Bank of America SafePass Card Token Out of Sync: How to Resynchronize & Fix Errors

By David Sterling, Senior Financial Systems & Cybersecurity Analyst (CISA) Published: September 2026 | Technical Verification: HMAC-Based One-Time Password (HOTP) Cryptography

If you are an international client, a high-net-worth customer, or a commercial account holder who uses Bank of America's credit-card-sized physical SafePass® token, you rely on its tiny LCD screen and internal microchip to generate 6-digit one-time security codes. But when you press the button, carefully type the displayed numbers into online banking, and click Submit, the portal displays: "The code you entered is invalid. Please check your SafePass card and try again."

You generate a second code, type it in, and it fails again. After three attempts, the system locks you out.

This frustrating breakdown does not mean your card is fake or your account is compromised. In cryptographic security, this phenomenon is known as counter drift or clock desynchronization. Here is why your physical SafePass card became out of sync and how to recalibrate it using Bank of America's self-service cryptographic portal.


Basic Troubleshooting First Aid: SafePass Card Health Check

Symptom / Physical State Underlying Technical Cause Solution Resolution Time
Codes rejected repeatedly Counter drift (button pressed without submitting code) Perform 2-code token resync via self-service portal 3 minutes
Faint / flickering LCD digits Internal lithium coin-cell battery depletion (< 2.7V) Order replacement card via 1-866-283-4093 3–5 business days
Screen shows "bAtt" or blank Battery dead; microchip non-volatile memory cleared Card permanently retired; switch to SMS/mobile 2FA Immediate via phone
Physical bubble on card surface Delamination of internal printed circuit board (PCB) Defective hardware; replace immediately Requires new card
Recently traveled across time zones Not a factor (HOTP tokens use event counters, not time) Follow standard counter re-sync steps below 3 minutes

How Physical SafePass Cards Work: The HOTP Event Counter

Unlike smartphone authenticator apps that utilize Time-Based One-Time Passwords (TOTP, RFC 6238) driven by atomic clocks, Bank of America's ultra-thin physical SafePass cards utilize an HMAC-Based One-Time Password algorithm (HOTP, RFC 4226).

[Physical Card Pressed] ──> [Internal Counter: C = C + 1] ──> [HMAC-SHA1 Hash] ──> Displays 6 Digits
                                                                                          │
                                                                                   (Must Match Server)
                                                                                          ▼
[BofA Security Server] ──> [Server Counter: S = S + 1] ────> [Validates Match] ──> Access Granted

Why Counter Drift Occurs

Every time you press the button on your card, the internal microchip advances its internal counter by 1 ($C = C + 1$) and generates a hash based on a secret cryptographic seed embedded during manufacturing.

Bank of America's authentication server maintains an identical counter ($S$). Under normal circumstances, the server allows a small "look-ahead window" (typically 5 to 10 events) in case you pressed the button by mistake in your wallet without entering the code.

However, if the card button was pressed repeatedly—such as by being pressed inside a tight wallet, played with by a child, or activated multiple times without logging in—the card's internal counter advances far ahead of the server's expected counter ($C >> S$). When this happens, the server can no longer recognize the generated numbers, rejecting every code.


Step-by-Step Guide to Resynchronize Your SafePass Token

Bank of America maintains a dedicated, self-service cryptographic resynchronization portal that allows you to reset the server's look-ahead window by entering two consecutive codes.

Step 1: Access the Official SafePass Management Portal

  1. Open your web browser and navigate directly to: https://safepass.bankofamerica.com/sasuser/Home.do
  2. Sign in with your standard Online ID and Passcode. (Note: If you cannot access this portal due to a hard lockout, call the dedicated SafePass desk at 1-866-283-4093).

Step 2: Navigate to Token Operations

  1. From the left navigation menu, click Token Operations (or Manage SafePass).
  2. Select Synchronize Token from the list of available actions.

Step 3: Generate Two Consecutive Cryptographic Codes

  1. Take your physical SafePass card.
  2. Press the power button once to generate your first 6-digit code. Enter it into the field labeled: First Passcode.
  3. Wait 5 seconds until the display clears, or press the button a second time to generate a brand-new 6-digit code.
  4. Enter the second code into the field labeled: Second Passcode.
  5. Click Submit.

What the Server Does During Resync:

By analyzing two consecutive codes, Bank of America's security server mathematically calculates the exact delta between your card's internal counter and the server's ledger. The server instantly recalibrates its counter forward to match your card, restoring 100% functionality.


What to Do If the Card Display Is Faded or Dead

Physical SafePass cards are powered by an ultra-thin lithium coin cell engineered to last between 3 and 5 years. Because the electronics are hermetically sealed inside the laminated plastic card, the battery cannot be replaced or recharged.

Warning Signs of Battery Failure:

  • The digits appear dim, requiring you to tilt the card under bright light to read them.
  • The display segments flicker or show incomplete numbers (e.g., an 8 looking like a 0).
  • The card fails to power on when pressing the activation circle.

Ordering a Free Replacement Card:

  1. Call the SafePass Technical Support Desk at 1-866-283-4093 (toll-free in the US) or collect at +1-315-724-4022 (international).
  2. Inform the specialist that your physical SafePass card display has failed or the battery has depleted.
  3. The representative will deactivate the defective token on your profile and dispatch a brand-new card via secure mail (typically arriving in 3 to 5 business days for domestic addresses).
  4. In the interim, ask the agent to enable Mobile SMS SafePass or In-App Mobile App Push Verification on your verified smartphone so you do not lose digital banking access while waiting for the physical replacement.