Setting up two-factor authentication
- Author
- CRYPTO PORT Editorial
- Published
- Updated
- Reading time
- 5 min
In short
Two-factor authentication is the minimum protection that keeps an account safe when a password leaks. For a crypto account, the right order is to set it up before any money goes in. And unless you keep the backup codes shown during setup, losing your phone locks you out of your own account.
Key points
- Set it up before you deposit, not after money has arrived
- An authenticator app beats SMS; a security key is stronger still where supported
- Always store the backup codes offline, for a lost or replaced phone
- Do it together with eliminating password reuse
Definition
A mechanism that requires a second factor — a one-time code from an authenticator app, a security key — in addition to a password when logging in or withdrawing. Also written 2FA.
Two-factor authentication matters especially on a crypto account because transfers cannot be reversed. Where a bank might attempt to claw back a fraudulent payment, assets already on-chain are gone. In other words, the loss is fixed the moment someone gets in — which is why you configure this before depositing anything.
The available methods differ in strength. Receiving codes by SMS is easy to set up but can be defeated by a SIM swap that takes over your phone number. An authenticator app (TOTP) generates time-limited codes on the device itself and is more robust. Where an operator supports a security key, that is the strongest option. Which methods are offered varies, so check the settings screen.
Setting up an authenticator app generally runs like this: open the two-factor item in the exchange's security settings, scan the QR code it displays with your authenticator app, then type the six-digit-or-so code the app shows to activate it. A string often called a secret key may be displayed alongside the QR code — it lets you generate the same codes on another device, which helps when you change phones. Treat it carefully, though: anyone who has it can defeat your second factor.
Save the backup codes at the same time, without exception. If your phone is lost, breaks or is reset, the authenticator's codes cannot be regenerated. Without backup codes you fall into an identity-document recovery process, during which you cannot withdraw. Print them or store them offline; do not screenshot them into a cloud photo library.
Once set up, log out and log back in to confirm it actually works. If the operator also offers two-factor prompts on withdrawals, or pre-registration of withdrawal addresses, enable those too — protecting only the login leaves you unable to stop a withdrawal if a session is hijacked. 'Security basics' covers the rest of the measures.
Watch out for
- · Never read a code out to anyone. No genuine support agent will ever ask for one
- · Do not keep backup codes and the secret key only on the same phone that runs the authenticator — losing the device loses both at once
- · Two-factor does not help if you type the code into a look-alike site yourself. Always log in from a bookmark
Frequently asked questions
What should I do when I change phones?
While the old phone still works, either use the authenticator app's own migration feature or disable and re-enrol 2FA at the exchange from the new device. Wiping the old phone without preparing first means going through account recovery.
Is SMS authentication not good enough?
It is far better than nothing, but it is weak against attacks that take over your phone number. Where an operator offers an authenticator app or a security key, prefer those.