Library · Crypto, word by word · Scams and security
What is two-factor authentication (2FA)?
Two-factor authentication asks for a second proof of identity on top of a password, such as a code from an app, a text message or a physical security key, so a stolen password alone cannot open an account.
What it means for you
For an exchange account, 2FA is the main barrier between a leaked password and an emptied balance. A code by text message is the weakest kind, because a SIM swap can redirect it; an authenticator app is stronger, and a security key is the hardest to phish. 2FA protects accounts, not a wallet's seed phrase: anyone with the phrase needs no second factor.
How it works
CISA describes the forms in order of strength: text message and voice codes at the bottom, app-based codes and push prompts in the middle, and FIDO or WebAuthn security keys and passkeys as the only widely available kind that resists phishing, because the key checks which website is asking. Its advice is that any 2FA beats none. Push prompts can be abused by sending a stream of them until someone taps approve, which is why number matching was added. Recovery codes saved when 2FA is set up are the way back in if the phone is lost.
Source: CISA: More than a password (multifactor authentication) · checked 5 October 2026
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.