Definition
2FA combines two distinct authentication factors: something you know, something you have or something you are. A password plus a code from a registered authenticator is a common example. Two passwords are still one factor category, so merely adding a second screen or question does not necessarily provide true two-factor protection.
How It Works
After checking the first factor, a service verifies the second according to its design. This may involve a time-based code, a physical security key or another supported authenticator. Some authenticators combine a possession factor with local PIN or biometric activation in one device. A crypto service may require authentication for login or withdrawal, but these checks protect that service account rather than changing the rules of an unrelated blockchain private key.
Key Considerations
Protection varies by method. Codes can be stolen through real-time phishing, and phone-number-based codes can be exposed by SIM-swap attacks. Properly implemented origin-bound security keys offer stronger phishing resistance. Save recovery codes securely, review the account recovery process and remove lost authenticators through trusted channels. Enabling 2FA does not undo a compromised session or make malicious transactions harmless, and it does not protect assets controlled directly by a leaked seed phrase.