People ask for “2FA on my crypto wallet” because bank apps trained that habit. In non-custodial wallets, the model is different: the seed phrase is still the master key.
Quick answer
For a non-custodial wallet like My Wallet, your seed phrase is the primary secret. App password / passcode, biometrics, and auto-lock add a second barrier on the device—useful, but not the same as exchange SMS or authenticator 2FA that protects a hosted login. If someone has your seed, device 2FA will not stop them from restoring the wallet elsewhere. Official support never asks for your seed.
Custodial 2FA vs non-custodial reality
| Model | What “2FA” usually means | If you lose device access |
|---|---|---|
| Custodial exchange / app | Password + SMS / authenticator / email | Provider account recovery (with their rules) |
| Non-custodial wallet | Seed (and/or hardware key) + optional app locks | Seed / hardware recovery—provider cannot reset keys |
Exchanges add 2FA because they hold assets behind an account. Non-custodial wallets put you behind cryptographic keys. That is why seed hygiene outranks SMS codes.
What My Wallet offers instead of classic 2FA
Device-side protections:
- Password / passcode for wallet access and confirmations
- Biometric authentication (Face ID / fingerprint) to confirm operations
- App lock / auto-lock after inactivity
- Remember Passcode convenience (when biometrics are disabled)—understand the trade-off before enabling
These features stop casual access if someone picks up your unlocked phone. They do not:
- Move custody to My Wallet servers
- Let support “turn on 2FA” by asking for your seed
- Replace an offline seed backup
Change-password and forgot-password flows ultimately lean on knowing the current password or re-importing with the seed.
What 2FA does not mean here
- SMS codes are not a seed substitute. SIM-swap attacks already plague exchange accounts; they are the wrong mental model for self-custody.
- Authenticator apps on the same phone as the wallet are still “something on one device,” not a second key holder.
- Hardware keys / multisig are closer to true second factors for spending—but they are separate designs. See What Is Multisig? and Hardware wallet integration explained.
Practical setup checklist
- Create or import My Wallet from official links only.
- Back up the seed offline before depositing size.
- Set a strong app password; enable biometrics if you trust the device.
- Turn on auto-lock.
- Treat every unexpected signature request as hostile until proven otherwise.
- For larger savings, consider a hot/cold split—not “more SMS codes.”
Security basics: Crypto Wallet Security Basics.
If you came from an exchange
Moving from custodial 2FA to self-custody feels like losing a safety net. You are trading provider recovery for key ownership. That is the point of non-custodial wallets—and why fake “support 2FA reset” chats are so dangerous.
Download My Wallet
Download My Wallet to enable device locks; still guard the seed—you hold the keys.
FAQ
Does My Wallet support Google Authenticator 2FA?
My Wallet’s security model centers on password, biometrics, and auto-lock for the app—not exchange-style authenticator 2FA for server-side custody. The seed remains primary for recovery.
If I enable Face ID, am I safe if my seed leaks?
No. Anyone with the seed can restore the wallet on another device. Rotate to a new wallet if a seed may be exposed.
Is SMS 2FA good enough for crypto?
On custodial accounts it can help against password reuse—and still fails to SIM swaps. For non-custodial wallets, prioritize seed and download hygiene over SMS theater.
Helpful My Wallet guides
- What security settings does My Wallet offer?
- How to secure My Wallet
- How can I change my password?
- Remember Passcode
- What is a seed phrase? How to store a seed phrase?
