Bitcoin Forum
October 20, 2025, 06:49:32 PM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: 2FA on a bitcoin wallet  (Read 99 times)
PostQuantumBTC (OP)
Newbie
*
Offline Offline

Activity: 28
Merit: 7


View Profile
October 07, 2025, 03:19:40 PM
 #1

I have only been using the TOTP that are six in number until I saw Cake wallet. The wallet has 8 TOTP which is 2 numbers more than the others that I have seen before.

If you want to proceed to enable the 2FA on the wallet, it will let you read that hackers may be able to know the TOTP which the authenticator is producing every 30 seconds, just to make sure that you protect your wallet very well, but its own is 8 numbers and it still give this warning.

If you have your 2FA on another device, also if the device the 2FA is always offline, is it true that hackers can still be able to know the 2FA? I think Cake is only referring to online 2FA. Can hackers be able to know the offline 2FA OTP?

The second question is that is 8 number TOTP more secure than 6 numbers?

I know that online wallets are not safe like offline wallets.
Cookdata
Legendary
*
Online Online

Activity: 1470
Merit: 1110


Not Your Keys, Not Your Bitcoin


View Profile
October 07, 2025, 04:02:01 PM
 #2

I have only been using the TOTP that are six in number until I saw Cake wallet. The wallet has 8 TOTP which is 2 numbers more than the others that I have seen before.

You know one thing about Authenticators, they change every 30 seconds. Even with 4 combinations of code, if the hacker doesn't have access to your secret key, it will be very difficult to guess 4 combinations under 30 seconds  unless maybe the hacker was able to tampered with the device where you kept the Authenticator.

Quote
If you want to proceed to enable the 2FA on the wallet, it will let you read that hackers may be able to know the TOTP which the authenticator is producing every 30 seconds, just to make sure that you protect your wallet very well, but its own is 8 numbers and it still give this warning.

This warning is normal in every security alerts. I'm not sure if you have tried to back up recovery phrase on your phone and you try to take a screenshot of the image, it stops you and give you warning. I have seen that in couple of software wallets I have tried to backup, that's just normal warning you getting.

Quote
If you have your 2FA on another device, also if the device the 2FA is always offline, is it true that hackers can still be able to know the 2FA? I think Cake is only referring to online 2FA. Can hackers be able to know the offline 2FA OTP?

The second question is that is 8 number TOTP more secure than 6 numbers?

I know that online wallets are not safe like offline wallets.

2FA doesn't need internet to work, they need just your phone to function to generate the digit number. So it's not possible for a hacker to have access to your secret key but some Authenticators encrypt your the password used to encrypt your backup on their server which you can access through login. Authy for example, with your mobile number and password even if you loss the phone where the authenticator is installed, you can retrieve it back again, they do say it's safe but who knows if there is a backdoor, if an hacker get hold of that, then game over.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀
 
..PLAY NOW..
dkbit98
Legendary
*
Offline Offline

Activity: 2758
Merit: 8261


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
October 07, 2025, 05:40:01 PM
 #3

I have only been using the TOTP that are six in number until I saw Cake wallet. The wallet has 8 TOTP which is 2 numbers more than the others that I have seen before.
I am using Cake wallet but I never saw option for 2FA in settings until now.
You should be just fine with regular PIN that has 4 numbers, since Cake should be used as hot wallet only, not for large amount of coins.
If you still want to use authenticatin and 2FA than I suggest reading dedicated page about that on Cake website:
https://docs.cakewallet.com/features/advanced/authentication/

The second question is that is 8 number TOTP more secure than 6 numbers?
Yes it does because it have significantly larger number of possible combinations.
But I don't think it really makes any difference for you.

██████▄██▄███████████▄█▄
█████▄█████▄████▄▄▄█
███████████████████
████▐███████████████████
███████████▀▀▄▄▄▄███████
██▄███████▄▀███▀█▀▀█▄▄▄█
▀██████████▄█████▄▄█████▀██
██████████▄████▀██▄▀▀▀█████▄
█████████████▐█▄▀▄███▀██▄
███████▄▄▄███▌▌█▄▀▀███████▄
▀▀▀███████████▌██▀▀▀▀▀█▄▄▄████▀
███████▀▀██████▄▄██▄▄▄▄███▀▀
████████████▀▀▀██████████
 BETFURY ....█████████████
███████████████
███████████████
██▀▀▀▀█▀▀▄░▄███
█▄░░░░░██▌▐████
█████▌▐██▌▐████
███▀▀░▀█▀░░▀███
██░▄▀░█░▄▀░░░██
██░░░░█░░░░░░██
███▄░░▄█▄░░▄███
███████████████
███████████████
░░█████████████
█████████████
███████████████
███████████████
██▀▄▄▄▄▄▄▄▄████
██░█▀░░░░░░░▀██
██░█░▀░▄░▄░░░██
██░█░░█████░░██
██░█░░▀███▀░░██
██░█░░░░▀░░▄░██
████▄░░░░░░░▄██
███████████████
███████████████
░░█████████████
Charles-Tim
Legendary
*
Offline Offline

Activity: 2072
Merit: 5965


Leading Crypto Sports Betting & Casino Platform


View Profile
October 07, 2025, 07:41:57 PM
 #4

I am using Cake wallet but I never saw option for 2FA in settings until now.
You should be just fine with regular PIN that has 4 numbers, since Cake should be used as hot wallet only, not for large amount of coins.
To set up 2FA on Cake wallet, no addictional cost and it is very easy to setup. I do not also recommend having high amount of money on such wallet but if 2FA can be used for making transactions on the wallet, it is not bad at all. Even if only small amount of money will be stored on it, not bad to use the 2FA if he knows that the device the 2FA is will be readily available if he wants to make transaction on the wallet.

If you want to see the seed phrase on the wallet but 2FA is enabled, the wallet will ask for password and the 2FA OTP before the seed phrase can be seen. Which means if someone around you know the wallet password, he can not access your seed phrase and he will also not be able to spend your coins.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Hatchy
Hero Member
*****
Offline Offline

Activity: 938
Merit: 988


Hatchy managerial services


View Profile WWW
October 07, 2025, 08:13:15 PM
 #5

I am using Cake wallet but I never saw option for 2FA in settings until now.
You should be just fine with regular PIN that has 4 numbers, since Cake should be used as hot wallet only, not for large amount of coins.
To set up 2FA on Cake wallet, no addictional cost and it is very easy to setup. I do not also recommend having high amount of money on such wallet but if 2FA can be used for making transactions on the wallet, it is not bad at all. Even if only small amount of money will be stored on it, not bad to use the 2FA if he knows that the device the 2FA is will be readily available if he wants to make transaction on the wallet.

If you want to see the seed phrase on the wallet but 2FA is enabled, the wallet will ask for password and the 2FA OTP before the seed phrase can be seen. Which means if someone around you know the wallet password, he can not access your seed phrase and he will also not be able to spend your coins.
He probably didn't know of the 2FA on cake wallet because he had no use of it. I've come across it several times but I don't usually see the use of setting up a 2FA on my wallet, when I can just save my seedphrase instead. For me cake wallet is just a mean for me to avoid those centralized exchanges high conversion fee between various altcoins. I don't really store coins on it. I simply use it to swap my coins when ever it's needed.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Forsyth Jones
Legendary
*
Offline Offline

Activity: 1694
Merit: 1679


I love Bitcoin!


View Profile WWW
October 07, 2025, 08:39:57 PM
 #6

If you want to proceed to enable the 2FA on the wallet, it will let you read that hackers may be able to know the TOTP which the authenticator is producing every 30 seconds, just to make sure that you protect your wallet very well, but its own is 8 numbers and it still give this warning.

If you have your 2FA on another device, also if the device the 2FA is always offline, is it true that hackers can still be able to know the 2FA? I think Cake is only referring to online 2FA. Can hackers be able to know the offline 2FA OTP?
I've never used Cake Wallet and I also didn't know it was possible to enable TOTP 2FA.

In summary, this warning is just to alert you that a hacker or malicious app could intercept your TOTP code. This possibility arises from the fact that you store the TOTP key backup on the same device. An account/app with TOTP 2FA only makes sense if you set up TOTP 2FA on another device, as this is essentially the second factor of authentication.

Think with me, whenever you enable TOTP 2FA on an account or app, a QR code or a set of hexadecimal characters is displayed. This is your TOTP key backup. In other words, if someone has access to this backup key, they can use it to restore it on any device and generate the same 6 or 8-digit codes that appear on the registered 2FA device.

It's recommended that you have a second device, mobile or desktop, to store your 2FA backup keys, and in this case, there are several applications recommended for this, avoid Google Authenticator, the Keepass password manager can be used to save your 2FA codes and passwords securely.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!