1. Home
  2. Glossary

What is two-factor authentication (2FA), and why turn it on?

Short answer

Two-factor authentication (2FA) means that to log in or withdraw, you need a one-time code on top of your password, such as the 6-digit code an authenticator app shows, which changes every 30 seconds. If someone steals your password but doesn't have your phone, they still can't get in.

  • Use an authenticator app such as Google Authenticator or Microsoft Authenticator. It's safer than text messages.
  • Write the backup key down on paper when you set it up, and never give anyone your codes.

In one line

A second code on top of your password, one that only you can get.

An example

Your password leaks from another website, and someone tries it on your exchange account:

  • Without 2FA: the password works, they get in, and they may withdraw your crypto.
  • With 2FA: they also need the 6-digit code from the authenticator app on your phone. They don’t have it, so they can’t get in.

FAQ

Which kind of 2FA is best?

An authenticator app is the most common, and it's safer than text messages, which someone can intercept by taking over your phone number. Email codes are only as safe as your email account.

What if I lose my phone or get a new one?

Use the backup key you wrote down to restore your authenticator app on the new phone. If you didn't keep it, you'll have to go through the exchange's reset process and wait for a review.

Someone is asking for my 2FA code. Should I give it?

No. Never give your codes to anyone, including people claiming to be support. Exchange staff will never ask for them.