Coinbase Now Requires Two Factor Authentication For Certain Actions
Coinbase now requires two-factor authentication (also known as 2FA) for certain transactions and changes to an account. The one primarily dealt with in their blog post, seen here, is sending more than $100 of Bitcoin in a day. They also list the following scenarios as requiring 2FA before the action can be completed:
- Recurring sends
- Enabling/disabling your API key
- Changing your password
- Changing phones on your account
- Changing your Google Authenticator settings
- Changing your SMS pin number
What’s interesting, although unsurprising, to note is that they do specifically mention that “Two factor verification does not apply to Coinbase access via the API key or via OAuth. So you still need to be careful with not leaking your API key and only authenticating trusted applications via OAuth.” This weakness in the system is likely to be abused more now that more the of the options for scammers are being closed with extra security. Coinbase users (myself included), should be wary for any website that asks for your API key, and if it doesn’t seem legitimate at all, leave quickly.