Two-factor authentication
Two-factor authentication, usually shortened to 2FA, adds a second step after the password at login: a code from an authenticator app, an SMS, or a message to your email. Where a platform offers it, it is the strongest single control available on an account that holds a token balance or a stored payment method.
Where you see it
It lives in account or security settings, often named "two-step verification" rather than 2FA. Once switched on, it shows up as a code prompt after the password whenever you sign in from a new device.
Why it matters
2FA closes the most common takeover route, where a password leaked from an unrelated service is replayed against your account. The trade-off is recovery: lose the phone or the authenticator app with no backup codes saved, and the same barrier that stops an attacker also stops you. SMS codes have a second cost - they attach a working phone number to the account, which is a detail some readers would rather not hand an adult platform.