Two-Factor Authentication (2FA)
Two-factor authentication adds a second step beyond a password, such as an authenticator app code or hardware key, to protect exchange accounts.
Two-factor authentication requires two separate proofs of identity to log in or withdraw: something you know, like a password, and something you have, like a phone app or a physical security key. Crypto exchanges and custodial wallets support it, and enabling it is one of the most effective steps against account takeover.
Not all second factors are equal. SMS codes are the weakest because attackers can take over a phone number through a SIM swap, a technique that has been used to drain many crypto accounts. Authenticator apps such as Google Authenticator or Authy generate codes on the device and are much harder to intercept. Hardware security keys that support FIDO2 or passkeys are the strongest option.
2FA protects accounts, not self-custody wallets. A seed phrase or private key has no login to protect, so 2FA does not apply. For exchange accounts, enabling 2FA on withdrawals as well as logins, and setting a withdrawal address allowlist, adds further protection.
Coinucation