Zkitszo - The Real
September 30, 2026

Re-Flashed Your Pi and SSH Says No? One Command

A frustrating error comes up on a re-flashed Pi... a security feature- but an annoying one. Not thoroughly documented, or just not in a way we'd be searching for when troubleshooting. It just isn't documented in a manner in which you could easily track down. The project relies on it, maybe a headless project where you are squeezing out your Pi's performance to only what's necessary- there's nothing to display, so a monitor is redundant... nothing requiring user interaction outside of the initial setup, anything after that is data collection, so a direct and constant keyboard and mouse isn't necessary- you can do everything from a remote computer and SSH in- you once had SSH access to that Pi, it worked yesterday, and now it flat out refuses. Mostly saving this here for me to remember, and for you if you landed here from a search bar.

The story usually goes like this- a new project, or another use for the Pi, required a re-flash. Or maybe you were troubleshooting some other issue and wanted to start fresh... SD card wiped, new Raspberry Pi OS image, boots fine. Then you go to SSH back in and get hit with a wall of @ signs.

This, an error, I personally come across more than I'd like to admit- and spent even more time trying to solve- last time re-flashing an old Pi that had a generic OS on it at the time to something more capable and on topic, specifically to run https://detecxceo.gumroad.com/l/fsnimq

The Wall of @ Signs

On a Mac or Linux machine (and Windows 10/11 with the built-in OpenSSH client) it looks something like this:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
...
Offending ED25519 key in /Users/you/.ssh/known_hosts:3
Host key verification failed.

"Someone is doing something nasty"... thanks, SSH. That reads like a hacker is sitting in your router.

Don't fret. This is a safeguard. It is normal after re-flashing Raspberry Pi OS.

Why Did My Pi Change Its Face?

Every SSH server has a "host key"- this being the equivalent of an ID card for your Pi. The first time you connect, your computer will ask "are you sure?", of course you are, so you type yes. That ID gets written to a file called known_hosts (in the hidden .ssh folder of your home directory). Every connection that you make after that, your computer will check the ID against what it previously saved.

When you flash a brand new fresh image, the Pi gets rid of the old keys and makes brand new ones on its first boot following the new flash. The Raspberry Pi OS comes with a small one-off service called regenerate_ssh_host_keys. This deletes /etc/ssh/ssh_host_*_key* and runs ssh-keygen -A to make new SSH keys, then disables itself. It keeps the same IP address and the same hostname, except... a completely different ID card being that regenerated SSH key.

Your computer runs a check- like a security guard at a high security building... they see the same ID come up, yet looking at you, they see someone different- the same address with a different face, a different SSH key... doesn't match what it previously recognized- so, rightfully, it does exactly what it should do- refuses. From where it sits, that looks the same as somebody pretending to be your Pi. The OpenSSH manual says as much:

If a host's identification ever changes, ssh warns about this and disables password authentication to prevent server spoofing or man-in-the-middle attacks

The Fix- One Command

Tell your computer to forget the old ID:

ssh-keygen -R PI_IP

Example:

ssh-keygen -R 192.xxx.x.xx

Swap in whatever your Pi's actual IP address is. The -R removes every key belonging to that host from your known_hosts file. It works even when the file is "hashed" (scrambled so you can't read the hostnames in it, which some systems do by default).

Then reconnect like normal.

Step by Step, Mac or Linux

Here's the exact process to finish connecting.

1. Open Terminal

On your Mac or Linux desktop. (Windows 10/11 folks- PowerShell does the same job, same commands.)

2. Clear the old key

Replace raspberrypi.local with your Pi's actual IP address or hostname:

ssh-keygen -R raspberrypi.local

A sneaky miss which stumps even the experienced... known_hosts remembers the hostname and the IP as separate entries. If you've ever connected both ways- by raspberrypi.local one day and by 192.xxx.x.xx another- well, you have cleared one... the other still sits as the old, now unrecognizable- non-matching- so... you gotta clear both! Clear both, or you'll fix one and still get the wall of @ signs on the other:

ssh-keygen -R raspberrypi.local
ssh-keygen -R 192.xxx.x.xx

3. Connect with your standard SSH command

ssh pi@raspberrypi.local

Hold on though- is your user actually "pi"? Since the April 2022 Bullseye update, new Raspberry Pi OS images don't come with a default "pi" user anymore. You pick the username in Raspberry Pi Imager's settings (the cogwheel) before writing the card, or in the first-boot wizard. If you named yourself something else, it's ssh yourname@raspberrypi.local. Same goes for the hostname- if you changed it in Imager, raspberrypi.local won't answer.

4. Accept the new fingerprint

The terminal asks if you want to continue connecting. Type yes and press Enter. The new ID gets written into known_hosts and you're back in.

That's it. Reboot, re-flash, repeat... it'll happen again next time you wipe that card... now you know.

Oh- the flip side. If you did not re-flash anything, didn't swap the SD card, didn't reinstall SSH, and this warning shows up anyway... don't just run the command and move on. Something changed on that address and it wasn't you. A different device grabbed that IP from your router? Maybe harmless. Maybe not. You shouldn't ignore this- there may be some nefarious activities being attempted- it's something to pin down and understand why it happened. More than likely nothing other than that re-flash... can't be too cautious- better safe than have your Pi turned into an attack vector in some botnet...

Ever had this one eat an evening on you? Or hit it on something other than a Pi- a router, a VPS, a NAS? Leave a comment.

More Pi stuff while you're here:
SD Card Formatter, That's All - for when that card needs wiping before the flash
1 Pi, 2 WiFi - two WiFi adapters on one Pi

Glossary

  • SSH (Secure Shell) — an encrypted way to log in to and control another computer from your terminal.
  • Re-flash — writing a fresh operating system image onto the Pi's SD card (or SSD), wiping what was there.
  • Host key — the SSH server's own key pair; its public half is the "ID card" your computer checks on every connection.
  • Fingerprint — a short hash of a host key, shown so a person can compare keys at a glance (e.g. SHA256:...).
  • known_hosts — the file in ~/.ssh/ where your SSH client stores the host keys it has already accepted.
  • Hashed known_hosts — a known_hosts file where hostnames are stored scrambled, so you can't read them by eye; ssh-keygen -R still finds them.
  • Man-in-the-middle (MITM) attack — someone sitting between you and the device, pretending to be the device to read or change your traffic.
  • ssh-keygen — the OpenSSH tool for making and managing keys; -R removes a host's entries from known_hosts.
  • Hostname / .local — the Pi's network name; raspberrypi.local is found on your network via mDNS (Bonjour/Avahi) instead of an IP.
  • Raspberry Pi Imager — the official tool for writing Pi OS to a card; its settings let you set username, password, hostname and enable SSH before the first boot.

Sources

Comments