Two-factor authentication (2FA)
Logging in with two independent proofs, such as a password plus a code from an authenticator app. For accounts with exchanges and Bitcoin apps, 2FA is a must – and SMS codes are the weakest option.
Also2FAtwo-step verificationMFAmulti-factor authenticationauthenticator appTOTPsecurity key
With two-factor authentication, a password alone isn’t enough. You need two proofs from different categories: something you know (a password, a PIN), something you have (a smartphone, a security key) or something you are (a fingerprint).[1] Anyone who only steals your password still can’t get into your account.
| Method | Assessment |
|---|---|
| SMS code | better than nothing, but vulnerable to SIM swappingGlossarySIM swappingFraudsters get your mobile number transferred to their own SIM card and so receive your text-message codes. They use this to take over accounts that are only protected by SMS. Protection: 2FA via an app or security key instead of SMS.On the learning path: Stage 6 · Step 2 – Spotting scams →In the glossary → |
| Authenticator app (usually a 6-digit code that changes every 30 seconds) | a good standard |
| Hardware security key (FIDO) | the most secure |
According to the BSI, Germany’s Federal Office for Information Security, a key stored in hardware, such as on a FIDO/U2F stick, is more secure than one stored in software. SMS codes shouldn’t arrive on the same device you log in with.[1]
With exchanges and Bitcoin apps
- Turn on 2FA for logging in and for withdrawals, wherever possible.
- Write down the backup codes offline when you set it up – otherwise you’ll lock yourself out if you lose your phone.
- Only ever enter 2FA codes yourself, in the official app or on the official website. If someone asks for one on the phone or in a chat, it’s a scam – even if they claim to be support.
Related terms
These terms are closely connected.
- This termTwo-factor authentication(2FA)
- SIM swappingFraudsters get your mobile number transferred to their own SIM card and so receive your text-message codes. They use this to take over accounts that are only protected by SMS. Protection: 2FA via an app or security key instead of SMS.
- PhishingFraud using fake emails, text messages, websites or calls that look like genuine exchanges, wallet makers or banks. The goal is your passwords, 2FA codes – and above all your seed phrase.
- Custodian (custodial)A provider such as an exchange or app that holds the private keys for you. Convenient, because support can help if you lose your password – but you don’t hold the bitcoin yourself and depend on the provider paying out.
- Exchange (crypto exchange)A trading platform where buyers and sellers trade bitcoin with each other via an order book. The price results from supply and demand; fees usually follow the maker-taker model.
Explained in depth
These articles go into more detail:
- Stage 4 · Step 3Buying BitcoinRegistration, ID check, two-factor protection, SEPA deposit and first purchase: the complete process with example screens and warnings.
- Deep dive · Stage 6Security checklistThree checklists to tick off – basics, your own hardware wallet, significant holdings: how to secure your account, wallet and seed phrase step by step.
- Stage 6 · Step 2Spotting scamsPhishing, fake support, investment and romance scams, AI fakes: how to spot 13 typical Bitcoin scams – and what to do if the worst happens.
More from „Wallets & security“
Sources1 sources · 1 publishers
The superscript numbers in the text refer to these sources.
- Zwei-Faktor-Authentisierung – Bundesamt für Sicherheit in der Informationstechnik (BSI) (accessed 28/09/2026)
This entry is for education only and is not investment, tax or legal advice.