Topic
What is 2FA in crypto?
Last reviewed:
- Quick fact 1
Two-factor authentication adds a second check beyond your password.
Source: FTC: Use two-factor authentication to protect your accounts
- Quick fact 2
Text-message codes can be stolen through a SIM swap; authenticator apps and security keys are safer.
Source: FTC: Use two-factor authentication to protect your accounts
- Quick fact 3
CISA urges people to turn on multifactor authentication for their accounts.
Source: CISA: More than a password (multifactor authentication)
The short lesson
2FA, or two-factor authentication, means you need two things to log in: something you know (your password) and something you have (a code or a device). If a thief steals your password, they still need the second factor.
Crypto exchanges ask for 2FA at login and often again before a withdrawal. Turn it on. Then choose the strongest kind you can:
- Security key. A small physical key you plug in or tap. Very strong against phishing.
- Authenticator app. An app that shows a new six-digit code every 30 seconds. Stronger than text codes.
- Text-message codes. Better than nothing, but a SIM swap can steal them.
Two rules:
- Never share a 2FA code. Anyone who asks for one, even “support,” is trying to get into your account.
- Back up your 2FA. Save the recovery codes offline, so a lost phone does not lock you out.
2FA protects accounts. It does not protect a self-custody wallet. That is the job of your seed phrase.

Related terms
Go deeper in Lesson 7: What an exchange is
Common questions
Which 2FA is best?
A security key is strongest, then an authenticator app, then text messages.
Should I ever share a 2FA code?
No. Real support never needs it.
What if I lose the phone with my authenticator?
Use the recovery codes you saved when you set it up, or the service’s recovery process.
Does 2FA protect my seed phrase?
No. 2FA protects accounts. Anyone with your seed phrase can still empty a self-custody wallet.