Two factor authentication for crypto exchange account setup with app not SMS
At 2:47 AM on a Tuesday, an attacker called T-Mobile. They convinced a customer service rep to swap the SIM on an account to a phone they controlled. By 3:02 AM the victim’s texts were routed to the attacker’s device. By 3:08 AM the attacker had reset the password on the victim’s Coinbase account using the SMS code sent to that phone. By 3:19 AM they had drained the account. This is not a hypothetical; this is the mechanism a SIM swap attack uses. App-based two-factor authentication (TOTP) stops that sequence at step one.
Here is how to set it up on Coinbase before you deposit a dollar.
Installing the authenticator app
You need an app that generates time-based one-time passwords. Google Authenticator is free and works offline. Authy is free and syncs across devices but has tradeoffs covered below. Download one before you do anything else.
Open Coinbase on your phone or desktop. Go to Settings (the gear icon), tap Security, find Two-factor authentication, and select Authenticator app.
Coinbase will show a QR code. Open your authenticator app, select the option to add a new account (usually a + icon), and scan that QR code. The app will immediately display a six-digit number that changes every 30 seconds.
Type that number into Coinbase. This step is fast. The next step takes ten seconds longer and matters more.
The backup code screen most users skip
After you enter the TOTP code, Coinbase displays a list of ten backup codes. They look like random letters and numbers. Copy them. Put them someplace that is not your phone: a handwritten note in your wallet, a password manager you trust, a fireproof safe.
These backup codes are your only way back in if you lose the phone with your authenticator app. Without them, you will need to go through identity verification with Coinbase support, which can take days, and in those days your assets sit unreachable.
Do not store the backup codes in your phone’s notes app. That defeats the purpose.
App TOTP vs YubiKey: what changes
A YubiKey is a hardware token that plugs into your device or taps via NFC. It does not display a code. You touch it, and the computer reads it. No one can phish that credential remotely because the YubiKey never outputs a code that can be typed into a fake website.
App-based TOTP is still phishable. If you type a code into a lookalike Coinbase page, the attacker can use that code immediately. A YubiKey using FIDO2 protocol cannot be relayed that way.
For most people starting out, TOTP is a massive improvement over SMS and it is free. A YubiKey costs $25 to $55. The difference matters once you hold an amount you would be angry to lose.
The Authy phone number problem
Authy offers cloud backup of your TOTP secrets. This is convenient if you switch phones. It is also a risk.
Authy ties its backup to your phone number. That phone number gets a recovery code via SMS. If an attacker SIM-swaps that phone number, they can request the Authy recovery code, receive it on the swapped SIM, restore your Authy secrets to their own device, and now they have all your TOTP codes.
This defeats the entire purpose of moving off SMS. Google Authenticator does not have this cloud recovery. You are responsible for the backup codes you wrote down.
The practical sequence
- Download Google Authenticator or Authy.
- On Coinbase, enable Authenticator app 2FA.
- Scan the QR code.
- Enter the six-digit code shown.
- Copy the ten backup codes to paper.
- Store that paper separately from your phone.
That is it. Should take four minutes. The SIM swap attack requires the attacker to get your phone number first; app-based TOTP means that phone number gives them nothing. The backup code paper is the part most people skip. Do not skip it.
Not financial advice. babybtc.xyz publishes market data and general information about Baby BitCoin. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.