Plain-English trading and crypto, with the risks left in.

Plain-English trading and crypto, with the risks left in.

Delayed data

Education, not investment advice. Trading can lose you money. How we check every fact

Explainer · Crypto Safety

2FA for crypto accounts: how each method can fail

Two-factor authentication adds a second lock to your login, but not every second factor stops the same attacks. On a crypto account, where transfers are hard to undo, the difference matters.

Two hands holding a smartphone above a table
Photo: "Iphone Smartphone" by Adrianna Calvo, CC0 (edited: cropped/resized).

Quick answer

Two-factor authentication asks for a second proof besides your password. Use it on every crypto and email account. A physical security key is the strongest option for consumers [1]. CISA says text-message codes should be a last resort, and any code you type can be stolen by a fake site [2].

Key points

  • Two-factor authentication requires credentials from two of three categories: something you know, have or are [1].
  • Any code you type, from a text message or an app, can be captured on a fake login page and replayed [2].
  • Text-message codes can be stolen through a SIM swap; CISA calls SMS a last resort [2].
  • FIDO/WebAuthn security keys are the only widely available phishing-resistant option [2].
  • Never share a code with someone who contacted you [1], and never approve a login prompt you did not start: push bombing relies on that tap [2].
On this page

What is two-factor authentication?#

A password is something you know. Two-factor authentication (2FA) adds a second, different kind of proof before you can log in. The US Federal Trade Commission explains that accounts with 2FA require a credential from two of three categories [1]. The US cybersecurity agency CISA lists the three as something you know, something you have and something you are [2]. Multi-factor authentication (MFA) is the general term for two or more.

The SEC's custody bulletin tells crypto investors to use strong passwords and multi-factor authentication for all their online crypto asset accounts [3]. That matters more for crypto than for most accounts: a payment in crypto typically cannot be reversed [4], so a thief who gets in and withdraws your coins rarely has to worry about the transfer being undone.

Which kinds of second factor can you choose?#

An exchange may offer you several options. The FTC lists one-time codes by text or email, authenticator apps on a phone or tablet, and physical security keys [1]. CISA adds push notifications, which ask you to tap Approve in an app [2]. The table compares them on the question that matters most: can a fake website steal it?

Second factorHow it worksStops a fake login page?Main weakness
Text-message (SMS) codeA one-time code is sent to your phone numberNo, you type the codeSIM swaps hand your number, and your codes, to an attacker
Email codeA one-time code is sent to your inboxNo, you type the codeOnly as safe as your email account
Authenticator app codeAn app on your phone shows a new six-digit codeNo, you type the codeA fake page can capture the code along with your password
Push notificationAn app asks you to approve the loginNoPush bombing: repeated prompts until you tap Approve
Security key (FIDO/WebAuthn)A small physical device you plug in or tapYesYou must keep it, and a backup, safe

Sources: FTC guide to 2FA [1]; CISA fact sheet on phishing-resistant MFA [2]; NIST SP 800-63B-4 on codes you type [5].

The FTC calls security keys the strongest method of two-factor authentication because they do not use credentials that hackers can steal [1]. CISA says FIDO/WebAuthn is the only widely available phishing-resistant authentication [2]. Anything that makes you type a code is, by the US standards body NIST's definition, not phishing-resistant [5].

How can a fake login page beat a six-digit code?#

Nobody needs to guess your code. A six-digit code has 1,000,000 possible values, so one random guess has a 1 in 1,000,000 chance, or 0.0001% (calculated). Attackers ask you for it instead. CISA describes phishing pages that capture the username, the password and the six-digit code from an authenticator app [2]. The attacker types them into the real site while the code is still valid, and the second factor has been passed.

Link to a fakeexchange loginYou typepassword andcodeAttacker relaysboth to thereal siteAttacker islogged inCoins arewithdrawnLink to a fake exchange loginYou type password and codeAttacker relays both to the realsiteAttacker is logged inCoins are withdrawn
How a phished code is replayed. The relay CISA describes for codes you type. Any factor you type into the fake page can be passed on in the same way.

What are SIM swaps and push bombing?#

A SIM swap targets text-message codes. CISA explains that attackers convince mobile carriers to transfer control of a victim's phone number to a SIM card the attacker controls [2]. From then on, the codes arrive on the attacker's phone. CISA says SMS or voice MFA should only be used as a last resort [2]. NIST's 2025 guidance labels the use of the phone network for these codes as restricted and lists SIM change and number porting as risk signals [5].

Push bombing targets approval prompts. CISA describes attackers bombarding a user with push notifications until they press Accept [2]. Number matching, where you type a number shown on the login screen into the app, adds a step that makes blind approval harder [2].

One caveat: NIST and CISA write for government systems and organisations, not for crypto exchanges [5]. Their reasoning about codes, phones and prompts still applies to any login.

2FA in numbers
Categories a 2FA login draws from
2 of 3FTC [1]
Possible six-digit codes
1,000,00010 to the power 6, calculated
Time limit NIST sets for an out-of-band login
10 minutesNIST SP 800-63B-4 [5]
Phishing-resistant method CISA calls widely available
FIDO/WebAuthnCISA fact sheet, 2022 [2]

How do you set up 2FA on a crypto account?#

  1. Secure your email first

    The FTC says to start with your most sensitive accounts and names email among them [1]. If your email can reset your exchange password, it needs the same protection as the exchange.

  2. Pick the strongest factor the exchange offers

    A security key if it is supported [1]. If not, an authenticator app. Use text messages only when nothing else is offered, as CISA advises [2].

  3. Check what the fallback is

    If the account still accepts a text-message code when the stronger factor is unavailable, that fallback is the weak point an attacker will aim for.

  4. Store backups offline

    If the exchange gives you recovery codes, or lets you register a second security key, keep them somewhere offline and separate from your phone.

  5. Only let the account remember your own devices

    Do not tick remember this device on a shared or public computer [1].

  6. Decide your rule for codes now

    You will never read out a code, enter one on a page you reached from a message, or approve a prompt you did not start. Writing the rule down before a scammer calls makes it easier to keep.

Mistakes beginners make with 2FA for crypto accounts#

  • Sharing a code with someone who contacted you

    The FTC's rule: no matter what the story is, do not share a verification code with someone if you did not contact them first [1]. The FBI gives the same advice for one-time passwords and seed phrases [6].

  • Approving a prompt you did not trigger

    A login prompt you did not start means someone else has your password. Deny it and change the password; tapping Approve to make the prompts stop is what push bombing relies on [2].

  • Relying on text messages when better options exist

    SMS codes are exposed to SIM swaps and phishing, which is why CISA calls them a last resort [2].

  • Protecting the exchange but not the email

    If your inbox can reset your exchange password, an attacker who controls the inbox may not need your password at all. Give your email the same second factor as your exchange.

  • Thinking 2FA protects a self-custody wallet

    Fake airdrop sites ask for the seed phrase itself, and whoever enters it can take the coins [6]. Read seed phrase vs private key to see what those words unlock.

Frequently asked questions#

Is text-message 2FA better than nothing?

Yes. CISA says any form of MFA is better than no MFA, while calling phishing-resistant MFA the gold standard [2]. Use text messages if they are the only option, and switch when the exchange offers something stronger.

Are passkeys the same as security keys?

Our sources do not discuss passkeys by name. They describe FIDO/WebAuthn authentication as phishing-resistant [2]. If your exchange offers passkeys, check whether it describes them as FIDO or WebAuthn.

Someone asked for my 2FA code. What should I do?

Do not give it, whatever the story [1]. Log in to the account yourself by typing its address, change your password and check recent activity. Our guide to crypto scams covers the scripts scammers use.

Does 2FA protect my coins if the exchange is hacked or fails?

No. 2FA protects your login. If a custodian is hacked, shuts down or goes bankrupt, you may lose access to your crypto regardless [3].

The bottom line#

Turn on two-factor authentication for your email and every crypto account, and choose the strongest factor offered: a security key first, an authenticator app second, text messages only as a last resort. Then keep one rule: never share a code or approve a prompt you did not start. 2FA protects your login, not your coins against every risk, so read the risk disclosure and our custodial vs non custodial wallet guide too.

Sources

  1. Use Two-Factor Authentication To Protect Your Accounts. U.S. Federal Trade Commission (Consumer Advice), 2024.
  2. Implementing Phishing-Resistant MFA (CISA fact sheet). U.S. Cybersecurity and Infrastructure Security Agency (CISA), 2022.
  3. Crypto Asset Custody Basics for Retail Investors - Investor Bulletin. U.S. Securities and Exchange Commission, Office of Investor Education and Advocacy (Investor.gov), 2025.
  4. What To Know About Cryptocurrency and Scams. U.S. Federal Trade Commission (Consumer Advice), 2025.
  5. NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management - Authenticators section. U.S. National Institute of Standards and Technology (NIST), 2025.
  6. Cybercriminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards. U.S. Federal Bureau of Investigation (FBI), 2025.

Education only. This page is not investment, tax or legal advice. Trading and crypto can lose you money. See our risk disclosure.

Keep reading