Key Takeaways:
• The hardware path: Bank of America dropped the SafePass Card and now recommends a customer-bought FIDO2 USB security key, roughly $18 to $50, up to two per account.
• The SMS path: SafePass codes come from U.S. short code 73981, registered in 2011, so the number on file has to accept U.S. short-code texts.
• The money wall: Secured Transfer asks for "a U.S. mobile number and debit card" once a transfer passes your daily limit, and the screen stores up to two numbers.
• Quick next step: buy a key before you fly and register a U.S. mobile line at slynumber.com/app/register from $4.99/month, so one failure does not lock you out.
1. Can you receive Bank of America codes abroad?
Yes, and Bank of America documents two routes for it. One is a U.S. mobile number that receives SafePass texts. The other is a physical USB security key that needs no phone at all. On a retail account, the bank's security screen shows three mechanisms side by side: Passkey, Secured Transfer, and USB Security Key.
The reason this bank reads differently from its peers is the hardware. Bank of America phased out the wallet-sized SafePass Card that used to generate codes offline. In its place, the bank tells customers to buy a FIDO2-certified USB key from a retailer and register it. Its own page recommends this for people who cannot get U.S. texts, which is close to an official acknowledgment that living abroad breaks the SMS route. The key costs roughly $18 to $50 and you can register up to two per account.
It is not a full replacement for a phone number, though. Passkey covers sign-in and the key covers high-risk transfers, while Secured Transfer still asks for a U.S. mobile number when you move money above your daily limit. That is why the strongest setup abroad is both: a registered key and a real U.S. mobile line, each one covering the other's failure.
Bank of America's USB Security Key page markets the key "if you don't have access to a U.S. mobile phone number or can't receive texts to your phone". The key is FIDO2-certified and bought at retail for about $18 to $50, with up to two per account. It is removed automatically after six months of inactivity or three years without renewal.
What this means for you: the bank has written down that "no U.S. texts" is a real customer situation, and it published a workaround for it. Use that workaround, and keep a working U.S. number for everything the workaround does not cover.
2. What replaced the SafePass Card
SafePass began as a texted-code program with a paid card as the offline option. The Electronic Frontier Foundation documented that setup in December 2016: you enrolled a mobile number for texted codes, or you paid for a SafePass Card. The card is gone. What remains is the SMS side of SafePass plus the retail USB key.
The SMS side has a fingerprint worth knowing. SafePass codes come from short code 73981, registered on September 16, 2011 under the campaign name "SafePass One Time Password Program". Short codes are U.S. carrier infrastructure. Short-code messaging is also technically different from ordinary person-to-person SMS: the message originates from an application-to-person (A2P) messaging platform and has to be supported across the originating application, the carrier network, the subscriber account and, when roaming, the visited network. A phone that receives ordinary texts abroad is therefore not guaranteed to receive every U.S. short-code authentication message, and no error message explains the silence.
That is where the hardware key earns its place for an expat. A FIDO2 key generates its proof locally over USB. It works on hotel Wi-Fi, on a plane, and in places where local carriers do not deliver inbound U.S. short codes. The trade is physical. Lose the key overseas and you are buying a replacement from a foreign retailer, then registering it from an account you may not be able to reach.
A short-code registry entry for 73981 shows the campaign live since 2011 and a sample message: "Bank of America: DO NOT share this code. We NEVER call or text for it. Code 335634. Reply HELP if you didn't request it." The EFF's 2016 SafePass walkthrough records the original mobile-number-or-card enrollment choice.
What this means for you: keep both, a registered key and a U.S. mobile line, because each one covers the other's failure.
3. Secured Transfer, the wall that hits when you move money
Secured Transfer is a transaction-level check, not a login check. It triggers when you send more than your daily limit. Expats can bank happily for months, then hit it during a rent payment or a property transfer. Bank of America's own wording is direct: if you're transferring more than your daily limit, the bank requires Secured Transfer, and you'll need a U.S. mobile number and debit card to confirm your identity. The screen stores up to two numbers.
Two things follow from that. First, a passkey does not get you past it, because a passkey authenticates the sign-in rather than the transfer. Second, the two-number slot is why one expat forum described registering a trusted contact's U.S. number and coordinating over Skype when a code was needed. That is a customer workaround, not a bank feature, and Bank of America's copy asks only for a U.S. mobile number. The cleaner reading of the same requirement is to hold a U.S. mobile line of your own that reaches you wherever you live.
It is worth being precise about why the line type matters here. A phone number is more than ten digits: telecommunications and identity systems associate it with attributes such as country, carrier, line type, portability status, and whether the service is classified as mobile, landline or VoIP. Those attributes feed fraud-prevention and authentication decisions, and a number that fails the eligibility test can be refused before a message is ever sent.
Bank of America's Additional Security Features screen lists Passkey, Secured Transfer and USB Security Key side by side, and states the Secured Transfer requirement as "a U.S. mobile number and debit card", with up to two numbers stored.
What this means for you: plan for the transfer check separately from the login check, because BofA treats them as separate mechanisms.
4. Three BofA failure patterns expats report
Bank of America has never published a position on VoIP numbers or international SMS, so the failure map comes from customers. Three patterns repeat across the Philippines Expats forum, Nomad List, and a long-running Thailand expat thread about the SafePass Card being retired. Each one has a different cause, and we attribute each source below.
-
Google Voice works, then doesn't, then does
The reports contradict each other, and the same person's experience changes over time. One expat spent years unable to receive BofA codes on a Google Voice number, then found it working one day with no announcement. Another traveler named Bank of America as the worst offender for refusing this kind of number. A rule you cannot predict is worse than a rule that says no. The technical reason is that a VoIP number may receive an ordinary SMS and still fail a financial institution's authentication system, either before delivery because the number does not satisfy eligibility rules, or later in the messaging path because short-code and A2P traffic is not supported on that route.
On the Philippines Expats Forum, user Gentleman.Jack.Darby wrote in a thread titled "Google Voice Now Receiving Bank of America SMS": "I commented that I'd never been able to receive Bank of America SMS verification codes using my Google Voice number with forwarding to my e-mail account... today, for whatever reason, it worked. I have no explanation as to WHY, but something changed somewhere and it's working." On Nomad List, user @mwp wrote: "my google voice number actually works for most of these. The picky ones that don't all have email options for 2 factor codes (Bank of America seems to be the main offender that I recall)."
Why a real U.S. mobile line helps: a SLYNUMBER is registered as a mobile line rather than VoIP. That is not the category these reports call unpredictable.
-
The USB key has housekeeping rules that bite from a distance
The key is the sanctioned answer, and it comes with two clocks. Bank of America removes a registered key after six months of inactivity, and after three years without renewal. An expat who uses the key twice a year for rent transfers can find it quietly deregistered. Re-registering usually means passing the security check the key was there to replace in the first place, which is the exact loop you were trying to avoid.
The bank's USB Security Key page sets the terms: up to two keys per account, retail purchase at roughly $18 to $50, and auto-removal after six months idle or three years without renewal. A long-running ASEANNOW thread records how expats handled the switch when the SafePass Card was retired.
Why a real U.S. mobile line helps: a working U.S. number lets you re-register a key, or a replacement, without calling the bank from overseas.
-
The Bank of America authenticator app you will find is not for you
Search for a BofA authenticator and you land on Flagscape Authenticator, which does support push approval and offline codes. It is built for the bank's business and corporate platforms, CashPro and Flagscape, and we found no confirmation that it covers individual retail accounts. On the retail side the closest thing is Passkey, and a passkey signs you in rather than clearing a Secured Transfer. Installing the wrong app is a day lost, not a solution.
Bank of America's Flagscape Authenticator help page documents push and offline one-time passcode (OTP) support for its corporate platforms. No Bank of America page confirms retail availability, so treat the app as out of scope for a personal account.
Why a real U.S. mobile line helps: the retail account still runs on SafePass texts to a U.S. mobile number. Solve that piece properly.
5. How to prepare a BofA account for living abroad, in 5 steps
- Buy and register the USB key first. Pick a FIDO2-certified key at retail, roughly $18 to $50, and register it while you still have U.S. access. Register a second one as a spare, since the account allows two.
- Add a real U.S. mobile number. Sign up at slynumber.com/app/register, choose your area code, and get a mobile line from the North American Numbering Plan. SafePass texts come from 73981.
- Set up Passkey for sign-in. Passkey sits on BofA's security screen next to the key and Secured Transfer, and it covers day-to-day logins from your own devices.
- Check your Secured Transfer numbers. The screen holds up to two. Make sure at least one is a number you can actually receive texts on from where you live.
- Use the key at least twice a year. Six months of inactivity removes it. Add a SLYNUMBER eSIM data plan if you want cellular data abroad without hunting for local SIM cards.
6. BofA verification options compared
Bank of America splits security across sign-in and money movement, so the axes below follow that split: whether the option works with no U.S. SMS, whether it clears a Secured Transfer, what upkeep it demands, and what it costs.
| Option | Works with no U.S. SMS access | Clears a Secured Transfer | Upkeep or expiry | Cost |
| SLYNUMBER real U.S. mobile line | It is U.S. SMS, delivered to the app over Wi-Fi or local data | Meets the "U.S. mobile number" requirement BofA states | None beyond the subscription | $4.99/mo, billed $14.99 per quarter |
| BofA USB security key (FIDO2) | Yes, no phone involved | Yes, BofA's documented high-risk-transfer path | Removed after 6 months idle or 3 years without renewal | $18 to $50 at retail, up to 2 keys |
| BofA Passkey | Yes, for sign-in | No, it authenticates the login, not the transfer | Tied to the device you registered | Free |
| Google Voice or other VoIP | Inconsistent, per expat reports | Not reliable enough to plan on | None | Free |
| U.S. SIM on international roaming | Only where your carrier delivers roaming SMS | Yes while roaming works | Day charges add up on long stays | AT&T International Day Pass $12/day, 210+ destinations |
Quick recap: the strongest setup at Bank of America is a registered USB key plus a real U.S. mobile line. The key covers high-risk transfers with no phone at all, and the number covers SafePass texts and re-registration if the key expires or goes missing. A SLYNUMBER line costs $14.99 every three months. Passkey handles sign-in and stops there. Google Voice is the option expats describe as working unpredictably. Roaming works while your carrier plays along, at $12 a day on AT&T's International Day Pass.
7. Features and pricing
Core features
SLYNUMBER provides real U.S. mobile numbers, registered as mobile lines rather than VoIP, which is why they pass checks that reject VoIP-classified numbers. Each number supports:
• SMS and MMS, including U.S. short-code messages such as 73981
• Inbound and outbound voice calls
• Custom voicemail per number
• Call routing, forwarding, and per-contact blocking
• Your choice of U.S. area code
• eSIM data plans on a pay-as-you-go basis for cellular data in 150+ countries
Why the classification matters
Messages and calls reach the app over connections encrypted with Transport Layer Security (TLS), the standard behind online banking. Voice uses Secure Real-Time Transport Protocol (SRTP). Delivery travels over the internet. What a bank's carrier lookup reads is the number's classification, and a SLYNUMBER is classified as a U.S. mobile line.
Pricing
• Quarterly: $4.99/month, billed $14.99 every three months
• Annual: $49.99/year, the lowest per-month rate
• Add-on credits: $10 for 1,000 credits
The 3-Month Base Plan includes unlimited inbound calls and texts plus 100 outbound credits per month, which fits someone whose main need is receiving codes.
Availability and honesty note
SLYNUMBER is on the App Store and Google Play, with 200,000+ users across 150+ countries. SLYNUMBER has not been tested against Bank of America's systems, and nothing here claims otherwise. If you want a path the bank itself endorses for customers without U.S. texts, that is the USB security key. Both the FBI and CISA recommend moving away from SMS codes where a stronger option exists.
A community-banking trade analysis, "Rethinking SMS for Two-Factor Authentication" (August 21, 2025), covered a joint Bloomberg and Lighthouse Reports investigation. It notes that third-party SMS vendors used by banks can be compromised, and that both the FBI and CISA have warned against SMS-based two-factor authentication, recommending alternatives such as passkeys.
8. Frequently asked questions
You need a number that is registered as a U.S. mobile line, because SafePass codes go out as U.S. short-code SMS from 73981. A SLYNUMBER is that kind of line, issued from the North American Numbering Plan and classified as mobile rather than VoIP. It rings in an app over Wi-Fi or local data. Plans start at $4.99 per month, billed $14.99 every three months. Bank of America's own alternative, if you would rather carry no phone dependency, is the USB security key.
It is the one path Bank of America itself recommends for customers without U.S. text access. You buy a FIDO2-certified key at retail for roughly $18 to $50, and you can register up to two per account. Two housekeeping rules catch people out. A key is removed automatically after six months of inactivity, and after three years without renewal. So use it occasionally even when you are not moving money.
That prompt appears when the bank cannot confirm the device or the number on file. Bank of America has no help page confirming voice-call codes as an official channel, so treat that as unconfirmed. What is documented is Passkey for sign-in, SafePass texts to a U.S. mobile number, and the USB security key. Setting up a passkey and keeping a working U.S. mobile line on file removes most of these prompts.
Reports go both ways, which is the real problem. One Philippines-based expat had never been able to receive BofA codes on his Google Voice number, then one day it worked with no explanation. A Nomad List poster named Bank of America as the main offender among banks that refuse VoIP numbers. Bank of America has published nothing either way. A number registered as a U.S. mobile line takes that uncertainty out of the picture.
73981, registered on September 16, 2011 under the campaign name "SafePass One Time Password Program". A typical message reads: "Bank of America: DO NOT share this code. We NEVER call or text for it. Code 335634. Reply HELP if you didn't request it." It is a U.S. short code, so the receiving number has to support U.S. short-code SMS.
Expats worry about it out loud, and one forum poster raised both the longevity of his device and the bank questioning his whereabouts from an out-of-country IP address. Bank of America has published nothing about foreign IP addresses, so there is no policy to quote here. Keeping current contact details and a reachable U.S. mobile number is the practical hedge, since that is what the bank asks for.
Related reading: a U.S. phone number for expats, why banks block VoIP numbers, and real mobile numbers versus VoIP numbers.