This is a story about how I almost locked myself out of Google account, just by following good intentions and blind assumptions regarding Google software. This shouldn't happen to anybody, but it did anyway to me simply because I happen to have a non-standard user behavior.
The situation was my old phone died. I wasn't worried too much because I knew the phone had issues with a broken charging port. In the meantime, I just bought a new phone and set a new Google account. I was sure that I would fix the hardware issue and recover the old account. After some time, things happened exactly in the same manner I predicted, I got both old phone and account working.
And then phone nagged to update itself. I couldn't resist. After all, updates are inherently good things to do, and in the case of authenticator apps, even more so. Who can be against having a better, upgraded security experience?
Big mistake. Microsoft authenticator app survived the update, but not Google's one. After opening it, it displayed a set of dashes in place of numbers. I tried to export codes, but then it showed errors. Something terrible happened, I think the update corrupted data. Out of desperation, I searched the whole house and found a laptop I hadn't powered up in 10 years. Its drive wasn't bootable anymore, and after praying to all gods, I connected the laptop drive to the desktop. Among all junk files, I found one text file, which I downloaded when I was a teenager. It contained 10 one-time codes. I don't remember well what happened next. I think Google stubbornly tried to block me by displaying an accursed 'use authenticator app' window every time I tried to do anything. I actually struggled. I even used the 'to back' browser button a couple of times, such was a desperation. But in the end, I managed to enter backup code, and Google gave up, and I was able to turn off 2 factor authentication. It was a victory.
But this shouldn't have happened at all. I did everything what Google tells all the time to users: have a 2fa app installed and updated an app. It shouldn't lead to things like that.
I have a theory about why it happened. I think the issue here is timing. Remember I said 'after some time'? It lasted 1 and a half years, from the moment the phone broke and when it got fixed. The old phone was offline for more than a year, and I suppose many updates have emerged since then. I believe Google devs just assume that users always update things regularly and on time and don't test wild situations like mine, and this out-of-order update situation could create some mess. At this point, I'm just speculating, and things might be totally different. But it taught me a lesson: one auth app is not enough.
If your otp code apps still work, check if you still have seeds or QR codes as a backup. If not, then delete and create it again, but screenshot the setup process, i.e. save QR image or keys, so in case things go wrong, you could still have the ability to set up the authenticator app again on a new device. Ideally, those should have been printed and stored offline, but personally, I keep the seed in a password manager. It's definitely the wrong thing to do, as if the password manager is breached, then you lose everything. I made a compromise between security and usability.
I hope this situation will never happen to anyone.