Explainer · Crypto Safety
2FA for crypto accounts: how each method can fail
Two-factor authentication adds a second lock to your login, but not every second factor stops the same attacks. On a crypto account, where transfers are hard to undo, the difference matters.

Quick answer
Two-factor authentication asks for a second proof besides your password. Use it on every crypto and email account. A physical security key is the strongest option for consumers [1]. CISA says text-message codes should be a last resort, and any code you type can be stolen by a fake site [2].
Key points
- Two-factor authentication requires credentials from two of three categories: something you know, have or are [1].
- Any code you type, from a text message or an app, can be captured on a fake login page and replayed [2].
- Text-message codes can be stolen through a SIM swap; CISA calls SMS a last resort [2].
- FIDO/WebAuthn security keys are the only widely available phishing-resistant option [2].
- Never share a code with someone who contacted you [1], and never approve a login prompt you did not start: push bombing relies on that tap [2].
On this page
What is two-factor authentication?#
A password is something you know. Two-factor authentication (2FA) adds a second, different kind of proof before you can log in. The US Federal Trade Commission explains that accounts with 2FA require a credential from two of three categories [1]. The US cybersecurity agency CISA lists the three as something you know, something you have and something you are [2]. Multi-factor authentication (MFA) is the general term for two or more.
The SEC's custody bulletin tells crypto investors to use strong passwords and multi-factor authentication for all their online crypto asset accounts [3]. That matters more for crypto than for most accounts: a payment in crypto typically cannot be reversed [4], so a thief who gets in and withdraws your coins rarely has to worry about the transfer being undone.
Which kinds of second factor can you choose?#
An exchange may offer you several options. The FTC lists one-time codes by text or email, authenticator apps on a phone or tablet, and physical security keys [1]. CISA adds push notifications, which ask you to tap Approve in an app [2]. The table compares them on the question that matters most: can a fake website steal it?
| Second factor | How it works | Stops a fake login page? | Main weakness |
|---|---|---|---|
| Text-message (SMS) code | A one-time code is sent to your phone number | No, you type the code | SIM swaps hand your number, and your codes, to an attacker |
| Email code | A one-time code is sent to your inbox | No, you type the code | Only as safe as your email account |
| Authenticator app code | An app on your phone shows a new six-digit code | No, you type the code | A fake page can capture the code along with your password |
| Push notification | An app asks you to approve the login | No | Push bombing: repeated prompts until you tap Approve |
| Security key (FIDO/WebAuthn) | A small physical device you plug in or tap | Yes | You must keep it, and a backup, safe |
Sources: FTC guide to 2FA [1]; CISA fact sheet on phishing-resistant MFA [2]; NIST SP 800-63B-4 on codes you type [5].
The FTC calls security keys the strongest method of two-factor authentication because they do not use credentials that hackers can steal [1]. CISA says FIDO/WebAuthn is the only widely available phishing-resistant authentication [2]. Anything that makes you type a code is, by the US standards body NIST's definition, not phishing-resistant [5].
How can a fake login page beat a six-digit code?#
Nobody needs to guess your code. A six-digit code has 1,000,000 possible values, so one random guess has a 1 in 1,000,000 chance, or 0.0001% (calculated). Attackers ask you for it instead. CISA describes phishing pages that capture the username, the password and the six-digit code from an authenticator app [2]. The attacker types them into the real site while the code is still valid, and the second factor has been passed.
What are SIM swaps and push bombing?#
A SIM swap targets text-message codes. CISA explains that attackers convince mobile carriers to transfer control of a victim's phone number to a SIM card the attacker controls [2]. From then on, the codes arrive on the attacker's phone. CISA says SMS or voice MFA should only be used as a last resort [2]. NIST's 2025 guidance labels the use of the phone network for these codes as restricted and lists SIM change and number porting as risk signals [5].
Push bombing targets approval prompts. CISA describes attackers bombarding a user with push notifications until they press Accept [2]. Number matching, where you type a number shown on the login screen into the app, adds a step that makes blind approval harder [2].
One caveat: NIST and CISA write for government systems and organisations, not for crypto exchanges [5]. Their reasoning about codes, phones and prompts still applies to any login.
How do you set up 2FA on a crypto account?#
- Secure your email first
The FTC says to start with your most sensitive accounts and names email among them [1]. If your email can reset your exchange password, it needs the same protection as the exchange.
- Check what the fallback is
If the account still accepts a text-message code when the stronger factor is unavailable, that fallback is the weak point an attacker will aim for.
- Store backups offline
If the exchange gives you recovery codes, or lets you register a second security key, keep them somewhere offline and separate from your phone.
- Only let the account remember your own devices
Do not tick remember this device on a shared or public computer [1].
- Decide your rule for codes now
You will never read out a code, enter one on a page you reached from a message, or approve a prompt you did not start. Writing the rule down before a scammer calls makes it easier to keep.
Mistakes beginners make with 2FA for crypto accounts#
- Approving a prompt you did not trigger
A login prompt you did not start means someone else has your password. Deny it and change the password; tapping Approve to make the prompts stop is what push bombing relies on [2].
- Relying on text messages when better options exist
SMS codes are exposed to SIM swaps and phishing, which is why CISA calls them a last resort [2].
- Protecting the exchange but not the email
If your inbox can reset your exchange password, an attacker who controls the inbox may not need your password at all. Give your email the same second factor as your exchange.
- Thinking 2FA protects a self-custody wallet
Fake airdrop sites ask for the seed phrase itself, and whoever enters it can take the coins [6]. Read seed phrase vs private key to see what those words unlock.
Frequently asked questions#
Is text-message 2FA better than nothing?
Yes. CISA says any form of MFA is better than no MFA, while calling phishing-resistant MFA the gold standard [2]. Use text messages if they are the only option, and switch when the exchange offers something stronger.
Are passkeys the same as security keys?
Our sources do not discuss passkeys by name. They describe FIDO/WebAuthn authentication as phishing-resistant [2]. If your exchange offers passkeys, check whether it describes them as FIDO or WebAuthn.
Someone asked for my 2FA code. What should I do?
Do not give it, whatever the story [1]. Log in to the account yourself by typing its address, change your password and check recent activity. Our guide to crypto scams covers the scripts scammers use.
Does 2FA protect my coins if the exchange is hacked or fails?
No. 2FA protects your login. If a custodian is hacked, shuts down or goes bankrupt, you may lose access to your crypto regardless [3].
The bottom line#
Turn on two-factor authentication for your email and every crypto account, and choose the strongest factor offered: a security key first, an authenticator app second, text messages only as a last resort. Then keep one rule: never share a code or approve a prompt you did not start. 2FA protects your login, not your coins against every risk, so read the risk disclosure and our custodial vs non custodial wallet guide too.
Sources
- Use Two-Factor Authentication To Protect Your Accounts.
- Implementing Phishing-Resistant MFA (CISA fact sheet).
- Crypto Asset Custody Basics for Retail Investors - Investor Bulletin.
- What To Know About Cryptocurrency and Scams.
- NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management - Authenticators section.
- Cybercriminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards.
Education only. This page is not investment, tax or legal advice. Trading and crypto can lose you money. See our risk disclosure.


