Monero only. BlackOps settles in one coin and keeps several onion addresses live. Free to read · no account · nothing collected
12 database entries · 5 guides
3 verified addresses
Overview Database Guides Addresses FAQ About

Home / Database / Account and login

Locked out after losing the PGP key used for two factor Serious

Two factor is enabled and the key that signs the challenge is gone.

PGP two factor is the strongest protection on the account and it cuts both ways. If the private key is gone, the challenge cannot be signed, and knowing the password does not help.

What you can try

  1. Look for a key backup before anything else, including old machines and any encrypted archive you keep
  2. If the key exists but the passphrase is forgotten, treat that as the same problem and check password manager entries
  3. Use the recovery route the market provides, which is why the recovery phrase belongs on paper
Watch out. Back the key up on paper or offline storage the day you generate it. A key that exists in exactly one place is a key you are going to lose eventually.

Why it is still worth enabling

Without two factor a leaked password is the whole account. With it, a leaked password is an inconvenience. The lockout risk is real and it is managed with a backup, while the credential theft risk cannot be managed any other way.

Why two factor cannot be bypassed for you

The point of signing a challenge with a key is that only the key holder can do it. If a market could lift that requirement on request, anybody able to convince support they were you could do the same, and the protection would be worth nothing. So the same property that makes it strong is the property that makes a lost key painful.

That is a reason to back the key up rather than a reason to leave two factor off. Without it, a password leaked anywhere is the entire account. With it, the same leak is an inconvenience. The lockout risk is manageable with one copy stored offline, and the credential theft risk is not manageable any other way.

What not to do

  • Do not paste a private key into any web page for any reason
  • Do not accept help from somebody offering to restore access for a fee
  • Do not store the only copy of the key on the same machine you use to sign in
Related entries
SeverityProblemAreaLikely cause
CommonThe login rejects a password you know is correct
Credentials that worked before are refused.
Account and loginA cloned page, a stale session, or a two factor step not being completed.
SeriousPassword forgotten and the recovery phrase is missing
No password and no written recovery phrase.
Account and loginThe recovery phrase is the only route back and it was never stored.
CommonBlackOps will not load at all
The address times out or the page never finishes loading.
Access and loadingA degraded Tor circuit on your side, or a flood against that specific address.