Why should I never share a one-time code?

A one-time code - the six digits texted or generated when you log in or reset a password - is the final key to an account. It is valid for only a minute or two, and it belongs to whoever owns the account. Anyone who asks you to read one out is trying to get into an account. Every time.

Why the "share the code" trick works

  • A code sent to you is for your account. Read it to someone else and they can finish logging in, or reset your password and lock you out.
  • The message often looks like a friend. A hacked account messages its whole contact list: "the code went to your number by mistake, can you send it?" The person typing is not your friend - it is an attacker working through their contacts.
  • No genuine service asks for it. Banks, shops, and support lines will never call or message to ask for a code you have received.

What to do instead

  • Never share a code with anyone - not a friend, not "support", not someone who phoned you.
  • If a code arrives that you did not request, treat it as a warning that someone has your password and is trying to log in. Change that password.
  • If a friend's message asks for a code, reach them another way - their account is likely hacked.

If you already shared one

  1. Change the password on that account immediately, and turn on two-factor authentication.
  2. Check where you are signed in and remove anything you do not recognise.
  3. Warn the friend whose account was used, on a different channel.

Related: How can I tell if a message is a scam?

← All guides

General information, correct when last reviewed. Platforms and threats change - always confirm critical steps on the official source. Product names are used only to describe their features; Monkleton Labs is not affiliated with, or endorsed by, them. No ads, no affiliate links.