Guide · Account Security

How to Secure Your Gaming Account in 2026: 2FA and Passkeys on Steam, PlayStation, Xbox, Nintendo, Epic and Riot

A wallet balance is only as safe as the login in front of it. Where two-factor authentication and passkeys live on Steam, PSN, Xbox, Nintendo, Epic and Riot — the exact settings paths, the backup codes, Steam’s trade-hold rules, and what to do if you have already been hit.

  • Six platforms, exact settings paths
  • Checked against each platform’s own support docs
  • Updated 6 August 2026
✍️ Written by Virtwave Payments Team📅 August 6, 2026🕒 Updated August 6, 202611 min read✓ Reviewed by Rayyan Omar

Every guide on this blog ends the same way: redeem the code onto the right account. This one is about the part nobody thinks about until it is too late — whether that account can be taken from you. A gaming account in 2026 is a wallet with a library attached. There is stored balance on it, often a saved payment method behind it, a decade of purchases inside it, and in the case of CS2 or Dota inventories, tradeable items that convert to money in minutes. That combination is exactly why gaming logins are worth stealing, and why every major platform has spent the last two years pushing people off passwords entirely. The good news: hardening all six of the accounts below is genuinely a ten-minute job. Here is where each setting lives, what each method is actually worth, and the two mistakes that undo all of it.

Why the account is the target, not the code

A stolen gift card code is worth its face value once. A stolen account is worth the balance on it, plus whatever the saved card will authorise, plus the inventory, plus a clean identity to run the next scam from. That is why the attack has shifted: almost nobody bothers guessing passwords any more. They get you to hand over a login on a page that looks like the real one, or they lift an already-authenticated session, or they simply reuse a password that leaked from a completely unrelated site five years ago.

This is also why buying gift cards rather than saving a card on file is quietly a security decision as much as a budgeting one. A wallet top-up caps the blast radius: if someone does get in, they can spend what is loaded, not whatever your bank will approve at 3am. We made that argument in full in our guide to gaming spending limits and parental controls, and it applies to adults just as much as to kids.

Passkey vs authenticator app vs SMS vs email

All four get called “two-factor” somewhere in a settings menu, and they are not remotely equal. The difference that matters is whether the second factor can be repeated back to an attacker by a person sitting at a convincing fake login page.

What each second factor is actually worth
MethodStops a phishing page?Works offline?Main weakness
Passkey (face, fingerprint, device PIN)Yes — it is bound to the real domain and will not fire on a lookalikeYesTied to a device or password manager, so it needs a recovery path if that is lost
Authenticator app (TOTP)No — the code can be typed into a fake page inside its 30-second windowYesLose the phone without backup codes and you are in a support queue
SMS codeNoNo — needs signalSIM swapping, plus codes that arrive late or not at all when roaming
Email codeNo — and it collapses entirely if the mailbox is what was breachedNoOnly ever as strong as the email account behind it
Passkey
Authenticator app
How you sign in
Face ID, fingerprint or device PIN — nothing to type
Open the app, read a six-digit code, type it before it rotates
Phishing resistance
Strong — it will not offer itself to a lookalike domain
Weak — the code is just a number, and a fake page will ask for it
New device setup
Syncs through your password manager or platform keychain
Needs a re-scan of the QR code or a fresh enrolment
Best for
PlayStation, Microsoft/Xbox and Nintendo, where it is supported today
Steam, Riot and Epic, plus anywhere a passkey is not offered yet

Where the setting lives on each platform

Bookmark this table. Half the reason people never turn any of this on is that the setting sits four menus deep and is named differently on every service.

The exact path to the security settings, platform by platform
PlatformBest available optionWhere to find it
SteamSteam Guard Mobile AuthenticatorSteam Mobile App → Steam Guard → Add Authenticator
PlayStationPasskey + 2-step verificationAccount Management → Security → Sign In with Passkey / 2-Step Verification
Xbox / MicrosoftPasskey (passwordless)account.microsoft.com → Security → Advanced security options
NintendoPasskey + 2-step verificationNintendo Account settings → Sign-in and security settings
Epic GamesAuthenticator app 2FAAccount Settings → Password & Security → Two-Factor Authentication
Riot GamesRiot Mobile or authenticator app MFAaccount.riotgames.com → Multi-Factor Authentication → Enable

Steam — where the authenticator does double duty

Steam has no passkey option, so the Steam Guard Mobile Authenticator inside the official Steam Mobile App is the strongest thing on offer — Valve itself describes it as the highest level of security available for an account, and says having it makes recovery faster if the account is ever stolen. It is also the only setting in this article that changes what you are allowed to do with your account, which is where the confusion starts.

  1. Install the official Steam Mobile App
    Valve publishes it on the App Store, Google Play and the Microsoft Store. Sign in with your Steam account — anything else calling itself a Steam authenticator is not one.
  2. Open Steam Guard and choose Add Authenticator
    The Steam Guard section is reachable from the menu inside the app.
  3. Verify a phone number
    Steam sends an SMS to confirm the number and you enter that confirmation code once. From then on the app generates the codes itself, no signal required.
  4. Write down the recovery code
    Steam shows a recovery code at the end of setup. This is the single most important screen in this entire article — photograph it, print it, store it somewhere that is not the phone you just set up.

The trade and Market holds nobody expects

Steam ties trading and Community Market privileges directly to how long your account has been protected. If you play CS2, Dota 2, Rust or anything else with an inventory, these timings decide whether an item actually moves.

Steam Guard timing rules for trades and Market listings
Your situationWhat Steam does
Steam Guard enabled for fewer than 15 daysYou cannot trade or use the Community Market at all
No mobile authenticator on the accountTrades and Market listings are held for 15 days before they complete
Mobile authenticator added less than 7 days agoAnything created inside that first week is still held for 15 days
Mobile authenticator active more than 7 daysTrades and Market listings complete without a Steam hold
Everything else about the Steam wallet — how balance behaves and what it can and cannot pay for — is covered in our complete Steam gift card guide, and refunds return to that same wallet, as explained in how to refund a game on Steam. Both are worth reading before you load a large amount onto one account.

PlayStation — passkey first, 2SV behind it

Sony now supports passkeys on PlayStation Network, so you can sign in with Face ID, a fingerprint or your device screen lock instead of typing a password. If you have ever entered a long password using a DualSense and an on-screen keyboard, that alone is reason enough.

  1. Sign in to Account Management on the web
    Use a browser rather than the console — the security page is far easier to work through there.
  2. Open Account → Security
    You will see “Sign In with Passkey”, which reads as Deactivated the first time.
  3. Select Edit, then Create a Passkey
    Your device or password manager handles the rest. Create it on the device you actually keep with you.
  4. Set 2-Step Verification on the same page
    Next to 2-Step Verification Status select Edit, choose Authenticator App rather than Text Message, scan the QR code, enter the generated code and select Activate.
  5. Record the backup codes
    PSN shows them immediately after activation. They are your way back in if the phone disappears.

Xbox — you may already be passwordless

Xbox sign-in is Microsoft account sign-in, so it inherited Microsoft’s passwordless push. New personal Microsoft accounts have been created passwordless by default since May 2025, with passkeys as the intended sign-in method across the ecosystem including Xbox — so if you made your account recently there may be no password to steal in the first place. Older accounts still have one, and that is the case worth fixing.

  • Go to account.microsoft.com → Security → Advanced security options.
  • Add a passkey for each device you actually game or shop on.
  • Add the Microsoft Authenticator app as a verification method — the console sign-in screen can then push an approval to your phone instead of asking for a password.
  • Once a passkey and the authenticator are both in place, consider removing the password from the account entirely, which Microsoft supports for personal accounts.
  • Review the devices and sessions listed on the same page and sign out anything you do not recognise.

Nintendo — 2-step verification, plus passkeys

Nintendo Accounts support both passkey sign-in and classic 2-step verification, the latter using a rotating code from an authenticator app such as Google Authenticator. Given that your eShop balance lives on the account and Nintendo will not move funds between accounts under any circumstances, this is one worth doing properly.

  • Sign in to your Nintendo Account settings in a browser and open the sign-in and security section.
  • Register a passkey on your phone or password manager for everyday sign-in.
  • Enable 2-Step Verification and pair it with an authenticator app.
  • Save the backup codes — Nintendo lets you review them again later from the same settings area, which is a small mercy no other platform here offers.
  • On a shared family console, confirm which console profile maps to which Nintendo Account before you change anything.
If you are redeeming eShop cards onto that account, our Nintendo eShop card guide covers the region rule that decides whether a perfectly genuine card works at all.

Epic, Riot and the launcher accounts

Epic Games

Epic offers three flavours of 2FA — an authenticator app, an email code and an SMS code. Pick the authenticator app. Epic also makes 2FA a hard requirement for parts of the store: it is required to claim certain free games, and required to send gifts in Fortnite. If you have ever wondered why the free weekly game refused to add itself to your library, this is usually why.

Riot Games

Riot supports multi-factor authentication through the Riot Mobile app, a standard authenticator app such as Google or Microsoft Authenticator, or an emailed code. Enable it at account.riotgames.com under Multi-Factor Authentication. Riot has also started making MFA mandatory for higher-ranked and shared accounts, rolling the requirement out region by region — so if you play ranked VALORANT or League seriously, expect the prompt eventually and get ahead of it. The “remember this device for 30 days” box is a convenience option, not a reason to skip setup.

What turning it on actually unlocks

Security features are a hard sell, so publishers bribe people into them. The bribes are real, and in a couple of cases they gate things you probably want anyway.

Perks and requirements tied to 2FA
PlatformWhat you get or unlock
SteamTrading and Community Market access, and no 15-day hold on completed trades
Epic GamesClaiming certain free store games, gifting in Fortnite, and the Boogie Down emote
Riot GamesIn-game rewards across its titles, including a VALORANT gun buddy and a League emote
PlayStation / Xbox / NintendoNo cosmetic bribe — just the part where your balance stays yours

Backup codes: the step everyone skips

Here is the failure mode we see most often, and it has nothing to do with hackers. Someone enables an authenticator app, then replaces their phone, wipes the old one, and discovers the codes did not come with it. The account is not stolen — it is simply unreachable, and getting back in means a support ticket and proof of purchase.

  • Save every platform’s backup or recovery codes at setup time, before you close the tab
  • Store them somewhere that survives losing your phone — a password manager, a printed note, an encrypted file on another device
  • Never keep them as a screenshot in the phone’s photo roll, which syncs to the cloud account an attacker may already be inside
  • Prefer an authenticator app with its own encrypted backup, so a new phone can restore the codes
  • Keep the recovery email address on each account current, and secure that mailbox with its own passkey

The scams that get past 2FA anyway

Two-factor authentication raises the floor. It does not make you immune, because the most effective attacks in gaming do not break the login at all — they ask you to complete it on their behalf. Three patterns account for most of what actually happens.

  • The lookalike sign-in page — a “vote for my team” link, a fake trading site or a Discord message that opens a Steam login window which is really just an image inside a browser window. Whatever code you type there, they type into the real site seconds later.
  • The gift-card-as-payment demand — anyone insisting on being paid in gift card codes, whether they claim to be support, a seller, or a friend in trouble. No legitimate business or platform is ever paid this way.
  • Session and token theft — malware or a malicious browser extension that takes an already-authenticated session, at which point your second factor is never asked for at all.

If you think you are already compromised

Speed matters here, and order matters almost as much — changing a password before you have secured the mailbox behind it just hands the reset link straight back.

  1. Secure the email account first
    Change its password and enable a passkey or 2FA on the mailbox. Everything else on this list can be reset through email, so it has to be clean before you touch the gaming accounts.
  2. Change the gaming account password and revoke sessions
    Every platform here has a “sign out everywhere” control or an authorised-devices list. Use it — a password change alone does not always kill an active session.
  3. Use the platform’s own recovery flow if you are locked out
    Steam runs a self-service recovery wizard at help.steampowered.com that specifically handles a lost or deleted mobile authenticator as well as hijacked accounts, and it is the fastest route back in. PlayStation, Nintendo and Microsoft each have equivalent account-recovery forms.
  4. Check what was spent and what was added
    Look at the wallet balance, purchase history, saved payment methods and — on Steam — the trade history and any newly authorised API keys. Remove anything you did not add yourself.
  5. Contact your bank if a card was on file
    If a saved payment method was charged, the card issuer is the fastest way to stop further charges. This is precisely the scenario a prepaid wallet top-up avoids.
  6. Only then re-enable everything
    Set up the passkey or authenticator fresh, save the new backup codes, and treat the old ones as burned.

The 10-minute hardening pass

  • A unique password on every gaming account, generated and stored by a password manager
  • A passkey registered on PlayStation, Microsoft/Xbox and Nintendo
  • The Steam Guard Mobile Authenticator active in the official Steam Mobile App
  • Authenticator-app MFA on Epic and Riot, plus Battle.net, EA and Ubisoft if you use them
  • Backup and recovery codes saved off-device for every one of the above
  • The recovery email address current, and that mailbox secured with its own passkey
  • Saved payment cards removed in favour of wallet top-ups wherever you can manage it
  • A pass through authorised devices and active sessions, signing out anything unfamiliar

The account is the asset. The code, the game and the skin are just things sitting on top of it.

Virtwave Payments Team, Senior Payments & Wallet Specialists

FAQs

Is a passkey safer than an authenticator app?
Yes, in the way that matters most. A passkey is bound to the genuine website and will not offer itself to a lookalike page, so the most common attack — a convincing fake login — fails outright. An authenticator code is just six digits, and a fake page can ask for it and relay it in real time. Use a passkey wherever it is offered and an authenticator app everywhere else.
Should I use SMS codes if that is all a platform offers?
Yes. SMS is much weaker than an app or a passkey because of SIM swapping, but it is enormously better than nothing. Turn it on now and switch to a stronger method when the platform adds one.
Why can I not trade on Steam even though I turned Steam Guard on?
Steam requires Steam Guard to have been enabled for 15 days before trading or Community Market access opens at all. Separately, if you added the mobile authenticator less than seven days ago, anything you create inside that window is still held for 15 days. Both clocks have to run out.
I lost the phone with my authenticator on it. Is the account gone?
No, but it becomes a support process rather than a self-service one. If you saved the backup or recovery codes, use them and you are back in immediately. If not, every platform here has a recovery flow — Steam’s wizard has a dedicated path for a lost mobile authenticator — and it will ask you to prove ownership, usually with purchase details.
Does two-factor authentication slow down buying and redeeming codes?
Barely. Most platforms only prompt for the second factor on a new device or a sensitive change, and passkey sign-in is faster than typing a password. Redeeming a gift card code on a device you are already signed into is unaffected.
Is buying gift cards actually safer than saving a card on the account?
It limits the damage, which is a different thing from preventing an attack. A wallet holds a fixed amount, so a compromised account can only lose what is loaded on it, while a saved card can be charged repeatedly until someone notices. It is the same logic behind using a prepaid balance to control spending generally.
How often should I redo any of this?
Once properly, then a five-minute review whenever you change phones, plus a look at the authorised-devices list a couple of times a year. The setup does not decay — losing access to your second factor is the only thing that usually forces a repeat.
Once the account is locked down, the rest is the easy part. Virtwave delivers Steam, PlayStation and Xbox gift card codes by email in minutes. Before you buy, check how gift card regions and country locks work so the code matches the account you just secured, read the gift card scam statistics for the patterns worth recognising, and if you are choosing between subscriptions for that balance, our PS Plus vs Xbox Game Pass comparison is the companion piece.
Virtwave Payments Team
Senior Payments & Wallet Specialists

The Virtwave Payments Team has processed millions of gift card top-ups across 80+ countries. They test every major wallet platform (Razer Gold, PSN, Steam, Google Play, Apple, Xbox) on a weekly cadence to keep our how-to content accurate.

Virtwave Payments Team
Senior Payments & Wallet Specialists

The Virtwave Payments Team has processed millions of gift card top-ups across 80+ countries. They test every major wallet platform (Razer Gold, PSN, Steam, Google Play, Apple, Xbox) on a weekly cadence to keep our how-to content accurate.

Top up securely on Virtwave

All articles →
💬

FAQ Assistant

Click a question to see the answer

🤖

Select a question below
to get instant answers

🛒

Ordering & Purchasing

📧

Delivery & Activation

💰

Refunds & Returns

🔐

Account & Security

💬

Support

🔧

Technical Issues