC account recovery: which losses are survivable, which are final

With no identity on file, nobody can vouch for you. Which credential losses are survivable, which are terminal, and the ten minutes that decide.

By CryptoCard · 2875 words · about 13 min · updated

Contents

The safety net went out with the identity file

Every account recovery you have ever done worked the same way. You proved you were the person named in a file the provider opened when you signed up: a passport scan, an address, a phone number, the answer to a question you gave them years ago. The file is what made recovery possible.

A no-KYC account has no file. Opening one takes an email address and a password, and that is the complete list of what exists on our side about you — plus your balance, your cards and your transaction history. There is no name, no phone number, no document, and no home address once a physical card has shipped.

People read that as a privacy feature, and it is one. It is also, in exactly the same sentence, the removal of every recovery route you are used to. The two are not separable, and any provider telling you otherwise has either kept a file or is about to.

The usual proofAt a bank or an exchangeHere
A photo IDMatched against the document scanned when the account was openedNever collected — there is nothing on file to match it against
A home addressA utility bill checked against the address on recordNot on file. A shipping address is erased the moment a card is dispatched
A phone numberA one-time code sent by SMS to the recorded numberNo number on the account, deliberately — that is why codes go to email
Security questionsAnswers collected at signup and stored against the accountNever asked, so never stored
A support decisionAn agent weighs the evidence and restores the accountThere is no evidence to weigh, so there is no decision to make

So the useful question is not "what does support do if I get locked out". Support cannot do anything, and a service that could would be a service holding your passport. The useful question is the one this guide answers: which credentials actually open the account, and which combinations of loss are survivable?

It is worth ten minutes before your first $100 goes in, rather than after.

What actually opens the account

Three credentials exist. Not four, and the third one only if you turned it on.

  • Your mailbox. The address is the account's only identifier. It receives the password reset link, and — this is the part people miss — the six-digit 3-D Secure code that authorises online payments. It is not a contact detail. It is a key.
  • Your password. Between 8 and 200 characters, stored as a bcrypt hash. It is required again, on top of your session, to change your email address, to change the password itself and to close the account — so someone who steals a live session still cannot lock you out of your own account.
  • Your authenticator, if two-factor is on. A standard TOTP secret, six digits rotating every thirty seconds, readable by any authenticator app. The tolerance is one period either side, so a clock about half a minute out is forgiven and a clock further out is not.

Turning two-factor on is deliberately two steps: the secret is generated and held aside, and it only becomes real once you type a valid code from the app back into the page. You cannot end up with two-factor half-enabled on a secret you never actually scanned — a failure mode that has locked people out of other services on the first attempt.

At that same moment, and only at that moment, you are shown ten recovery codes.

The recovery matrix: what survives what

Nobody loses "the second factor". People lose a phone — which takes the authenticator and, if they photographed the codes, the codes with it. So the question worth answering is not what each credential does on its own, but what is left standing after a realistic accident.

Read the row that matches what you lost. Five of these seven are survivable.

What you lostThe way back inWhat to do
The passwordYour mailbox, then your authenticatorAsk for a reset link on the sign-in form, then answer the second-factor prompt as usual.
The authenticatorThe password plus one recovery codeSign in, enter a recovery code where the six digits go, then generate a fresh set immediately.
The recovery codesThe password plus the authenticatorSign in normally and generate ten new ones. The old ten die at that moment, used or not.
The mailboxThe password plus the authenticatorSign in — login never touches the mailbox — and change the address in Settings while you still can.
Password + authenticatorThe mailbox plus one recovery codeReset the password by email, then use a recovery code at the second-factor prompt.
Mailbox + passwordNothingA reset link is the only way to set a new password, and it is delivered to the mailbox.
Authenticator + codesNothingThis is the terminal one. No document exists to prove the account was yours.

Two rows say Nothing, and they are the whole reason this page exists.

The first, mailbox and password together, is unintuitive. Losing the mailbox alone is fine: signing in does not touch it, so you log in with your password and your authenticator and change the address in Settings. Losing the password alone is fine: the reset link fixes it. Losing both at once removes every route, because setting a new password requires a link that only the mailbox receives.

The second, authenticator and recovery codes together, is the classic one and it is final. The password still works, the mailbox still works, and neither is enough: the second-factor prompt accepts a valid TOTP code or an unused recovery code, and nothing else. There is no third path, because a third path is precisely what an identity document would be.

The ten codes, and the four ways they die

They look like this — XKF7Q-M2RJD — ten characters split by a hyphen, drawn from an alphabet with no capital I, no capital O, no zero and no one, so a code copied off paper cannot be mistyped in the usual way. You get ten. Each works exactly once, at the second-factor prompt, in place of the six digits from the app.

They are stored as hashes. We hold a fingerprint of each code, never the code, which means nobody here can read one back to you over email — including someone who has just taken over our support inbox, which is the reason it works that way. It also means that if you lose them, they are gone in the strong sense of the word.

Four things kill a set of codes, and only the first is obvious:

  1. Losing the paper. The expected one. Print or write, then store somewhere that is not the desk drawer next to the laptop.
  2. Storing them on the phone that runs the authenticator. A screenshot in the camera roll of the device holding your TOTP app is not a backup. It is the same single point of failure wearing a second hat — and it is the exact accident that produces the terminal row of the matrix.
  3. Generating a new set and keeping the old print. Regenerating replaces all ten. The previous ten are dead at that instant, used or not, and the paper in your safe now looks perfectly valid and opens nothing.
  4. Switching two-factor off. Turning it off deletes every recovery code on the account. Turning it back on issues ten new ones. Any print from before the gap is worthless.

Three and four are the quiet ones, because nothing tells you a printout has expired. If you cannot remember whether the sheet in your drawer belongs to the current set, it costs nothing to sign in and generate a fresh ten — and it costs the account to assume.

The mailbox is the account, not a contact field

On an ordinary financial account, the email address is where receipts go. Here it is load-bearing, and it carries more weight than most people notice until it fails.

It receives the password reset link. It receives the 3-D Secure code for every online payment that asks for one — because there is no phone number to text. It receives the security notifications that tell you a login happened. Lose control of it and you have not merely lost a way back in: you have lost the ability to complete a checkout, on an account whose balance is otherwise perfectly intact and still earning 4% a year.

Which produces two failure modes, and they need opposite defences.

You lose access to the mailbox. The provider closes it for inactivity, the domain lapses, the address belonged to an employer, the disposable inbox you used at signup expires. Nothing on our side breaks — you can still sign in — but you must change the address before the old one is gone, and doing that asks for your current password. Do it the day you know, not the day it stops working.

Someone else gains access to the mailbox. They can request a reset link and set a new password. If two-factor is off, that is the entire attack and the account is theirs. If two-factor is on, the reset gets them to the second-factor prompt and stops there, holding a password that is now wrong for you but useless to them. This single scenario is the whole argument for two-factor on a no-KYC account: it is the only thing standing between a compromised mailbox and a spendable balance.

So the address to use is not the throwaway you signed up with in ninety seconds. It is one you will still control in five years, on a provider that will not reclaim it for inactivity, protected at least as well as this account is. Changing it takes one screen — Settings → Account — and your password.

The ten-minute setup, in order

Do these in sequence, once, before the account holds anything worth losing. Steps five and six are the ones almost everybody skips, and they are the two that decide whether the rest was worth doing.

  1. Pick a mailbox you will still hold in five years. Not a disposable address, not a work address, not one on a domain you rent. It is a credential; treat it like one.
  2. Use a password unique to this account, generated by a password manager rather than by you. It is the one credential that unlocks changing the other two.
  3. Turn on two-factor in Settings → Two-factor authentication. Scan the QR code with any authenticator app and confirm one code.
  4. Save the ten recovery codes at the moment they appear. They are displayed once. Copy them into the password manager, and put a printed copy somewhere physical.
  5. Keep the codes off the phone that runs the authenticator. If the same accident can take both, you do not have a backup — you have one credential stored twice.
  6. Test one. Sign out, sign back in, and at the second-factor prompt use a recovery code instead of the app. It burns one of the ten and proves the sheet in your drawer belongs to the current set. Nine remain, which is eight more than anyone needs.
  7. If you use the API, treat the key as the account itself. It can issue cards and spend the balance without touching your password or your second factor. Keep it server-side, and rotate it the moment it might have leaked — a rotation takes effect on the very next request, with no grace period.

Ten minutes. Compare that with the alternative, which is not a support ticket but a permanent loss.

Locked out, but not lost: what to try before you panic

Most lockouts are not the terminal row of the matrix. Three of them look identical from the outside and are all temporary.

Too many attempts. Failures are throttled at 8 per email address and 20 per IP address within 15 minutes, and while the throttle is on, correct credentials are refused along with wrong ones. It clears by itself. Wait a quarter of an hour and try once, carefully — a successful sign-in clears the counter immediately, while another twelve guesses will not.

A code the app says is right and the site says is wrong. That is almost always the clock. The window is one period either side, which forgives roughly half a minute of drift and nothing beyond it. Turn on automatic time on the phone, wait for the next code, and try again. Nothing is wrong with the account.

A reset link that will not open. Each one lives 45 minutes and works once, and asking for a second link kills the first — so if you clicked twice out of impatience, the older mail in your inbox is the dead one. Take the most recent, and use it while it is fresh.

And the case that is genuinely terminal: the authenticator is gone and the recovery codes are gone. There is no ticket to open. The balance does not expire, there is no inactivity fee and nothing is swept, so the money continues to sit there earning 4% a year in an account nobody can open. That is not a comfort, it is an accounting fact, and it is the honest end of the no-KYC bargain: the same absence of a file that stops anyone from identifying you stops us from identifying you too.

Which is exactly why the ten minutes above are worth spending, and why we would rather write this page than answer the email.

Frequently asked questions

What happens if I lose access to my no-KYC account?

It depends on what you lost. A forgotten password is fixed by a reset link sent to your mailbox. A lost authenticator is fixed by one of your ten recovery codes. Losing your mailbox and password together, or your authenticator and recovery codes together, is terminal — there is no identity document on file to verify you against, because none was ever collected.

Can support restore my account if I prove who I am?

No, and it is worth understanding why rather than hoping otherwise. There is nothing on file to prove anything against: no name, no phone number, no document, no address. An account we could restore on request is an account someone else could take on request, and the only thing that would make it safe is the identity file this service does not keep.

I lost my phone. Is the account gone?

Not on its own. A phone takes the authenticator with it, and the password plus one recovery code gets you back in. Sign in, use a recovery code where the six digits go, then generate a fresh set of ten straight away and re-enrol your authenticator on the new device. The account is only lost if the codes were also on that phone.

Where should I store the ten recovery codes?

Two places, neither of them the phone running the authenticator: in your password manager, and printed on paper somewhere physical. The test is simple — if a single accident, a theft or a fire could take both your second factor and your codes, you have one credential stored twice rather than a backup.

Does resetting my password get me past two-factor authentication?

No. The reset link sets a new password and nothing more; sign-in then asks for your authenticator code or a recovery code exactly as before. That separation is deliberate, and it is what stops someone who has taken over your mailbox from also taking over your balance.

How long is the password reset link valid?

Forty-five minutes, and it works once. Requesting a new one invalidates any link still outstanding, so if you clicked twice, the older email is the dead one — always use the most recent. Whether or not an address has an account here, the reset form returns the same answer, so the page cannot be used to find out who has one.

Are the recovery codes I printed last year still valid?

Only if you have not regenerated them and have not switched two-factor off since. Generating a new set replaces all ten immediately, and disabling two-factor deletes them entirely. Neither event marks the old sheet, so if you are unsure, sign in and generate a fresh ten — it costs nothing and removes the doubt.

Why am I locked out after entering the right password?

Repeated failures are throttled at 8 per email address and 20 per IP address within a 15-minute window, and while the throttle is on it refuses correct credentials too. It clears on its own — wait fifteen minutes and try once. If your authenticator code is being rejected instead, check the phone's clock: the window tolerates about half a minute of drift and no more.

Can I change the email address on the account?

Yes, in Settings → Account, and it asks for your current password. Do it while you still control the old mailbox rather than after you have lost it — signing in does not require the mailbox, so a lost address is recoverable right up until you also lose the password.

Is my balance safe if I never log in for a year?

Yes. There is no inactivity fee, no dormancy charge and no expiry, and the balance keeps earning 4% a year while it sits. Nothing about a long absence puts the money at risk — the only thing that does is losing the credentials that open the account.

Product references and further reading

Published by CryptoCard. Product terms, eligibility and third-party features can change; use the linked reference for the current details.

Get your card

An email address, a first top-up from $100, and the card is live. No document, no phone number, and the first virtual card is free.

Keep reading