Skip to content
CryptoList.com.au

What is Two-factor authentication (2FA)?

A second login check beyond your password — ideally an authenticator app or hardware key, not SMS, which is vulnerable to SIM-swap attacks. The single highest-value security upgrade for exchange accounts.

Two-factor authentication adds a second lock to your accounts: something you have (a code-generating app, a hardware key) on top of something you know (your password). For crypto accounts it isn't optional hygiene — it's the single highest-value security upgrade available, because passwords leak constantly and crypto theft doesn't reverse.

The hierarchy matters: hardware security keys beat authenticator apps, which decisively beat SMS — text-message codes fall to SIM-swap attacks, where a criminal ports your phone number and receives your codes. Australian telcos have tightened porting rules, but SMS remains the weakest link, and exchanges are exactly where SIM-swappers aim. Set app-based 2FA on your exchange and email both (email resets everything else), store the recovery codes offline, and treat any unprompted 2FA code arriving as an attack in progress — someone has your password.

Related terms: Phishing · Custodial · Seed phrase · full glossary

FAQ

Why is SMS 2FA considered weak?

Because it authenticates your phone number, not you — and numbers can be stolen via SIM-swap social engineering against your telco. App or hardware-key 2FA lives on the device itself, out of the carrier's hands.

What if I lose my phone with the authenticator app?

That's what the recovery codes shown at setup are for — store them offline like a seed phrase. Without them, re-access means the exchange's identity-verification process: slow, but that friction is the security working.

General information only, not financial advice. Definitions are maintained in our fact database and reviewed with the daily rebuild.