You can protect your account and balances with several independent security layers.
Set a PIN and biometrics
You can require a PIN every time you open the mobile app or log in to the web app. Set a PIN on the mobile app:
- Tap “Account”
- Tap “Security”
- Toggle “Enable PIN”
- Enter 4 digits
- Re-enter the same PIN to confirm
- Toggle Face ID or Touch ID on mobile devices that support if you want to skip entering the PIN
You can change your PIN anytime by entering your current one. If you forget your PIN, contact support.
Enable two-factor authentication
You can require 2FA every time you log in to the mobile or web app. Go to “Account”, then “Security”, and toggle “Enable 2FA”.
To configure a passkey or security key:
- Follow your device’s instructions or insert your security key
- Add, rename, or remove keys anytime under “Manage passkeys”
To use an authenticator app like Google Authenticator or Authy:
- Scan the QR code or paste the setup key in your authenticator app
- Enter the generated 6-digit code
- Save your recovery codes as a backup if you lose access to the authenticator app
To disable an authentication method you no longer have access to, contact support.
To protect you from account takeovers, disabling 2FA takes effect after a 5-day delay. During this period, you’ll receive notifications via email and the app, giving you time to cancel the disablement if needed. This delay also applies if you switch your 2FA method from an authenticator app to passkeys, or vice versa.
Protect sensitive actions with 2FA
You can also require two-factor authentication for updating account information and initiating sends and withdrawals:
- Tap “Account”
- Tap “Security”
- Tap “Protected actions”
- Choose “Account updates”, “Sends & withdrawals”, or both
- Set a rolling 7-day threshold, after which 2FA is required again
You can protect more actions and lower the threshold amount instantly at any time. Before removing protections or raising the threshold, you must wait 5 days, during which you’ll be notified so you can easily cancel unintended changes.
Verify your anti-phishing code
Your anti-phishing code is unique to your account and included in every email you receive from Strike after you verify your identity. It’s a simple way to confirm an email is really from Strike and not a phishing attempt. If you receive an email that appears to come from Strike but doesn’t show your code, it’s not from us.
To find your current code and see when it was last updated, go to “Account” and “Security”.
You can rotate your anti-phishing code as many times as you want, with a 24-hour interval between each rotation. We recommend rotating it periodically, and immediately if you think someone else may have seen it. Strike may also refresh your code on your behalf if we detect a security concern. Once refreshed, you’ll receive a confirmation email that won’t contain the code and, from then on, all future emails from Strike will include the new code.
Manage logged-in devices
You can log out of devices remotely at any time on the mobile or web app. Remote logouts require 2FA when it is on. The mobile app automatically logs you out if you don’t access your account for 30 days.
Hide your balance
Shaking your phone or long-pressing your bitcoin or cash balance can help you avoid the risk of shoulder surfing when using the app in public. You can disable shake to hide at any time.