The same way you recover your account when you lose a password.
What benefit does your 128-bits authentication schema gain when anybody can just clone a phone number?
Or do you demand that the user has an email with that 128-bits authn too, with a key on the same phone that was lost?
What benefit does your 128-bits authentication schema gain when anybody can just clone a phone number?
Or do you demand that the user has an email with that 128-bits authn too, with a key on the same phone that was lost?