How to secure your Usko account with 2FA and an anti-phishing code
Switch on two-factor authentication, save your backup codes and set an anti-phishing code so you can spot fake emails instantly.
What you need first
- A Usko account you can log in to.
- A smartphone with an authenticator app installed. Any of the common ones work — they all follow the same standard.
- Somewhere safe to write down backup codes. Paper is fine.
Two-factor authentication (2FA) means that knowing your password is not enough to get into your account. A second, constantly changing code is also required, and that code lives on your phone. It is the single most useful thing you can do to protect an exchange account.
Step 1 — Open your security settings
Select your profile icon in the top right, then Security. You will see the security options for your account, including two-factor authentication, active sessions and the anti-phishing code.
Step 2 — Start setting up two-factor authentication
Select Enable next to two-factor authentication and choose the authenticator app method. Usko shows a QR code on screen and a long text key underneath it.
Step 3 — Scan the code with your authenticator app
- Open the authenticator app on your phone.
- Choose to add a new account, then scan the QR code on your screen.
- If the camera will not scan, type the long text key in by hand instead — it does exactly the same thing.
- The app now shows a six-digit code for Usko that changes every thirty seconds.
Step 4 — Confirm the code
Type the current six-digit code from the app into Usko and confirm. If it is rejected, wait for the next code and try again — and check that the clock on your phone is set to update automatically, because these codes depend on accurate time.
Step 5 — Save your recovery information somewhere safe
When 2FA is switched on you are shown recovery information. Write it down and keep it offline — a piece of paper in a drawer is genuinely a good answer.
This matters more than people expect. If you lose your phone and have no backup, recovering access means a manual identity check with our support team, which takes time. See the 2FA questions in the FAQ for how recovery works.
Step 6 — Set an anti-phishing code
Still in Security, open Anti-phishing code and choose a short word or phrase that only you would recognise. Save it.
From then on, every genuine email from Usko contains that word. A scammer sending a fake “Usko” email does not know it, so any message without your code is a fake — no matter how convincing the logo looks.
Step 7 — Review your active sessions
The security page lists the devices currently signed in to your account. Look through it. If anything is unfamiliar, sign that session out and change your password immediately.
Habits that keep the account safe
- Usko will never ask for your password, your 2FA codes or remote access to your device. Anyone who does is a scammer.
- Reach Usko by typing the address yourself or using your own bookmark — not by clicking links in messages.
- No genuine member of staff will contact you first and ask you to move funds to a “safe” account. There is no such thing.
- Keep your email account locked down too, with its own strong password and its own 2FA. Whoever controls your email can attempt to reset everything else.