Topic

What is 2FA in crypto?

Last reviewed:

The short lesson

2FA, or two-factor authentication, means you need two things to log in: something you know (your password) and something you have (a code or a device). If a thief steals your password, they still need the second factor.

Crypto exchanges ask for 2FA at login and often again before a withdrawal. Turn it on. Then choose the strongest kind you can:

  • Security key. A small physical key you plug in or tap. Very strong against phishing.
  • Authenticator app. An app that shows a new six-digit code every 30 seconds. Stronger than text codes.
  • Text-message codes. Better than nothing, but a SIM swap can steal them.

Two rules:

  • Never share a 2FA code. Anyone who asks for one, even “support,” is trying to get into your account.
  • Back up your 2FA. Save the recovery codes offline, so a lost phone does not lock you out.

2FA protects accounts. It does not protect a self-custody wallet. That is the job of your seed phrase.

Hands turning the pages of a book

Related terms

Common questions

Which 2FA is best?

A security key is strongest, then an authenticator app, then text messages.

Should I ever share a 2FA code?

No. Real support never needs it.

What if I lose the phone with my authenticator?

Use the recovery codes you saved when you set it up, or the service’s recovery process.

Does 2FA protect my seed phrase?

No. 2FA protects accounts. Anyone with your seed phrase can still empty a self-custody wallet.

Start here

Start here. Learn first. The sample lessons, topic pages, glossary and tools are open, with no card and no sign-up.

Start with Lesson 1