6 min read

Enabling Two-Factor Authentication (2FA)

How to add a second layer of security to your Pilotbot login using a TOTP authenticator app, and what to do if you lose access.

P

Pilotbot Team

Author

On this page

In the world of high-frequency P2P trading and arbitrage, account compromise means an immediate standstill for your entire business. If an unauthorized third party gains access to your dashboard, active arbitrage pairs, order book ad controls, and session security are placed under threat. In this environment, a classic password alone can no longer be considered a reliable shield.

Two-factor authentication (2FA) turns any leaked or compromised password into a useless string of characters. Even with your password in hand, an attacker cannot enter the system without physical access to your personal device and the one-time 6-digit code refreshed every 30 seconds.

Enabling 2FA is not a formality; it is essential body armor for your Pilotbot trading profile.


TOTP Architecture: Mathematics Guarding Your Orders

Pilotbot uses the globally recognized industry standard TOTP (Time-based One-Time Password) governed by the RFC 6238 specification.

Unlike outdated and vulnerable SMS codes, which are easily intercepted via SIM card duplicates (SIM swapping) or mobile carrier protocol vulnerabilities, TOTP ensures uncompromising autonomy:

  • Complete Network Isolation: Your authenticator app never sends or receives internet requests. Codes are calculated locally by your smartphone's cryptographic engine using a secret seed and the current Unix timestamp.
  • Dynamic 30-Second Cycle: Every thirty seconds, the HMAC-SHA1 algorithm computes a new one-time password. Once time expires, the old code is permanently invalidated.
  • Immunity to Delayed Attacks: Even if an attacker peeks at your code over your shoulder or intercepts it in the clipboard, they only have seconds before the code expires.

Security Center: Your Perimeter Under Complete Control

Pilotbot's Security Center is designed so you can immediately inspect the live security posture of your account and react to any environmental changes in real time.

All protection layers converge here: two-factor authentication status, registered biometric Passkeys, active session history, and encryption parameters for connected exchange accounts (Binance, Bybit, OKX, HTX, Bitget).


Defense Line Comparison: Why TOTP Beats Passwords and SMS

Security MethodInterception ResistanceCellular IndependenceLogin SpeedSIM-Swap Risk
Standard PasswordZero (infostealers, phishing, leaks)Full10–20 secNone
SMS ConfirmationLow (carrier interception, SIM clones)Dependent on cell network and roaming20–60 secCritical
TOTP (Google Auth, 2FAS)High (local cryptographic execution on chip)100% offline (works without internet)5–10 secZero
Passkey (FIDO2 / Touch ID)Maximum (hardware-backed cryptography)100% autonomous at OS levelLess than 1 secZero

Step-by-Step Guide: Enabling 2FA in 4 Steps

Step 1. Navigate to Security Settings

  1. Sign in to your Pilotbot account.
  2. In the top profile menu, open Security Settings.
  3. Locate the Two-Factor Authentication (TOTP) section and click Connect.
  4. A unique QR code and plaintext secret key will appear on screen.

Step 2. Select an Authenticator App

If you do not already have an app for generating codes, choose any proven solution:

  • Google Authenticator (iOS / Android) — classic reliable tool with optional Google account sync.
  • Apple Passwords / iCloud Keychain (iOS / macOS) — native TOTP code support in the Apple ecosystem with autofill.
  • 2FAS Authenticator (iOS / Android) — independent open-source app with encrypted cloud backup.
  • 1Password / Bitwarden — industry-leading password managers with integrated TOTP generators.

Step 3. Scan the QR Code and Back Up the Secret Key

  1. Open your authenticator app on your smartphone.
  2. Tap the button to add a new account (typically a "+" icon or "Scan QR code").
  3. Point your camera at the QR code displayed in Pilotbot. An entry named Pilotbot will appear instantly.
  4. Be sure to save the backup key: Beneath the QR code, Pilotbot displays a 32-character alphanumeric key. Copy and store it in a secure offline location.

Step 4. Confirm and Activate Protection

  1. Check the 6-digit code displayed in the app next to the Pilotbot entry.
  2. Enter this code into the confirmation field in Pilotbot.
  3. Click Confirm and Activate.

Once the system validates the code, two-factor authentication is immediately active. For all future sign-ins, after entering your password, you will be prompted for a fresh code from your app.


Emergency Situations: What to Do If You Lose Your 2FA Phone

If your phone is damaged, lost, or the app was deleted without a backup:

  1. If you saved the 32-character secret key: Simply open your authenticator on a new phone, select manual key entry, paste the saved string, and code generation resumes.
  2. If the backup key is lost: Use the official security check reset procedure. For safety reasons, instant one-click 2FA disabling in the UI is blocked so attackers cannot turn off protection.

Follow the detailed step-by-step verification instructions in How to Regain Access After Losing a Security Verification.


Next Evolution Step: Passkeys

Want to sign in to Pilotbot without typing passwords or copying 6-digit codes at all?

Pilotbot supports Passkeys (FIDO2 / WebAuthn) — the revolutionary biometric sign-in method using your fingerprint (Touch ID) or facial recognition (Face ID / Windows Hello). It is faster, more convenient, and completely eliminates phishing at the browser cryptographic level.

Learn more in Passkeys — Passwordless Sign In.


Related articles

    Enabling Two-Factor Authentication (2FA)