What a second factor protects
A password can leak through a breached service, malicious browser extension, or fake login page. Two-factor authentication adds another requirement before someone can access your account. Enable it on your email first, then on each exchange, before depositing funds.
Account security and custody are separate problems. A second factor does not protect you from an exchange failure or a withdrawal you authorize yourself. Keep your recovery plan and your choice of where to hold crypto separate from your login settings.
Security key, authenticator app, or SMS?
Where supported, a FIDO security key or passkey provides phishing resistance by binding authentication to the real service. Check how the exchange implements passkeys and which recovery methods can bypass them. A strong login method is weakened by an unprotected fallback.
An authenticator app generates time-based codes without relying on your mobile carrier. This removes the SMS interception route, but a fake website can still trick you into entering a valid code. SMS is an improvement over a password alone when no stronger option exists, but it should not be your first choice for an account holding funds.
Set it up in a deliberate order
Open the exchange from your saved address and find its security settings. Follow its current instructions; labels and supported methods differ by provider.
- Install your chosen authenticator from its official publisher, or register a supported security key or passkey.
- For an authenticator, scan the setup QR code in the app and enter the current verification code into the exchange.
- Treat the setup QR code and secret as credentials. Do not screenshot them into a photo account that syncs to the cloud.
- Save the recovery codes before closing the setup screen. Register a second security key if the provider supports one.
- Test the new sign-in method in another session while your original session remains available.
- Review old SMS methods, trusted devices, and account-recovery settings. Remove unnecessary fallbacks without locking yourself out.
Recovery codes are spare keys
A lost phone should not mean a lost account. Keep recovery codes somewhere you can access without that phone, such as a protected offline record. Anyone with these codes may be able to bypass your second factor, so do not send them to support or share them in a chat.
Cloud synchronization and authenticator backups can make device replacement easier. They also create another account to secure. Understand whether your app synchronizes secrets, how recovery works, and whether a separate recovery password is required.
If the phone or key disappears
Use your registered spare key or a recovery code from the legitimate exchange website. Once you regain access, remove the missing device, issue fresh recovery codes where possible, and inspect sessions, withdrawal addresses, and recent activity.
If you cannot authenticate, contact support through the official website. Identity checks may be required. A person who contacts you privately offering to bypass that process should not receive credentials, remote access, or a payment.
Sources & limits
Source review: Oct 1, 2026. Availability and provider terms can change.
Keep exploring
Keep a phone-number takeover from becoming an account takeover
Reduce reliance on SMS, protect carrier-account changes, and know the first steps to take if your number is transferred without permission.
Read page →Build a password-manager setup you can recover
Use unique passwords, protect the vault, separate high-value second factors, and keep a recovery plan that survives a lost device.
Read page →Secure an exchange account and understand custody risk
Review authentication, withdrawals, API permissions, the legal entity holding your crypto, and what protection applies to each balance.
Read page →