rvz 4 years ago

> - All of my accounts _except_ coinbase are secured with an auth app vs. SMS 2FA, so they couldn't gain email access without my physical phone.

I thought lessons have been learned here, since the SIM swapping attacks and phone number social engineering attacks (phone numbers obtained via data breaches). [0]

Not only you should not be storing the majority of your cryptocurrencies on any exchange, the worst part is why are services still providing SMS 2FA for user funds such as cryptocurrencies or even logins for bank accounts?

This user should consider themselves lucky. Had their coins been stolen on Coinbase, that would be the end of the story and those coins would have been totally lost forever.

Not your keys, not your coins.

[0] https://news.ycombinator.com/item?id=27447430