A password alone is not enough to protect a financial account. Two-factor authentication (2FA) requires a second, time-based code generated on your phone, so a stolen password is useless by itself.
Setting up 2FA
- Install an authenticator app: Google Authenticator, Authy or any TOTP-compatible app.
- In Palzea, open Profile → Security → Two-factor authentication.
- Scan the QR code with the app.
- Write down the backup codes and store them offline — they are the only way back in if you lose the phone.
- Enter the 6-digit code to confirm activation.
When 2FA is required
Once enabled, Palzea asks for a code at login from new devices, on every withdrawal, and when changing security settings. This means an attacker with your password still cannot move funds.
Best practices
- Prefer an authenticator app over SMS — SIM-swap attacks make SMS the weakest 2FA method.
- Never share a 2FA code with anyone, including people claiming to be Palzea staff.
- Keep backup codes on paper, not in a notes app synced to the cloud.


