[GH-ISSUE #6833] [BWA-253] Authenticator app showing phantom/ghost/non existent TOTP codes #50603

Open
opened 2026-05-01 13:46:59 -05:00 by GiteaMirror · 6 comments
Owner

Originally created by @Abhijay-Tank on GitHub (Apr 24, 2026).
Original GitHub issue: https://github.com/bitwarden/android/issues/6833

Steps To Reproduce

I am not sure what causes these issues. I have updated both Bitwarden Authenticator and Bitwarden Password manager to their latest versions as of date 24/04/2026.
My Setup:

  1. TOTP codes have been setup in Password Manager(free plan)
  2. Using Authenticator app for viewing them. Connect/Sync them.
  3. Observe the List of TOTP codes and the number of entries

Expected Result

User expects TOTP codes only for services user has setup in their password manager. For example if I have not setup any TOTP code for my Reddit account stored in my password manager then a TOTP code for reddit account is not supposed to show up in authenticator app.

Actual Result

As you can see in the screenshot attached below. The reddit account with username ending in Books does not have any TOTP entry in the password manager app however still it shows up in authenticator app.

Screenshots or Videos

Image Image

Additional Context

No response

Build Version

Authenticator app: Version:2026.4.0 (1497)

What server are you connecting to?

US

Self-host Server Version

No response

Environment Details

-Device: Motorola g40 fusion. Android 12

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
Originally created by @Abhijay-Tank on GitHub (Apr 24, 2026). Original GitHub issue: https://github.com/bitwarden/android/issues/6833 ### Steps To Reproduce I am not sure what causes these issues. I have updated both Bitwarden Authenticator and Bitwarden Password manager to their latest versions as of date 24/04/2026. My Setup: 1. TOTP codes have been setup in Password Manager(free plan) 2. Using Authenticator app for viewing them. Connect/Sync them. 3. Observe the List of TOTP codes and the number of entries ### Expected Result User expects TOTP codes only for services user has setup in their password manager. For example if I have not setup any TOTP code for my Reddit account stored in my password manager then a TOTP code for reddit account is not supposed to show up in authenticator app. ### Actual Result As you can see in the screenshot attached below. The reddit account with username ending in Books does not have any TOTP entry in the password manager app however still it shows up in authenticator app. ### Screenshots or Videos <img width="696" height="1550" alt="Image" src="https://github.com/user-attachments/assets/098fb32b-e0d6-4c49-af12-021e21bd4ff7" /> <img width="1128" height="1342" alt="Image" src="https://github.com/user-attachments/assets/dcef06d2-af63-40a0-bb33-129fc1d35492" /> ### Additional Context _No response_ ### Build Version Authenticator app: Version:2026.4.0 (1497) ### What server are you connecting to? US ### Self-host Server Version _No response_ ### Environment Details -Device: Motorola g40 fusion. Android 12 ### Issue Tracking Info - [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
GiteaMirror added the bugapp:authenticator labels 2026-05-01 13:47:00 -05:00
Author
Owner

@bitwarden-bot commented on GitHub (Apr 24, 2026):

Thank you for your report! We've added this to our internal board for review.
ID: BWA-253

<!-- gh-comment-id:4310952618 --> @bitwarden-bot commented on GitHub (Apr 24, 2026): Thank you for your report! We've added this to our internal board for review. ID: [BWA-253](https://bitwarden.atlassian.net/browse/BWA-253) [BWA-253]: https://bitwarden.atlassian.net/browse/BWA-253?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
Author
Owner

@rmcdowell-bitwarden commented on GitHub (Apr 24, 2026):

Hi there,

I am unable to reproduce this issue, it has been escalated for further investigation. If you have more information that can help us, please add it below.

Thanks!

<!-- gh-comment-id:4311041644 --> @rmcdowell-bitwarden commented on GitHub (Apr 24, 2026): Hi there, I am unable to reproduce this issue, it has been escalated for further investigation. If you have more information that can help us, please add it below. Thanks!
Author
Owner

@pamperer562580892423 commented on GitHub (Apr 24, 2026):

@Abhijay-Tank @rmcdowell-bitwarden Also since some of the TOTP verification codes are identical in that screenshot, this looks like a duplicate of https://github.com/bitwarden/android/issues/6526 (maybe the new part here is that it also affects synced codes)

<!-- gh-comment-id:4311548776 --> @pamperer562580892423 commented on GitHub (Apr 24, 2026): @Abhijay-Tank @rmcdowell-bitwarden Also since some of the TOTP verification codes are identical in that screenshot, this looks like a duplicate of https://github.com/bitwarden/android/issues/6526 (maybe the new part here is that it also affects synced codes)
Author
Owner

@Abhijay-Tank commented on GitHub (Apr 24, 2026):

Yes I checked out #6526 and I firmly believe it is related with same issue. In that post , the ghost TOTP were visible in app/onsite itself. In my case since I am a free user, they are showing up on my authenticator app. Please let me know if I should close this a duplicate of that issue? I can comment my experience down there. I am sorry that I am not a github savvy user so I don't know how to proceed.

<!-- gh-comment-id:4312563509 --> @Abhijay-Tank commented on GitHub (Apr 24, 2026): Yes I checked out [#6526](https://github.com/bitwarden/android/issues/6526) and I firmly believe it is related with same issue. In that post , the ghost TOTP were visible in app/onsite itself. In my case since I am a free user, they are showing up on my authenticator app. Please let me know if I should close this a duplicate of that issue? I can comment my experience down there. I am sorry that I am not a github savvy user so I don't know how to proceed.
Author
Owner

@Dannixtar commented on GitHub (Apr 27, 2026):

i just tried an older version of the authenicator app version 2026.3.1 and then all totp codes sync correct if i use the newer version 2026.4.0 then i get ghost entries.

<!-- gh-comment-id:4328664787 --> @Dannixtar commented on GitHub (Apr 27, 2026): i just tried an older version of the authenicator app version 2026.3.1 and then all totp codes sync correct if i use the newer version 2026.4.0 then i get ghost entries.
Author
Owner

@pangyulei commented on GitHub (Apr 27, 2026):

Me too, still exist, first time encounter this bug. Many logins in Bitwarden without TOTP, has showed on Bitwarden Authenticator

<!-- gh-comment-id:4329338466 --> @pangyulei commented on GitHub (Apr 27, 2026): Me too, still exist, first time encounter this bug. Many logins in Bitwarden without TOTP, has showed on Bitwarden Authenticator
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#50603