Security
Two-factor authentication for crypto accounts
A password alone is insufficient protection for a crypto account, since passwords can be leaked, guessed, or captured through phishing. Two-factor authentication (2FA) adds a second, independent step before access is granted, meaning a stolen password alone is no longer enough for an attacker. Not every form of 2FA offers the same protection, however: SMS codes are more vulnerable than authenticator apps, which in turn are less robust than physical security keys. Below we explain the different methods, their strengths and weaknesses, and how to set up and back up 2FA correctly.
Why a password alone is not enough
Passwords are regularly exposed through third-party data breaches, reuse across multiple sites, or simple phishing pages that forward login credentials directly to an attacker. Because crypto transactions are final and irreversible, keeping the bar for account access high matters even more.
2FA adds a factor independent of something you know (the password): something you have (a device or key) or something you are (biometrics). Even if a password is compromised, an attacker still needs the second factor to log in.
SMS codes: the weakest form of 2FA
SMS-based 2FA sends a one-time code to your phone number. This is better than no 2FA, but vulnerable to SIM swapping: an attacker convinces a phone provider (often through social engineering or a bribed employee) to transfer your number to a SIM card in their possession, after which SMS codes are sent to them.
For accounts holding significant value, SMS-based 2FA is therefore not recommended as the sole layer of security. It is an improvement over a password alone, but not the strongest option available.
Authenticator apps: the common standard
An authenticator app generates time-based one-time codes (TOTP) locally on your phone, without relying on the mobile network. This makes it immune to SIM swapping, though phishing remains a risk: a fake login page can ask you to enter both your password and the current code, which the attacker then relays directly to the real site.
When setting up an authenticator app, always save the recovery codes most platforms provide; without them, you lose access to the account if your phone is lost, broken or replaced. Store these recovery codes as carefully as a seed phrase: physically and offline.
- Immune to SIM swapping, unlike SMS
- Vulnerable to real-time phishing if the code is entered on a fake site
- Recovery codes are essential if the device is lost
Hardware security keys: the strongest option
A physical security key using the FIDO2/WebAuthn protocol offers the strongest protection against phishing. These keys cryptographically verify that the website they are communicating with is genuinely legitimate, so a fake page cannot complete authentication even if a user accidentally attempts to log in there.
The downside is that not every platform supports hardware keys, and you need to carry a physical device. For accounts holding significant value, such as large exchange positions, this remains the most robust protection currently available against phishing-based takeovers.
Setting up and backing up 2FA correctly
Enable 2FA on every account where it is available, not only crypto platforms but also the email address linked to those accounts; a compromised email often leads to a cascade of further compromised accounts via password-recovery flows.
Where possible, set up multiple 2FA methods as backups for each other, for example an authenticator app plus a hardware key, and store recovery codes physically separate from your devices. Avoid using the same phone number or the same email as the sole recovery method for multiple critical accounts.
Frequently asked questions
Is SMS-based 2FA better than no 2FA at all?
Yes, SMS-based 2FA is a clear improvement over a password alone, but it offers less protection than an authenticator app or hardware key due to the risk of SIM swapping.
What happens if I lose my phone with the authenticator app?
If you saved the recovery codes provided during setup, you can restore access on a new device. Without these codes, you usually need to go through an extensive identity-verification process with the provider, which can take time.
Can 2FA fully prevent phishing?
Authenticator apps do not fully protect against phishing, since an attacker can relay an entered code directly to the real site. Hardware keys using FIDO2 do protect against this by cryptographically verifying the website's identity.
Should I also enable 2FA on my email account?
Yes, this is strongly recommended, since an email account is often used to recover passwords for other accounts. A compromised email can therefore lead to access to several other accounts.
Is biometric verification (fingerprint or facial recognition) a form of 2FA?
Biometrics can serve as a factor within a 2FA setup, but the security depends heavily on how the device and its software process and store the biometric data.
Read next
Recognising phishing and wallet drainers
How to recognise phishing sites, fake messages and wallet drainers targeting crypto users. Practical warning signs and protective steps.
Holding your own crypto
How to set up a self-custody wallet, store a seed phrase safely and decide when a hardware wallet is worth it. Practical guide, not advice.
Spot crypto scams before you pay
From guaranteed returns to fake platforms: the recurring patterns behind crypto fraud and the checks you can run in two minutes.
Buying crypto in the Netherlands
How to buy crypto in the Netherlands using euros, iDEAL or SEPA, which providers are MiCA-registered, and what it costs. A practical checklist, not investment advice.