If someone gets your password — through phishing, or because you reused it on another site that got breached — right now they could walk straight into your account and your balance. Two-factor authentication adds one more barrier: even with your password, they'd also need a code only you can generate.
How it works
You turn on 2FA from Account Settings → Security. You'll scan a QR code with an authenticator app (Google Authenticator, Authy, or whichever you use) and confirm with the 6-digit code it shows you. From then on, every time you log in, we'll ask for that code in addition to your password.
Save your backup codes
When you turn it on, we give you 8 single-use backup codes. They're for the day you lose your phone or switch devices and don't have the app handy — without them, and without the device, you'd be locked out of your account. Keep them somewhere safe, off your phone.
If you want to turn it off
To turn off 2FA we ask for your current password and a valid code (from the app or a backup one) — your password alone isn't enough, because otherwise anyone who got hold of it could disable the protection without any extra step.