
Confirm the page before entering anything
Use the official app or type a known official address yourself. Do not follow recovery links from search ads, direct messages or emails. A person who asks for remote access, payment or a one-time code is not providing a normal recovery service.
If the password is rejected
Check the account identifier, keyboard layout, password manager entry and whether the account was created with email, phone or another sign-in method. If the password is still rejected, use the reset option on the official sign-in page. Do not keep guessing until the account is rate-limited.
Stop at the step that actually fails. If the password is accepted and the next screen requests a code you cannot obtain, changing the password again does not restore that verification method. Write down which method is unavailable and keep any working method available for the official recovery flow.
If an email or SMS code does not arrive
Check spam, mailbox storage, forwarding rules, mobile signal and whether the masked email or number belongs to you. Request one code and wait; repeated requests can make older codes invalid. Protect the email and mobile account independently.
There are two different problems here. If you still control the inbox or number, investigate delivery. If it belongs to an old phone number or an email account you cannot open, repeated requests will keep sending codes somewhere you cannot reach. Use the unavailable-verification option offered by the official page, or explain the lost method to official support. Never ask the current owner of a recycled number to forward your codes.
If the authenticator code fails
Confirm the correct account entry and automatic device time. Never send the authenticator seed or recovery code to support or a third party. If the device is lost, use the official factor-reset or account-recovery path.
Do not delete the old authenticator entry merely to tidy the app while you are locked out. Record whether it still generates codes and whether the phone was lost, replaced or reset. These are useful symptoms; the code itself is not something to put into a support message.
If a passkey is unavailable
Check whether you are using the device, browser profile or password manager where the passkey was stored. A passkey may depend on a screen lock or cloud account. If it cannot be recovered, use another official verification method shown on the page.
A fresh browser profile does not necessarily contain the same passkeys as your usual one. Check the device or provider you originally used before removing credentials or resetting multiple security settings. If both the passkey and its supporting device or cloud account are inaccessible, say so in the official case; do not install a remote-control app offered as a shortcut.
If the account is under review
Save the exact notice and follow the stated waiting period or document request. Do not create another account, change residence details or pay an “agent” to speed up the review.
If you can sign in but cannot withdraw, record that distinction. Access recovery and a withdrawal restriction are different problems. The official authenticator-change guide describes a temporary restriction after that security change; read the notice applying to your own account instead of treating every restriction as another login failure.
After access returns
- Change any reused or exposed password.
- Review email security, devices, sessions and authentication methods.
- Check recent orders, withdrawals, API keys and saved addresses.
- Remove anything you do not recognize and keep the official case number.
- Expect temporary withdrawal restrictions after sensitive security changes.
What to give official support
Provide the account identifier through the official form, the exact error, time and timezone, device or app version and any case number. Do not send passwords, verification codes, authenticator seeds, identity files unless explicitly requested in the secure case, or remote-control access.
If you also see unfamiliar withdrawals, devices or changed contact details, treat it as suspected account access by someone else. Use the official account-freeze or support route from a trusted device and follow the account security checks. Restoring your own login does not establish that every other session has ended.