How to Set Up 2FA
If hackers get your password (from data breaches, phishing, etc.), 2FA is your last line of defense. Set this up IMMEDIATELY on all crypto accounts.
Why 2FA Matters
Two-factor authentication requires TWO things to log in:
- Something you know - Your password
- Something you have - Your phone with authenticator app
Even if hackers steal your password, they can't access your account without your phone.
Types of 2FA (Best to Worst):
| Type | Security | Notes |
|---|---|---|
| Hardware Keys (YubiKey) | Best | Physical device, unhackable remotely |
| Authenticator Apps | Excellent | Recommended for most users |
| SMS Text Message | Poor | Vulnerable to SIM swapping |
| Email Codes | Poor | If email is hacked, 2FA is useless |
Hackers can call your phone carrier, pretend to be you, and transfer your number to their SIM card. They then receive all your SMS codes. This is called "SIM swapping" and has stolen millions in crypto.
Choose an Authenticator App
Top Recommendations:
Authy (Recommended)
- Cloud backup (can recover if phone lost)
- Multi-device sync
- Works on desktop too
- Free
Google Authenticator
- Simple, no frills
- Now supports cloud backup
- Widely compatible
- Free
Microsoft Authenticator
- Cloud backup
- Good for Microsoft ecosystem
- Password manager built-in
- Free
Authy's cloud backup has saved countless people who lost their phones. Without backup, losing your phone means losing access to all accounts until you recover each manually.
Setting Up 2FA
General Process (same for most platforms):
- Download authenticator app on your phone
- Log into your crypto exchange/wallet
- Go to Settings → Security → Two-Factor Authentication
- Select "Authenticator App" (NOT SMS)
- A QR code will appear on screen
- Open your authenticator app
- Tap "+" or "Add Account"
- Scan the QR code
- Enter the 6-digit code shown in the app
- SAVE THE BACKUP CODES!
Authenticator codes expire quickly. If the code is about to change (timer running out), wait for a fresh code to avoid errors.
Enable 2FA on These First:
- Email - Your email is the master key to everything
- Crypto exchanges - Coinbase, Binance, Kraken, etc.
- Password manager - If you use one (you should!)
- Social media - Often used for crypto scams/impersonation
Backup Codes Are Critical
When you set up 2FA, you'll receive backup codes. These are your ONLY way to recover access if you lose your phone.
What to Do with Backup Codes:
- Write them down on paper (not digitally!)
- Store with your seed phrase backup
- Keep in a secure location
- Never share or store in cloud
If you lose your phone and don't have backup codes, you may have to go through lengthy identity verification to recover accounts. Some smaller platforms may not help at all. SAVE THOSE CODES!
If You Lose Your Phone:
- If using Authy - Install on new phone, log in with your number
- If using Google Auth without backup - Use backup codes to log in
- No backup codes - Contact support with ID verification (takes days/weeks)
When setting up 2FA, you can screenshot the QR code and store it securely (encrypted, offline). This lets you restore the same 2FA on a new device without backup codes. Store as securely as your seed phrase!