Two-Factor Authentication (2FA)
Platforms & ToolsA second login proof alongside the password for a trading account — with authenticator apps and hardware keys stronger than SMS, which SIM swaps can defeat.
Two-factor authentication requires a second proof of identity alongside the password when logging in to a trading account or client portal — typically a code from an authenticator app, a hardware key, or a code sent by SMS. It exists because passwords are reused and leaked, and a leaked password alone should not be enough to reach an account holding money.
The methods are not equivalent. An authenticator app or hardware key is bound to a device you hold; SMS codes travel over a network that can be redirected by a SIM swap, which is the attack most often used against accounts with funds in them. Where a broker offers both, the app or key is the stronger choice, and recovery codes should be stored somewhere other than the device generating them.