Crypto Explained SimplyStart here. No jargon, no assumptions.

How to Set Up Two-Factor Authentication

The single most valuable security setting on any exchange account, why SMS is the weakest option, and how to set up something better.

What this covers
  1. The three options, from weakest to strongest
  2. How to set up an authenticator application
  3. The setting that matters as much
  4. The third setting
  5. The dedicated email
  6. The ten-minute version

Two-factor authentication means proving who you are with something beyond a password. On a crypto account it is the difference between a leaked password being an inconvenience and being a total loss.

The three options, from weakest to strongest

SMS. A code sent to your phone number.

The weakness is that your phone number is controlled by your mobile carrier, not by you. An attacker who convinces the carrier to move your number to their SIM receives every code. This attack is documented, repeated, and typically completes within an hour.

An authenticator application. A code generated on your device from a shared secret. Nothing is transmitted, so a stolen phone number gains an attacker nothing.

This is the minimum acceptable option.

A hardware security key. A physical device required to log in. It verifies the site before responding, which means a fraudulent site receives nothing usable even if you are completely deceived.

This is the only option that defeats phishing, and phishing is the most common attack.

How to set up an authenticator application

  1. Install a reputable authenticator application
  2. In your exchange account settings, find two-factor authentication and choose the application option
  3. Scan the code displayed
  4. Save the backup codes or the setup secret. Write them down and store them with your other important documents
  5. Enter a generated code to confirm
  6. Remove SMS as an option if the platform allows it

Step four is the one people skip. Losing the phone without a backup means an account recovery process that can take weeks.

The setting that matters as much

Remove your phone number as a recovery option.

A stronger second factor is undermined entirely by leaving a weaker fallback attached to the same account. This is the most common configuration error.

Also set a port-out PIN with your mobile carrier, which prevents a number transfer without an additional code. It takes five minutes and is not enabled by default.

The third setting

A withdrawal address allowlist, with a delay before new addresses become usable.

This converts a successful account takeover from an instant theft into a window in which you might notice. Venues offering it, including exchanges that support direct bank transfer, document it in their security pages.

The dedicated email

Use an email address for financial accounts that you use nowhere else and do not publish, protected by a hardware key.

Email is the recovery path for everything else, which makes it the actual perimeter. Most account compromises start there.

The ten-minute version

Authenticator application. Backup codes written down. Phone number removed as recovery. Carrier PIN set. Withdrawal allowlist enabled. Dedicated email.

That list closes the routes through which almost every account compromise actually happens.