Security
Two-factor authentication
Setting it up, storing backup codes, and what to do when you lose the device.
Two-factor authentication protects the account against a stolen password. It is required to withdraw, and we recommend turning it on before your first deposit.
Setting it up
Use an authenticator application on a device you control — the codes are generated on the device and never travel over the network. Scan the QR code, then enter a code to prove the clock and the secret agree. Only after that is it switched on.
Backup codes
You are shown a set of single-use backup codes exactly once. Each works for one sign-in. Write them down and keep them somewhere that is not the phone holding the authenticator — a copy in the same place as the device protects you against nothing. Screenshots stored in a cloud gallery are not a safe place.
Step-up
Some actions ask for a code again even though you are already signed in: withdrawing, changing security settings, disabling two-factor. That is deliberate. A session left open on a shared computer should not be enough to move money.
If you lose the device
Use a backup code to sign in, then disable and re-enrol with the new device. If both the device and the codes are gone, contact support: recovery requires identity verification, it is deliberately slow, and it cannot be rushed by asking louder. That slowness is the same wall that stops someone else claiming to be you.
What we will never do
We will never ask for your password, a two-factor code or a recovery phrase — not by email, not on the phone, not in a support ticket. Anyone who does is not us.