You went to log in to Reddit and your password no longer works, or you opened the app to find posts, comments, and votes you never made sitting on your profile. Maybe the verification email landed in your inbox confirming an address change you did not request, or your account activity page shows logins from IP addresses in places you have never been.
These are the classic fingerprints of a compromised account, and the good news is that Reddit has an official path to take it back. The bad news is that recovery depends heavily on whether the original email is still attached, so the first thing to do is read the signs carefully before you act.
Make the new password count. A free password generator produces a long random string or a memorable passphrase locally in your browser, which beats any reused or predictable choice.
Reading the warning signs before you touch anything
Reddit lists a specific set of indicators that point to a hijacked account, and confirming which ones apply to you shapes everything that follows. Check for these symptoms now so you know exactly what you are dealing with.
Your password and/or email address changed without your request.
Unauthorized apps appear connected on your profile.
Your account activity page shows unusual IP history from locations you do not recognize.
There are votes, posts, or comments you do not remember making.
If even one of these is true, treat the account as compromised and move quickly. Before you start, do this from a device and network you have used to log in to Reddit before, since familiar devices and IP addresses help confirm you are the legitimate owner.
Do not create a brand new account to report or appeal the affected one, because creating accounts to deal with an existing issue can put both at risk.
The fastest way back in is a password reset
If the original email on the account is still under your control, recovery is straightforward. A password reset is the quickest official route, and it works in most cases where the attacker has not yet changed the email.
- 1.On the login screen, select the "Forgot password?" link below the login fields.
- 2.Enter your Reddit username or email address, then select Reset Password.
- 3.Open the email from Reddit and tap the reset link inside it.
- 4.Enter and confirm a new password, then select Continue.
The reset email can take up to an hour to arrive, and it sometimes lands in your spam or trash folder, so check there before assuming it failed.
To make sure future messages reach you, add [email protected] and the broader @reddit.com domain to your safe-senders list.
Choose a strong, unique password you have never used anywhere else, since the whole point is to lock the intruder out for good.
When the attacker already changed your email
If your account email was swapped to one you do not control, Reddit does not just leave you stranded. When an email change happens that you did not authorize, Reddit sends a message explaining how to change it back.
To reverse it, you will need to input the original email that was on the account before the hack, and then reset your password using the steps above.
This is precisely why keeping a current, verified email on the account matters so much.
If there is no email address on the account at all, Reddit states the hard limit plainly: you are locked out until you can remember your password, and there is no way for Reddit to send you a reset email or help you gain access.
In that specific situation, Reddit's only suggestion is to create a new account.
If a reset does not work, file a Security request
When you cannot recover the account by resetting the password, the official next step is to submit a request through the Reddit Help "Submit a request" form at support.reddithelp.com/hc/en-us/requests/new.
Open the request form and select the category "Security problems."
Choose "I think my account has been hacked."
Include the username of the affected account.
Explain clearly why you are concerned and what changed.
Be honest with yourself about what happens next. Reddit's own wording is cautious here: depending on the situation, it may be able to give you back access, and it states that you will only receive a response if Reddit is able to assist with gaining access to the account.
There is no published turnaround time for these requests, so do not expect a guaranteed reply or a fixed number of days.
Recovery is possible, but it is not promised.
Do not pay any third-party "account recovery," "unban," or "reinstatement" service that claims it can speed this up, because these are commonly scams and Reddit's free Security request is the legitimate channel.
Getting past two-factor authentication when it blocks you
During a hack, attackers sometimes enable or change two-factor authentication (2FA) to keep you out even after you know the password. If 2FA is now standing between you and your account, Reddit gives several ways through.
Enter one of your one-time backup codes as the authentication code at login.
If you are still logged in on another device, such as your computer, go to settings and generate new backup codes.
Connect your Google account or Apple ID in settings, then log in through a different browser or app using that.
Make sure your authenticator app is up to date.
One practical note: 2FA can currently only be enabled or managed by logging in to Reddit on a desktop web browser.
If the attacker turned on 2FA and you have no backup codes and no other logged-in device, the situation falls back to the same hacked-account path, which means resetting your password and, if you are still locked out, filing the "Security problems" then "I think my account has been hacked" request.
What to do if the account was locked as a precaution
Sometimes Reddit locks an account on its own as a security measure rather than the attacker locking you out.
If your account was locked as a precaution and you have an email connected to it, you can unlock it simply by resetting your password.
If there is no email on the account but you can still access it, add an email in your account settings first, and then reset your password.
Why changing your password is not enough on its own
Here is a detail many people miss. Changing your password does not automatically evict an attacker who holds OAuth access tokens for connected or authorized apps.
Those access tokens stay valid until you revoke them separately, which means a hijacker could keep a foothold even after you think you are secure.
Reddit's privacy and security controls address this. The official guidance is that you can manage your authorized applications to change what apps you have allowed to access your account and information, and this control is documented inside the "How can I control how Reddit uses my information?" article.
Review the connected apps and revoke anything you do not recognize or no longer use, since this is the step that actually severs the intruder's lingering access.
Locking the door so this does not happen again
Once you are back in and the attacker is out, spend a few minutes hardening the account so a repeat is far less likely. Reddit recommends a strong, unique password, a password manager to store it, a current verified email on the account, and turning on two-factor authentication.
Set a strong, unique password that you do not reuse on any other site, ideally stored in a password manager.
Confirm a current, verified email is on the account so future resets actually reach you.
Enable 2FA on a desktop web browser via Settings > Account authorization > Two-factor authentication.
Save the backup codes generated during setup.
To generate your safety net of codes, go to Settings > Account authorization > "Access your backup codes," enter your password, and select Continue.
Reddit creates ten backup codes, each usable one time, and recommends you write them down or store them in a password manager so a lost or replaced authenticator device never locks you out again.
Throughout all of this, never share a verification code, password, or 2FA code with anyone, and always confirm you are on the genuine support.reddithelp.com domain before entering credentials.
Frequently Asked Questions
How long does Reddit take to respond to a hacked account request?
Reddit does not publish a guaranteed turnaround time for hacked-account Security requests. It states only that you will receive a response if it is able to assist with gaining access to the account, so there is no fixed response window you can count on.
My password reset email never arrived. What should I check?
The reset email can take up to an hour to arrive and sometimes lands in your spam or trash folder, so check there first. Adding [email protected] and the @reddit.com domain to your safe-senders list helps ensure it reaches your inbox.
Can Reddit recover my account if there is no email attached to it?
No. Reddit states that with no email address on the account, you are locked out until you can remember your password, and there is no way for it to send a reset email or otherwise help you regain access. In that case its only suggestion is to create a new account.
I changed my password, so why might the attacker still have access?
A password change alone does not invalidate OAuth access tokens already granted to connected or authorized apps. You must review and revoke those authorized applications separately through Reddit's privacy and security controls to fully cut off the intruder.
I cannot pass the 2FA step. What are my options?
You can enter one of your one-time backup codes, generate new backup codes from settings if you are still logged in on another device, or connect your Google account or Apple ID in settings and log in through a different browser or app. Also make sure your authenticator app is up to date.
Should I pay a service that promises to recover or unban my account faster?
No. Paid third-party account recovery, unban, or reinstatement services are commonly scams. Use Reddit's free official channels, the password reset and the "Security problems" then "I think my account has been hacked" request, and never share a code or password with anyone.