Security

Two-Factor Authentication (2FA)

A second login check beyond your password, usually a one-time code, that blocks attackers who steal credentials.

Two-factor authentication (2FA) requires two things to log in: something you know and something you have. The second factor is often a six-digit code from an app like Google Authenticator, a hardware key, or—weakest of all—an SMS text.

SMS 2FA is the soft spot. Attackers run SIM swaps to hijack the phone number and intercept those codes. App-based or hardware-key 2FA closes that gap. On exchanges, turn it on and skip SMS where you can.

Related terms