Two-factor authentication (2FA) adds a second layer of security to your Duelbits account. With 2FA enabled, logging in requires both your password and a time-based 6-digit code from an authenticator app on your phone. Even if someone obtains your password, they cannot access your account without your device.
Enabling 2FA is the single most important step you can take to protect your account. Duelbits will never ask you to disable it, anyone who does is not from Duelbits.
📱 Compatible Authenticator Apps
Duelbits uses app-based 2FA only, SMS/text message authentication is not supported. You will need one of the following authenticator apps installed on your phone:
Google Authenticator: available on iOS and Android
Authy: available on iOS, Android, and desktop (supports cloud backup and multi-device sync)
Microsoft Authenticator: available on iOS and Android
1Password: available on iOS, Android, Mac, Windows (built-in authenticator alongside password manager)
Any TOTP-compatible authenticator app will work. If you already use one not listed above, it will work the same way.
Recommendation: Authy or 1Password are the safest choices because they support cloud backup of your 2FA keys. If you lose your phone, you can restore access from another device. Google Authenticator does not back up by default, if your phone is lost or reset, your 2FA codes are gone unless you manually backed up the setup key.
🔧 How to Enable 2FA
Log in to your Duelbits account.
Click your profile icon in the top-right corner.
Go to Security.
Under Two Factor, you will see two steps:
Step 1: Scan the QR Code
Open your authenticator app, tap the option to add a new account, and scan the QR code displayed on screen using your device's camera.
If you cannot scan the QR code (e.g., you are setting up 2FA on the same device), click "Copy code instead" to reveal a text key. Enter this key manually into your authenticator app.
Step 2: Verify Authentication Code
After scanning the QR code or entering the manual key, your authenticator app will begin generating 6-digit codes that refresh every 30 seconds. Enter the current code into the verification field on Duelbits.
Click Enable Two Factor
2FA is now active on your account. Every future login will require both your password and the current 6-digit code from your authenticator app.
🔑 Save Your Setup Key
When you set up 2FA, you have the option to click "Copy code instead" to reveal the text key behind the QR code. Save this key somewhere secure, written down offline, in a password manager, or in an encrypted note.
If you lose access to your authenticator app (phone lost, broken, or reset), this setup key is the fastest way to restore your 2FA. You can enter it into a new authenticator app on a different device and immediately generate valid codes again, without needing to contact support.
Duelbits does not provide separate backup codes. The setup key shown during initial configuration is your only self-service recovery option. Once you leave the setup screen, the key is no longer displayed.
✅ Test Before Relying on It
After enabling 2FA, test it immediately:
Log out of Duelbits.
Log back in with your username and password.
When prompted for the 6-digit code, open your authenticator app and enter the current code.
If you can log in successfully, 2FA is working correctly.
Do this before closing the setup screen, if something went wrong during configuration (wrong key scanned, time sync issue), you can fix it while you still have access.
🔒 What 2FA Protects Against
With 2FA enabled:
Stolen passwords: even if your password is compromised through a data breach on another site, phishing, or keylogging, the attacker cannot log in without the 6-digit code from your phone
Credential stuffing: automated attacks that try leaked email/password combinations across multiple platforms will fail at the 2FA step
Unauthorised account access: no one can access your account without physically having your authenticator device
Without 2FA, your account is protected by your password alone. Given that Duelbits handles cryptocurrency balances, this is not sufficient, enable 2FA immediately.
📵 What to Do If You Lose Access to Your Authenticator
If your phone is lost, broken, stolen, or reset and you no longer have access to your authenticator app:
If you saved your setup key:
Install your authenticator app on a new device.
Add a new account and enter the saved setup key manually.
The app will generate valid 6-digit codes and you can log in normally.
If you did not save your setup key:
Contact Duelbits support at [email protected].
Explain that you have lost access to your authenticator and cannot generate 2FA codes.
The support team will guide you through a recovery process, which may require additional identity verification to confirm account ownership.
This is why saving the setup key during initial configuration is critical, it is the difference between a 30-second self-recovery and a potentially multi-day support process.
🚫 How to Disable 2FA
2FA cannot be disabled through the profile interface. To disable it:
Contact Duelbits support via Live Support (left-hand navigation bar) or email [email protected].
Request 2FA removal.
The support team may require additional verification to confirm you are the account owner before removing 2FA.
Disabling 2FA is not recommended. If you are disabling it to switch authenticator apps, set up the new app first (using your saved setup key) before requesting removal of the old configuration.
⚠️ Common 2FA Issues
"Invalid code" when entering the 6-digit number
Make sure you are entering the code from the correct account in your authenticator app, if you have multiple accounts saved, you may be reading the wrong one
The code refreshes every 30 seconds. If the code is about to expire, wait for the next one and enter it immediately
Check that your phone's clock is set to automatic/network time. TOTP codes are time-based, if your device clock is even slightly off, the codes will not match
QR code will not scan
Make sure your camera has permission to access the authenticator app
Ensure the QR code is fully visible on screen and your camera is in focus
Click "Copy code instead" and enter the text key manually as an alternative
Authenticator app shows no codes after setup
You may not have completed the scan. Go back to Profile → Security and re-scan the QR code
If the QR code has changed (because you navigated away and came back), it may be a new key, scan the current one
❓ Frequently Asked Questions
Does Duelbits support SMS-based 2FA?
No. Duelbits uses authenticator-app-based 2FA only. SMS is less secure because phone numbers can be hijacked through SIM swapping.
Which authenticator app should I use?
Any TOTP-compatible app works. Authy and 1Password are recommended because they support cloud backup of 2FA keys, protecting you if your phone is lost. Google Authenticator works but does not back up by default.
Can I use 2FA on multiple devices?
If you saved your setup key, you can enter it into authenticator apps on multiple devices. Both will generate valid codes simultaneously. Authy also supports multi-device sync natively.
What happens if I get a new phone?
If you saved your setup key, add it to the authenticator app on your new phone. If you use Authy with cloud backup, your keys transfer automatically. If you did not save the key and do not have cloud backup, contact support for recovery.
Can someone from Duelbits ask me to share my 2FA code?
Never. Duelbits support will never ask for your 6-digit code, and will never ask you to disable 2FA. Anyone requesting either is impersonating Duelbits.
