
How Roobet's 2FA setup works
Roobet's current 2FA guide directs users to the Account Security page, where the two-factor setting can be enabled. The setup displays a QR code and a secret recovery key for an authenticator app. The user then enters the current code to confirm setup.
- Sign in by typing the official Roobet domain yourself.
- Open Account Security and start the two-factor setup.
- Scan the QR code or enter the setup key in a trusted authenticator.
- Store the recovery secret offline before completing setup.
- Enter the current authenticator code and confirm that 2FA is enabled.
Roobet says a new code is generated roughly every 30 seconds. Repeated failures can come from incorrect device time, the wrong authenticator entry or an old code. Do not disable 2FA simply because one code expired.
The recovery path deserves the same protection
An attacker who controls the account email may be able to trigger password recovery. Use a unique email password and enable the email provider's own 2FA. Do not store the Roobet password, email password and authenticator recovery secret in the same unprotected note.
The 2FA recovery key is sensitive. Roobet's guide warns that it can be used to remove 2FA. Never paste it into a support chat, social message or screenshot.
Use the official password-reset flow
The current reset guide says to choose Reset Password on the Roobet login page, enter the verified account email, then use the emailed recovery code in the reset screen. Open the message in another tab or device so the original reset flow remains active.
If a reset email arrives without your request, do not follow links in it. Open the official site separately, change both the Roobet and email passwords, review account activity and contact official support.
A 60-second phishing check
- Read the full domain, not just the page title or logo.
- Do not trust a search ad or social profile by appearance alone.
- Reject requests for a password, 2FA code, recovery key or wallet seed phrase.
- Do not install remote-access software for "support."
- Do not pay a fee to unlock a withdrawal or verification review.
- Start support from the signed-in account menu.
What to do after suspicious access
- Use a clean device and change the email password first.
- Reset the Roobet password from the official domain.
- Revoke unknown email and account sessions when controls are available.
- Reconfigure 2FA if the secret may have been exposed.
- Contact official live support with timestamps and transaction IDs.
- Contact the relevant wallet or exchange immediately if crypto was sent.
Preserve evidence before deleting messages. Screenshots, email headers, destination addresses and transaction hashes can help support or an exchange investigate.
Roobet security and wallet security are separate
Roobet account 2FA does not protect a self-custody wallet whose seed phrase has been exposed. Check the network and destination on every deposit and withdrawal. Roobet currently warns that gasless wallet infrastructure is not supported, which can create processing problems for affected deposits.