BloFin has significant infrastructure in place to protect user assets at the platform level: custody, encryption, and transaction monitoring. But account-level security is something only you can control. The most common way traders lose funds isn't through exchange hacks. It's through compromised accounts, phishing emails, and fake platforms. This guide covers what you need to do on your end to make sure your account stays yours.
Set up two-factor authentication
Two-factor authentication (2FA) is the single most effective thing you can do to secure your BloFin account. Even if someone gets hold of your password, they still can't log in or withdraw without the second factor.
BloFin uses Google Authenticator for 2FA. Once it's set up, every login and withdrawal requires a six-digit code that refreshes every 30 seconds from the app on your device. The code is time-based and tied to your device, so it can't be intercepted remotely.
How to set up Google Authenticator on BloFin
Step 1: Download the Google Authenticator app on your phone from the Apple App Store or Google Play Store.
Step 2: Log in to your BloFin account and hover over the avatar icon on the top right corner of the page. Then, click Account & Security.
Step 3: Under the Google Authenticator option, click Link.
Step 4: A popup window will appear showing your backup key and a QR code.
To set it up, open the Google Authenticator app on your phone and tap on the + icon at the bottom right corner of the screen.
Step 5: You may choose to either Enter a setup key or Scan a QR code. Choosing the former will require you to copy the backup key provided and manually enter it in the setup key field. Choosing the latter will require you to simply scan the QR code on your computer screen.
Be sure to also write down or securely save your backup key because this is what you'll need to recover your account if you ever lose your phone. Once done, click I have saved the backup key properly.
Step 6: Once your BloFin account appears in the app, enter the six-digit code it shows along with your email verification code into your browser.
Step 7: Click Submit and your Google Authenticator is now linked.
One additional tip: disable the Cloud Sync feature in the Google Authenticator app after setup. Cloud sync can create a vulnerability if your Google account is compromised.
Consider using Passkeys
Passkeys are a more recent option and arguably the most secure way to protect your BloFin account. They use FIDO authentication, the same standard used by major tech companies, which means you log in using your device's biometrics (fingerprint or Face ID) or a hardware security key. No password, no code to type.
The security advantage is significant. Passkeys are phishing-resistant by design. Even if someone sends you a convincing fake BloFin login page, your passkey won't work on it. It's tied cryptographically to the real BloFin domain, so it simply won't authenticate anywhere else.
Before setting up a Passkey, make sure you already have at least two of the following linked to your account: mobile number, email address, or Google Authenticator.
How to set up Passkey on BloFin
Step 1: Log in to your BloFin account and hover over the avatar icon on the top right corner of the page. Then, click Account & Security.
Step 2: Under the Passkey option, click Manage.
Step 3: A popup window will appear. Click Add Passkeys.
Step 4: Enter verification codes sent to your email address and phone, as well as the six-digit verification code on your Google Authenticator app. Then, click Submit.
Step 5: Once authenticated, click Create with this device and you may choose how you want to create your passkey:
Create with this device: Click Continue. Your browser or operating system will prompt you to choose how to save the passkey. Depending on your setup, you may see options including your Chrome profile, Google Password Manager, or iCloud Keychain. Select whichever you use, then complete the biometric authentication or PIN on your device.
Use a different phone, tablet, or security key: Either scan the QR code using your phone or tablet's native QR code scanner and complete authentication on that device, or insert a USB security key and follow the on-screen instructions.
Step 6: Once created, you can rename your passkey by clicking the edit icon next to it.
Set your anti-phishing code
BloFin's anti-phishing code is a short personal phrase or code that gets added to every official email BloFin sends you. If an email doesn't contain your code, it's not from BloFin. Simple as that.
It takes a couple of minutes to set up and makes fake BloFin emails immediately obvious. Given how many phishing attempts impersonate exchanges via email, this is one of the first things worth doing after you create your account.
How to set up anti-phishing code on BloFin
Step 1: Log in to your BloFin account and hover over the avatar icon on the top right corner of the page. Then, click Account & Security.
Step 2: Under the Anti-Phishing Code section, click Set Up.
Step 3: Enter a code or phrase of your choice. Make it something you'll recognize but that others wouldn't guess. Then, enter verification codes sent to your email address and phone, as well as the six-digit verification code on your Google Authenticator app.
Step 4: Click Submit. Your code is now active and will appear in all official BloFin emails going forward.
Use a strong, unique password
Your BloFin password should be used nowhere else. If you reuse passwords across platforms and one of those platforms gets breached, attackers will try the same credentials on crypto exchanges. It's a common tactic called credential stuffing, and it works precisely because most people reuse passwords.
A strong password is long, random, and doesn't include personal information. Using a password manager to generate and store it means you only need to remember one master password rather than dozens.
Know what fake BloFin platforms look like
BloFin has issued warnings about fake platforms designed to look like BloFin and trick users into depositing funds. Known fraudulent domains have included blofin.lol, blofintyu.top, blofincoin.com, blofinsign.com, and blofin-ai.com. These sites replicate BloFin's interface to look convincing.
BloFin's only official website is https://blofin.com. The easiest way to avoid fake sites is to type the URL directly into your browser every time rather than clicking links from emails, messages, or search ads. You may also bookmark the official page for ease of reference.
What BloFin will never ask for
Knowing what legitimate support looks like is just as important as knowing what to avoid. BloFin will never:
Ask for your password
Ask for your Google Authenticator code
Ask for your private keys or seed phrases
Contact you asking you to send funds to verify an account or claim a reward
If you receive a message asking for any of the above, whether through email, Telegram, social media, or any other channel, it's a scam.
If you think your account has been compromised
Act quickly. Change your password immediately, then revoke your Google Authenticator and set it up again on a clean device. Check your account history for any withdrawals or activity you don't recognize, and contact BloFin support directly through the official site, not through any link you've been sent.
If funds have been moved, contact support as soon as possible. The faster you act, the better the chance of any recovery options being available.
Frequently asked questions
What's the difference between Google Authenticator and Passkeys?
Google Authenticator generates a six-digit code every 30 seconds that you type in when logging in or withdrawing. Passkeys use your device's biometrics (fingerprint or Face ID) and don't require typing anything. Both are significantly more secure than SMS, but Passkeys are generally considered the stronger option because they're phishing-resistant by design.
Do I need both 2FA and Passkeys?
You don't need both at the same time. They're alternative methods. Most users set up Google Authenticator first since it's familiar, and some add Passkeys later for a more seamless login experience. Having at least one active is what matters.
What should I do if I lose my phone with Google Authenticator on it?
Use your backup key, which is the code you received when you first set up Google Authenticator. If you stored it safely, you can restore your 2FA on a new device. If you didn't save it, you'll need to go through BloFin's account recovery process by contacting support.
How do I know if an email is genuinely from BloFin?
Check for your anti-phishing code. Every official BloFin email will contain the code you set up. If it's not there, don't click anything in the email and don't respond to it.
Can I recover funds if I've been scammed?
It depends on the circumstances and how quickly you act. If you've interacted with a fake platform or sent funds to an unknown address, contact BloFin support immediately through blofin.com. Blockchain transactions are generally irreversible once confirmed, but BloFin support can advise on what options are available.
Researched and written by the BloFin Academy editorial team with AI-assisted drafting. All technical claims independently verified against published standards.
Disclaimer: This content is for educational purposes only and does not constitute financial, investment, legal, or tax advice. Crypto assets are highly volatile and carry significant risk of loss. Always verify local regulations and consult a qualified professional before making financial decisions.
