If you have successfully changed your Bank of America password only to have the app or website immediately demand that you reset it again, you are caught in a credential synchronization redirect loop.

This frustrating bug makes account holders feel as though their new password failed to save or their account has been breached. Do not panic: your funds and account security are completely intact. This glitch is caused by a race condition between your device's cached cryptographic authentication token and Bank of America's distributed core credential databases.

What Does the Password Reset Loop Mean?

The Bank of America password reset loop occurs when an outdated session cookie or mobile keychain token continually submits stale credentials in the background. When Bank of America's security gateway detects the old token right after you authenticate with a new password, it interprets the mismatch as suspicious activity and triggers an automated forced-reset flag.

Diagnostic Attribute Technical Detail
Institution Bank of America, N.A.
System Event Credential Token Invalidation Loop
Primary Causes iCloud Keychain / Chrome Autofill mismatch, stale biometric refresh token, IP anomaly
Affected Platforms Mobile App (iOS / Android), Mobile Web, Desktop Safari & Chrome
Estimated Resolution 4 to 8 minutes

🔴 Critical Warning: Do not attempt more than 3 consecutive resets in the same browser session. Repeated failed handshakes will trigger an administrative security lockout requiring tier-2 telephone unlock.

5 Step-by-Step Fixes for the Password Reset Loop

Follow these steps in precise order to purge the corrupted session state and restore clean access.

1. Disable Password Autofill Temporarily (Keychain & Chrome)

The number one cause of the loop is browser or mobile password autofill silently overwriting your newly created password with the previous one during the redirect handoff.

  1. On iPhone, go to Settings > Passwords > Password Options and toggle off Autofill Passwords and Passkeys.
  2. On Android / Chrome, go to Settings > Autofill and passwords > Google Password Manager > Settings gear > toggle off Offer to save passwords.
  3. Manually type your Online ID and newly created password character by character.

2. Revoke and Re-Authenticate the Biometric Keychain Token

If the loop occurs specifically on your smartphone app:

  1. Open the Bank of America mobile app.
  2. At the login screen, tap Cancel on the Face ID / Fingerprint prompt.
  3. Tap Forgot ID/Password on the login screen, complete the verification one final time using your debit card or account number, and establish your new password.
  4. When prompted "Enable Face ID / Touch ID for quick sign-in?", select Not Now.
  5. Log in manually once. Once inside your dashboard, navigate to Menu > Security Center > Face ID / Biometrics and re-enable it cleanly.

💡 Related Bank of America Solution: Encountering related issues? Check our verified fix for Bank of America Business & Personal Login Conflict: How to Link Accounts & Stop Redirects.

3. Clear Stale OAuth Cookies (Bypass the Host Header Cache)

If resetting via a desktop computer or mobile browser:

  1. Close all active Bank of America browser tabs.
  2. Clear cookies specifically for the domains bankofamerica.com and secure.bankofamerica.com.
  3. Flush your DNS cache or open a fresh Private / Incognito Window.
  4. Navigate directly to https://www.bankofamerica.com without using a bookmarked URL (old bookmarks frequently contain expired session query parameters like ?request_locale or stale state tokens).

4. Verify Identity Via the SafePass Secondary Channel

If Bank of America's fraud engine flagged your IP address, it will loop the reset until multi-factor verification is confirmed via an alternate channel.

  1. When prompted for SafePass verification, select Text Message rather than the mobile push notification.
  2. If the SMS fails to arrive within 60 seconds, select Call Me to receive the 6-digit code via automated phone call.
  3. Enter the code immediately—SafePass codes expire after exactly 10 minutes, but credential token resets require verification within 180 seconds.

5. Escalate to the Dedicated Digital Banking Escalation Desk

If the loop persists across multiple devices and incognito browsers, your profile has an administrative "must-change-password" database flag stuck in active status.

  • Call the Bank of America Online & Mobile Banking Support Desk at 1-800-933-6262.
  • When the automated IVR voice asks for your issue, clearly say: "Technical Support: Password reset redirect loop."
  • Request that the representative perform a "Remote Session Kill and Profile Cache Flush". This terminates all active OAuth tokens across all servers and clears the forced-reset flag.

Frequently Asked Questions (FAQ)

Did someone hack my Bank of America account? No. An automated password reset loop is almost universally a client-side token caching glitch or an anti-fraud heuristic triggered by changing your password from an unrecognized Wi-Fi network or VPN.

Why does the desktop website work while the mobile app keeps looping? The mobile app stores authentication tokens in a persistent hardware-backed keystore. If the app fails to overwrite the old token upon a password reset, it repeatedly submits expired credentials, triggering the loop.

How long should I wait before trying again? If you have failed twice, wait exactly 20 minutes before making a third attempt. This allows temporary anti-brute-force rate limits on Bank of America's authentication servers to clear.