Every guide on this blog ends the same way: redeem the code onto the right account. This one is about the part nobody thinks about until it is too late — whether that account can be taken from you. A gaming account in 2026 is a wallet with a library attached. There is stored balance on it, often a saved payment method behind it, a decade of purchases inside it, and in the case of CS2 or Dota inventories, tradeable items that convert to money in minutes. That combination is exactly why gaming logins are worth stealing, and why every major platform has spent the last two years pushing people off passwords entirely. The good news: hardening all six of the accounts below is genuinely a ten-minute job. Here is where each setting lives, what each method is actually worth, and the two mistakes that undo all of it.
Why the account is the target, not the code
A stolen gift card code is worth its face value once. A stolen account is worth the balance on it, plus whatever the saved card will authorise, plus the inventory, plus a clean identity to run the next scam from. That is why the attack has shifted: almost nobody bothers guessing passwords any more. They get you to hand over a login on a page that looks like the real one, or they lift an already-authenticated session, or they simply reuse a password that leaked from a completely unrelated site five years ago.
Passkey vs authenticator app vs SMS vs email
All four get called “two-factor” somewhere in a settings menu, and they are not remotely equal. The difference that matters is whether the second factor can be repeated back to an attacker by a person sitting at a convincing fake login page.
| Method | Stops a phishing page? | Works offline? | Main weakness |
|---|---|---|---|
| Passkey (face, fingerprint, device PIN) | Yes — it is bound to the real domain and will not fire on a lookalike | Yes | Tied to a device or password manager, so it needs a recovery path if that is lost |
| Authenticator app (TOTP) | No — the code can be typed into a fake page inside its 30-second window | Yes | Lose the phone without backup codes and you are in a support queue |
| SMS code | No | No — needs signal | SIM swapping, plus codes that arrive late or not at all when roaming |
| Email code | No — and it collapses entirely if the mailbox is what was breached | No | Only ever as strong as the email account behind it |
Where the setting lives on each platform
Bookmark this table. Half the reason people never turn any of this on is that the setting sits four menus deep and is named differently on every service.
| Platform | Best available option | Where to find it |
|---|---|---|
| Steam | Steam Guard Mobile Authenticator | Steam Mobile App → Steam Guard → Add Authenticator |
| PlayStation | Passkey + 2-step verification | Account Management → Security → Sign In with Passkey / 2-Step Verification |
| Xbox / Microsoft | Passkey (passwordless) | account.microsoft.com → Security → Advanced security options |
| Nintendo | Passkey + 2-step verification | Nintendo Account settings → Sign-in and security settings |
| Epic Games | Authenticator app 2FA | Account Settings → Password & Security → Two-Factor Authentication |
| Riot Games | Riot Mobile or authenticator app MFA | account.riotgames.com → Multi-Factor Authentication → Enable |
Steam — where the authenticator does double duty
Steam has no passkey option, so the Steam Guard Mobile Authenticator inside the official Steam Mobile App is the strongest thing on offer — Valve itself describes it as the highest level of security available for an account, and says having it makes recovery faster if the account is ever stolen. It is also the only setting in this article that changes what you are allowed to do with your account, which is where the confusion starts.
- Install the official Steam Mobile AppValve publishes it on the App Store, Google Play and the Microsoft Store. Sign in with your Steam account — anything else calling itself a Steam authenticator is not one.
- Open Steam Guard and choose Add AuthenticatorThe Steam Guard section is reachable from the menu inside the app.
- Verify a phone numberSteam sends an SMS to confirm the number and you enter that confirmation code once. From then on the app generates the codes itself, no signal required.
- Write down the recovery codeSteam shows a recovery code at the end of setup. This is the single most important screen in this entire article — photograph it, print it, store it somewhere that is not the phone you just set up.
The trade and Market holds nobody expects
Steam ties trading and Community Market privileges directly to how long your account has been protected. If you play CS2, Dota 2, Rust or anything else with an inventory, these timings decide whether an item actually moves.
| Your situation | What Steam does |
|---|---|
| Steam Guard enabled for fewer than 15 days | You cannot trade or use the Community Market at all |
| No mobile authenticator on the account | Trades and Market listings are held for 15 days before they complete |
| Mobile authenticator added less than 7 days ago | Anything created inside that first week is still held for 15 days |
| Mobile authenticator active more than 7 days | Trades and Market listings complete without a Steam hold |
PlayStation — passkey first, 2SV behind it
Sony now supports passkeys on PlayStation Network, so you can sign in with Face ID, a fingerprint or your device screen lock instead of typing a password. If you have ever entered a long password using a DualSense and an on-screen keyboard, that alone is reason enough.
- Sign in to Account Management on the webUse a browser rather than the console — the security page is far easier to work through there.
- Open Account → SecurityYou will see “Sign In with Passkey”, which reads as Deactivated the first time.
- Select Edit, then Create a PasskeyYour device or password manager handles the rest. Create it on the device you actually keep with you.
- Set 2-Step Verification on the same pageNext to 2-Step Verification Status select Edit, choose Authenticator App rather than Text Message, scan the QR code, enter the generated code and select Activate.
- Record the backup codesPSN shows them immediately after activation. They are your way back in if the phone disappears.
Xbox — you may already be passwordless
Xbox sign-in is Microsoft account sign-in, so it inherited Microsoft’s passwordless push. New personal Microsoft accounts have been created passwordless by default since May 2025, with passkeys as the intended sign-in method across the ecosystem including Xbox — so if you made your account recently there may be no password to steal in the first place. Older accounts still have one, and that is the case worth fixing.
- Go to account.microsoft.com → Security → Advanced security options.
- Add a passkey for each device you actually game or shop on.
- Add the Microsoft Authenticator app as a verification method — the console sign-in screen can then push an approval to your phone instead of asking for a password.
- Once a passkey and the authenticator are both in place, consider removing the password from the account entirely, which Microsoft supports for personal accounts.
- Review the devices and sessions listed on the same page and sign out anything you do not recognise.
Nintendo — 2-step verification, plus passkeys
Nintendo Accounts support both passkey sign-in and classic 2-step verification, the latter using a rotating code from an authenticator app such as Google Authenticator. Given that your eShop balance lives on the account and Nintendo will not move funds between accounts under any circumstances, this is one worth doing properly.
- Sign in to your Nintendo Account settings in a browser and open the sign-in and security section.
- Register a passkey on your phone or password manager for everyday sign-in.
- Enable 2-Step Verification and pair it with an authenticator app.
- Save the backup codes — Nintendo lets you review them again later from the same settings area, which is a small mercy no other platform here offers.
- On a shared family console, confirm which console profile maps to which Nintendo Account before you change anything.
Epic, Riot and the launcher accounts
Epic Games
Epic offers three flavours of 2FA — an authenticator app, an email code and an SMS code. Pick the authenticator app. Epic also makes 2FA a hard requirement for parts of the store: it is required to claim certain free games, and required to send gifts in Fortnite. If you have ever wondered why the free weekly game refused to add itself to your library, this is usually why.
Riot Games
Riot supports multi-factor authentication through the Riot Mobile app, a standard authenticator app such as Google or Microsoft Authenticator, or an emailed code. Enable it at account.riotgames.com under Multi-Factor Authentication. Riot has also started making MFA mandatory for higher-ranked and shared accounts, rolling the requirement out region by region — so if you play ranked VALORANT or League seriously, expect the prompt eventually and get ahead of it. The “remember this device for 30 days” box is a convenience option, not a reason to skip setup.
What turning it on actually unlocks
Security features are a hard sell, so publishers bribe people into them. The bribes are real, and in a couple of cases they gate things you probably want anyway.
| Platform | What you get or unlock |
|---|---|
| Steam | Trading and Community Market access, and no 15-day hold on completed trades |
| Epic Games | Claiming certain free store games, gifting in Fortnite, and the Boogie Down emote |
| Riot Games | In-game rewards across its titles, including a VALORANT gun buddy and a League emote |
| PlayStation / Xbox / Nintendo | No cosmetic bribe — just the part where your balance stays yours |
Backup codes: the step everyone skips
Here is the failure mode we see most often, and it has nothing to do with hackers. Someone enables an authenticator app, then replaces their phone, wipes the old one, and discovers the codes did not come with it. The account is not stolen — it is simply unreachable, and getting back in means a support ticket and proof of purchase.
- Save every platform’s backup or recovery codes at setup time, before you close the tab
- Store them somewhere that survives losing your phone — a password manager, a printed note, an encrypted file on another device
- Never keep them as a screenshot in the phone’s photo roll, which syncs to the cloud account an attacker may already be inside
- Prefer an authenticator app with its own encrypted backup, so a new phone can restore the codes
- Keep the recovery email address on each account current, and secure that mailbox with its own passkey
The scams that get past 2FA anyway
Two-factor authentication raises the floor. It does not make you immune, because the most effective attacks in gaming do not break the login at all — they ask you to complete it on their behalf. Three patterns account for most of what actually happens.
- The lookalike sign-in page — a “vote for my team” link, a fake trading site or a Discord message that opens a Steam login window which is really just an image inside a browser window. Whatever code you type there, they type into the real site seconds later.
- The gift-card-as-payment demand — anyone insisting on being paid in gift card codes, whether they claim to be support, a seller, or a friend in trouble. No legitimate business or platform is ever paid this way.
- Session and token theft — malware or a malicious browser extension that takes an already-authenticated session, at which point your second factor is never asked for at all.
If you think you are already compromised
Speed matters here, and order matters almost as much — changing a password before you have secured the mailbox behind it just hands the reset link straight back.
- Secure the email account firstChange its password and enable a passkey or 2FA on the mailbox. Everything else on this list can be reset through email, so it has to be clean before you touch the gaming accounts.
- Change the gaming account password and revoke sessionsEvery platform here has a “sign out everywhere” control or an authorised-devices list. Use it — a password change alone does not always kill an active session.
- Use the platform’s own recovery flow if you are locked outSteam runs a self-service recovery wizard at help.steampowered.com that specifically handles a lost or deleted mobile authenticator as well as hijacked accounts, and it is the fastest route back in. PlayStation, Nintendo and Microsoft each have equivalent account-recovery forms.
- Check what was spent and what was addedLook at the wallet balance, purchase history, saved payment methods and — on Steam — the trade history and any newly authorised API keys. Remove anything you did not add yourself.
- Contact your bank if a card was on fileIf a saved payment method was charged, the card issuer is the fastest way to stop further charges. This is precisely the scenario a prepaid wallet top-up avoids.
- Only then re-enable everythingSet up the passkey or authenticator fresh, save the new backup codes, and treat the old ones as burned.
The 10-minute hardening pass
- A unique password on every gaming account, generated and stored by a password manager
- A passkey registered on PlayStation, Microsoft/Xbox and Nintendo
- The Steam Guard Mobile Authenticator active in the official Steam Mobile App
- Authenticator-app MFA on Epic and Riot, plus Battle.net, EA and Ubisoft if you use them
- Backup and recovery codes saved off-device for every one of the above
- The recovery email address current, and that mailbox secured with its own passkey
- Saved payment cards removed in favour of wallet top-ups wherever you can manage it
- A pass through authorised devices and active sessions, signing out anything unfamiliar
“The account is the asset. The code, the game and the skin are just things sitting on top of it.”
— Virtwave Payments Team, Senior Payments & Wallet Specialists
FAQs
Is a passkey safer than an authenticator app?
Should I use SMS codes if that is all a platform offers?
Why can I not trade on Steam even though I turned Steam Guard on?
I lost the phone with my authenticator on it. Is the account gone?
Does two-factor authentication slow down buying and redeeming codes?
Is buying gift cards actually safer than saving a card on the account?
How often should I redo any of this?
The Virtwave Payments Team has processed millions of gift card top-ups across 80+ countries. They test every major wallet platform (Razer Gold, PSN, Steam, Google Play, Apple, Xbox) on a weekly cadence to keep our how-to content accurate.