Important: Funding 2FA requires the Global Settings Lock (GSL) to be enabled to be effective.
Enabling Two-Factor Authentication (2FA) for Deposits & Withdrawals (i.e. Funding) improves your account security by preventing attackers from moving funds in or out of your account even in the event of a compromise.
Deposits 2FA requires a 2FA code for:
- Generating a new cryptocurrency deposit address (and thus preventing existing addresses from expiring)
Withdrawal 2FA requires a 2FA code for:
- Withdrawing any type of funds from your Kraken account
- Transfers to your Futures wallet (but not from your Futures Wallet)
However, Withdrawal 2FA does not prevent the addition of cryptocurrency withdrawal addresses. For that, you'll need to enable the Global Settings Lock (GSL).
Below are screenshot examples of what you would see when 2FA for Deposits & Withdrawals is enabled.
1. Adding a cryptocurrency deposit address:
2. Requesting a withdrawal:
Should I set up Deposits & Withdrawals 2FA?
Adding 2FA for Deposits & Withdrawals is an excellent choice for high value accounts and clients who prefer top-notch security for their accounts.
Clients who hold funds in their account at Kraken, but do not frequently transfer funds to or out of their account are also encouraged to enable this feature.
How do I set up Deposits & Withdrawals 2FA?
If you have not already set up a Login 2FA on your account, you will be prompted to do so first before setting up 2FA for Deposits & Withdrawals.
You can set up a Deposits & Withdrawals 2FA by logging in to your Kraken account and clicking on the “Security” tab. Next, click the "On/Off" dial under “Deposits & Withdrawals” and choose the 2FA method you want to use.
The methods are:
- Yubikey device (most secure)
- Authenticator app (moderately secure)
- Static password (least secure; not recommended)
IMPORTANT: After enabling 2FA for Deposits & Withdrawals, you must also enable the Global Settings Lock (GSL) in order for it to be effective. Without the GSL, the Deposits & Withdrawals 2FA can be easily removed or changed by anyone who gains access to the account.