This is the question that stops people buying, so here is the answer up front.
If you prepared, losing a key is an administrative chore. If you did not, it is a bad day that ends in an account recovery process you will not enjoy.
The difference is entirely whether you bought a second key.
What a lost key does not do
Someone who finds your key cannot read your accounts off it. There is no list of sites on it, no usernames, no passwords. The credentials are cryptographic keys that never leave the device, and they only respond to the exact domain they were created for.
If the key required a PIN or a fingerprint, the finder needs that too. Without it, the key does nothing useful for the accounts that demanded user verification.
And a security key is a second factor. Whoever has it still needs the password or the account it belongs to, and they have no way of knowing which accounts that is.
So a lost key is not an open door. It is a lost second factor, which is a problem about your access rather than about their access.
What it does do
It takes away your way in.
If it was your only registered key, you are now relying on whatever backup method the account offers. Recovery codes if you saved them, a phone number, a service desk call. Those paths are weaker than the key you just lost, which is the awkward part of the whole situation.
The first hour
Sign in with your backup key. That is the whole point of having one.
Then remove the lost key from every account it was registered to. Every service that supports security keys lets you see which keys are registered and delete one. Do this even though the finder almost certainly cannot use it, because tidy is better than probably-fine.
Order a replacement immediately and make it your new backup. Getting back to two keys is the priority, and the window where you are down to one is the window where this happens again with worse consequences.
If it was a work key, tell whoever runs IT. On a managed tenant they may want to revoke the credential centrally and check whether the key had access to anything that deserves a closer look.
If you only had one key
Work through it in this order.
Recovery codes first, if you saved them when you set up the account. This is what they are for and it is the fastest route.
Then any other registered method: an authenticator app, a passkey on your phone, a backup email. Anything that gets you in without the key.
Then the service's account recovery process, which is slow by design and will ask you to prove who you are.
For a work account, the service desk. Expect identity checks, and understand why they are being thorough. This step is exactly the one attackers imitate.
Once you are back in, buy two keys.
Making it a non-event
The prepared version of this whole article is four sentences.
Buy two keys. Register both to every account that matters, at the same sitting. Keep the second one somewhere you can reach but that does not travel with the first. Test it once so you know it works.
Do that and a lost key costs you a replacement and ten minutes of tidying up.
For a business, add a small pool of spare keys held by IT so a replacement is handed over the same day, and give break-glass accounts their own dedicated pair stored separately. Mapping that out for a specific set of privileged roles is part of a Conditional Access review.