Two-Factor Authentication (2FA)
A second login check beyond your password, usually a one-time code, that blocks attackers who steal credentials.
Two-factor authentication (2FA) requires two things to log in: something you know and something you have. The second factor is often a six-digit code from an app like Google Authenticator, a hardware key, or—weakest of all—an SMS text.
SMS 2FA is the soft spot. Attackers run SIM swaps to hijack the phone number and intercept those codes. App-based or hardware-key 2FA closes that gap. On exchanges, turn it on and skip SMS where you can.
Related terms
An attack that transfers your phone number to the attacker's SIM card to intercept calls and SMS codes.
Social EngineeringManipulating people rather than code, tricking them into handing over keys, codes, or access.
PhishingA scam that tricks you into revealing keys or signing a malicious transaction by posing as something you trust.
Centralized Exchange (CEX)A company that runs an order book, holds your funds, and matches buyers with sellers for a fee.