Passkeys and two-factor
Passkeys first, an authenticator app as backup, and why we do not use SMS as a primary factor.
A passkey ties sign-in to your device and cannot be phished — there is no code to read out to someone pretending to be support.
Register a passkey per device you actually use. An authenticator app (TOTP) is a good backup for the day a device is lost.
We never ask for a code by phone or email, and we never ask for your password. If someone does, it is not us.
You cannot remove your last remaining factor, because that would lock you out of your own money.