All articles
Security · 7 min read

Two-Factor Authentication and Account Sales: What to Do Before Selling

Two-factor authentication is what turns a stolen password into a useless string of characters — which is exactly why it's the trickiest part of any legitimate account handover. This guide covers how each 2FA method behaves during a sale, and the correct order of operations to avoid lockouts.

The four 2FA methods you'll encounter

  • SMS codes. Convenient but the weakest form; vulnerable to SIM-swap and tied to a phone number that's usually the seller's personal number.
  • Authenticator apps (Google Authenticator, Authy, 2FAS). A time-based code generated from a seed stored on the device.
  • Hardware keys (YubiKey, Titan). Physical device that must be plugged in or tapped for login.
  • Backup codes. One-time codes issued at 2FA setup, meant for recovery when the primary method is unavailable.

What must change during handover — always

  1. The email address on the account.
  2. The password.
  3. The 2FA method, seed, and any backup codes.

Anything less and either side retains a re-entry path into the account after the sale. That is the exact vulnerability that produces "buyer paid, account recovered a week later" disputes.

SMS 2FA: the tricky one

A phone number cannot be handed over the way an email address can. Two workable paths:

  • Seller disables SMS 2FA during the handover session, and buyer immediately enables authenticator-app 2FA on their side before doing anything else.
  • Both sides switch the account to a virtual number (Google Voice, TextNow, MySudo) that the buyer controls. Do this in-session, not before.
Do not just leave your personal number on the account "for a few weeks until it settles". The account can be recovered to your phone at any time, and the buyer has no way to know that until it happens.

Authenticator apps: the cleanest handover

  1. Seller removes 2FA from the account entirely.
  2. Buyer signs in, immediately re-enables 2FA using their own authenticator app.
  3. Buyer generates and saves a fresh set of backup codes.

Never share the QR code or seed of your authenticator setup with the buyer. Sharing the seed means both parties can generate valid codes forever — which is exactly what you're trying to prevent.

Hardware keys

Hardware keys cannot be transferred meaningfully — the buyer needs their own physical key. The seller unregisters their key from the account, the buyer signs in with the temporary window (usually authenticator-app fallback) and registers their own key.

Backup codes are as sensitive as the password

Every backup code is a permanent, one-shot bypass of 2FA. If backup codes generated during the seller's ownership still exist anywhere, the account is not truly secure. Standard practice:

  1. Seller invalidates all existing backup codes at the end of handover (usually by regenerating them, then discarding the new set).
  2. Buyer generates a fresh set after re-enabling 2FA on their own device.

Recommended order of operations

  1. Escrow confirms funds are held.
  2. Seller: change account email to a fresh handover inbox.
  3. Seller: disable 2FA on the account.
  4. Seller: hand over inbox login (email + password + inbox 2FA) via the escrow chat.
  5. Buyer: sign in, change email to their own, change password.
  6. Buyer: re-enable 2FA using their own authenticator app or key. Save new backup codes.
  7. Buyer: confirm access. Escrow releases funds.

What good escrows do at this stage

Every step above happens with the escrow watching the chat log in real time. If one side pauses at the "seller shares credentials" step and the other side then vanishes, the escrow sees exactly when the deal broke and mediates from evidence, not from claims. That's why the process is worth doing inside an escrow chat rather than a private DM.

Advertisement

Frequently asked questions

Should I disable 2FA before selling an account?

+

No — leave 2FA on and instead reset the second factor to a brand-new authenticator app or phone number that you will hand over to the buyer during the escrow. Fully disabling 2FA leaves the account vulnerable during the window between listing and sale.

What is the safest way to transfer 2FA to a buyer?

+

Log out of every session, remove existing authenticator devices, then let the buyer scan a fresh QR code live over screen share while the escrow is funded. The buyer confirms they can generate a code, then you release credentials.

What happens if the seller keeps a 2FA backup after the sale?

+

They can trigger a recovery flow and steal the account back. That is why the first thing a buyer must do — inside 30 minutes of receiving credentials — is regenerate 2FA, rotate the password, and update backup codes so any old recovery method the seller kept becomes useless.

Trading a digital asset and want a human coordinator in the middle?

Start a SafeEscrow trade