Two-factor authentication: why and how
TOTP-based 2FA closes the most common account-takeover vector. Set it up in two minutes.
Most "hacked account" stories boil down to a leaked or guessed password. Two-factor authentication breaks that chain: even with the password, an attacker needs the rotating 6-digit code from your phone to get in.
What you need
A TOTP authenticator app. Anything that implements the standard works:
- Authy (cross-device backup, recommended for non-technical users)
- Aegis (Android, open source)
- Google Authenticator (simple, no backup)
- 1Password, Bitwarden (built into the password manager)
Setting it up
- Go to Settings → Security and click Enable 2FA.
- Scan the QR code with your authenticator app, or type the secret manually.
- Enter the 6-digit code the app shows to confirm.
- Save your recovery codes. Print them or store them in your password manager. If you lose your phone, these are the only way back in.
Logging in with 2FA
Every login asks for your password, then for the current 6-digit code. The code rotates every 30 seconds. If your code keeps failing, your phone's clock is probably out of sync — toggle automatic time on, or in Authy, use "Sync Time."
If you lose your device
Use a recovery code to log in, then disable 2FA, then re-enable it with the new device. If you also lost the recovery codes, contact support — be prepared to verify identity through the original email, recent deposit address, and other account history.

