exchanges

Two-Factor Options at Venues Compared

Which authentication methods each platform supports, and why the weakest one is frequently the default.

C
Chris DelaneyJuly 17, 2026 · 2 min read

Account security is the part of a venue review that determines whether a password leak is an inconvenience or a total loss.

What we check

SMS. Still offered widely, frequently as the default. Defeated by a phone call to a mobile carrier, which is a documented and repeated attack.

Authenticator application. Codes generated on your device. Defeats SIM swapping entirely. This is the minimum acceptable option and it is off by default everywhere we have looked.

Hardware security key. A physical device. Defeats phishing as well, because it verifies the site before responding. The only method that does.

Passkeys. Increasingly supported, functionally similar to a hardware key, bound to a device.

The setting that gets missed

Whether the phone number can be removed as a recovery option.

A stronger second factor is undermined entirely by a weaker fallback on the same account. Several platforms require a phone number and do not allow removal, which caps how secure the account can be made.

We check this specifically, because it is invisible unless you look and it determines the ceiling.

The adjacent features

Withdrawal address allowlist, with a delay before new addresses become usable. This converts a successful takeover from an instant theft into a window.

It is the single most effective setting available and almost nobody enables it.

Session management, so old logins can be revoked.

API key permissions, with read-only, trading and withdrawal as separate grants, ideally with IP restriction.

Notifications on login, authentication change and withdrawal.

What the options tell you about a platform

A venue offering only SMS has made a decision about how much it invests in customer security.

A venue offering hardware keys, allowlists with delays and granular API permissions has made a different one, and those features are documented rather than advertised. Platforms publishing their full security model, including a platform we ran a full withdrawal through, let you check before opening an account.

The configuration we recommend

Authenticator application at minimum, hardware key where supported. Backup codes written down. Phone number removed as recovery where possible. Carrier port-out PIN set. Allowlist enabled with a delay. Notifications on. API keys reviewed.

Ten minutes, once. It closes the routes through which nearly every account compromise actually happens.

How this review was done

Products covered here are bought at full retail price and used for real transactions before anything is written. There are no affiliate links on this site, no sponsored placements and no review units. If that ever changes, it will be disclosed at the top of the article.