What Two-Factor Authentication Is and Why It Matters for Crypto
What 2FA is, how an authenticator app works, why it beats SMS, and what to do if you lose your phone. Plain explanation for crypto users.

Two-factor authentication adds a second lock to your account. A password can be stolen. The second factor lives on your phone and changes every 30 seconds. Even with your password, an attacker cannot get in without that code.
How it works
When you log in, the service asks for your password and then a six-digit code from an authenticator app. The app generates codes locally, without an internet connection, based on the current time. Each code expires in 30 seconds and cannot be reused.
Why an authenticator app beats SMS
SMS codes are better than a password alone, but they can be intercepted. SIM-swapping attacks redirect your phone number to an attacker's SIM, giving them your SMS codes. For any account holding meaningful funds, use an authenticator app instead.
Which app to use
Any standard authenticator app works. They run without internet access and without an account. Pick one and stick with it.
The trap people fall into at setup
When you enable 2FA, the service shows backup codes or a recovery QR. Write those down and store them offline. If you lose your phone without a backup, you lose access to the account. That is the most common way people get locked out permanently.
Where to enable it without exception
On exchanges and wallets where funds are stored. Also on the email address those accounts use for recovery. If your email has no 2FA, an attacker who gets into your email can reset the exchange password and bypass the second factor entirely.
What 2FA does not protect against
If you enter your credentials, including your 2FA code, on a phishing site, the attacker uses that code immediately on the real site. Two-factor authentication is not a defense against phishing. That requires checking the URL before you type anything.



