Two-Factor Authentication (2FA)
Two-factor authentication, or 2FA, is an account-security method that requires two different forms of verification before access is granted. Instead of protecting an exchange account with only a password, 2FA adds a second authentication factor.
✦ Key Insight
Protects your account from hackers even if your password is stolen — essential for any CEX holding funds.
✕ Common Misconceptions
Relying on SMS when stronger options are available
Saving recovery codes insecurely
Approving unexpected authentication prompts
Using the same password everywhere
Forgetting to protect the email account linked to the exchange
Confusing 2FA with wallet private-key security
Detailed Explanation
How It Works
A user first enters their password.
The service then requires another factor, which might include:
An authenticator-app code
A hardware security key
A passkey or device confirmation
A one-time SMS code
Authenticator apps and physical security keys generally avoid some of the risks associated with SMS, such as SIM-swapping attacks.
FAQs
Does 2FA protect a stolen seed phrase?
No. Someone with a self-custody wallet's recovery phrase generally does not need your exchange 2FA.
Is SMS 2FA better than no 2FA?
Usually, but stronger authentication methods may provide better protection.
Should my email also use 2FA?
Yes. Email can be a critical recovery channel for financial accounts.
