We conducted an awareness survey of 293 people with crypto assets (also known as virtual currencies) experience regarding two-factor authentication (2FA), a security measure essential to safe crypto asset management. The survey found that while overall 2FA adoption reached roughly 80%, fewer than 40% of respondents had enabled 2FA across every service they use. “Operational hassle” and “concerns about convenience” topped the list of reasons preventing setup, yet about 54% of holders without 2FA also reported feeling anxious about their current situation — a clear dilemma.

In particular, nearly all respondents in the high-investment bracket (over ¥500,000) had already set up 2FA, while low-investment and beginner segments showed a notably weaker security mindset.

This article draws on detailed cross-tabulated data by age group and investment amount to analyze why some holders never set up 2FA, what pushed others to finally do it, and the resulting literacy gap in asset protection. In a market where “self-responsibility” is the guiding principle, we lay out concrete steps holders should take now to defend their assets from increasingly sophisticated cyberattacks.

2FA Adoption Nears 80%, but Partial Setups Leave a “Management Gap”

Full Coverage Under 40%: Holders Torn Between Convenience and Security

Response

Respondents

Share

Enabled on some services only

122

41.64%

Enabled on all services

112

38.23%

Not enabled

44

15.02%

Don't know

15

5.12%

Two-factor authentication (2FA) is the most basic yet powerful safeguard for protecting crypto assets. Among the crypto asset users surveyed, only 38.23% had enabled 2FA on all the services they use. Meanwhile, the largest group — 41.64% — had enabled it on only some services.

This result highlights the reality that many holders recognize the importance of security but, in practice, prioritize “convenience” and avoiding “hassle.” This difficulty is especially pronounced for users who hold accounts with multiple Crypto Asset Exchange Service Providers, where maintaining strict management across every account is challenging. If even one account is left unprotected, it can become an entry point for attackers — meaning the overall management posture must be considered insufficient.

It is also deeply concerning that 15.02% reported having no 2FA set up at all. In a world where self-custody is the guiding principle, relying on an ID and password alone leaves users nearly defenseless against phishing scams and credential-stuffing attacks. For the market to develop in a healthy way, raising user literacy and promoting 2FA adoption to a near-mandatory standard are urgent priorities.

Even Among Users With 3+ Years of Experience, 1 in 10 Still Lack 2FA

Investment Experience

Enabled on All

Enabled on Some Only

Not Enabled

Don't Know

Total

Less than 6 months

9 (21.43%)

24 (57.14%)

7 (16.67%)

2 (4.76%)

42

6 months to under 1 year

34 (35.79%)

38 (40.00%)

14 (14.74%)

9 (9.47%)

95

1 to under 3 years

37 (48.05%)

27 (35.06%)

11 (14.29%)

2 (2.60%)

77

3+ years

31 (46.27%)

28 (41.79%)

7 (10.45%)

1 (1.49%)

67

Prefer not to answer

1 (8.33%)

5 (41.67%)

5 (41.67%)

1 (8.33%)

12

Analyzing 2FA setup status by years of investment experience shows a clear trend: the longer someone has been investing, the more likely they are to have enabled 2FA across all their services. Among veteran holders with 3+ years of experience, roughly half have completed setup on every service, suggesting a heightened sense of urgency shaped by past market incidents. By contrast, among beginners with less than 6 months of experience, the combined share who have not set up 2FA or don’t know their status exceeds 20%, highlighting weaker defenses during the early stage of market entry.

Notably, even among respondents with 3+ years of experience, more than 10% said they had not enabled 2FA. Even knowledgeable holders may develop a sense of complacency from being accustomed to daily operations, and that complacency can create security gaps. In the world of crypto assets, a single mistake can lead directly to catastrophic loss, so even veteran holders need to return to the basics.

For beginners to establish themselves safely in the market, deliberate measures — such as building 2FA into the initial account setup flow — are essential. Regardless of years of experience, holders need to stay continually informed about the latest security threats and keep updating their defenses. Abandoning the unfounded confidence of “I’ll be fine” and building technical safeguards instead is an effective way to protect one’s assets.

Holders With Over ¥500,000 Invested Show a 90% Setup Rate — Larger Holdings Drive Greater Urgency

Investment Amount

Enabled on All

Enabled on Some Only

Not Enabled

Don't Know

Total

Under ¥10,000

26 (24.30%)

49 (45.79%)

23 (21.50%)

9 (8.41%)

107

¥100,000 to under ¥500,000

61 (47.29%)

52 (40.31%)

12 (9.30%)

4 (3.10%)

129

¥500,000 or more

21 (53.85%)

15 (38.46%)

3 (7.69%)

0 (0.00%)

39

Prefer not to answer

4 (22.22%)

6 (33.33%)

6 (33.33%)

2 (11.11%)

18

There is a very strong correlation between investment amount and 2FA adoption. Among holders with more than ¥500,000 invested, over 90% have enabled 2FA in some form, showing that larger holdings directly translate into greater security awareness. This suggests that the larger the potential loss, the more proactively holders adopt technical safeguards.

On the other hand, holders investing under ¥10,000 showed the highest non-adoption rate of any segment. This appears to be driven by a psychological complacency — the assumption that “a small holding won’t be targeted” — which leads to setup being deprioritized. However, attackers target vulnerable accounts regardless of the amount held, so the risk exists equally even for small holdings.

Even among the mid-tier segment (¥100,000 to under ¥500,000), many holders have set up 2FA on only some of their services. This suggests that many holders are in a “transitional phase,” where their security level has not yet caught up with their growing investment amount. A mindset shift is needed to treat the cost and effort of protecting one’s assets as a necessary expense of investing.

People in Their 20s Show the Highest Non-Adoption Rate — Mobile Convenience Fuels Risk Complacency

Age Group

Enabled on All

Enabled on Some Only

Not Enabled

Don't Know

Total

20s

16 (30.19%)

21 (39.62%)

12 (22.64%)

4 (7.55%)

53

30s

30 (35.29%)

39 (45.88%)

13 (15.29%)

3 (3.53%)

85

40s

29 (40.85%)

28 (39.44%)

11 (15.49%)

3 (4.23%)

71

50s

26 (42.62%)

25 (40.98%)

6 (9.84%)

4 (6.56%)

61

60s

7 (58.33%)

5 (41.67%)

0 (0.00%)

0 (0.00%)

12

70 and older

4 (36.36%)

4 (36.36%)

2 (18.18%)

1 (9.09%)

11

Breaking the results down by age group reveals that the working-age cohort — those in their 20s, 30s, and 40s — has relatively high rates of not having enabled 2FA. Among respondents in their 20s in particular, the combined share who have not enabled 2FA or don’t know their status approaches 30%, indicating relatively lower interest in security compared with other age groups. Despite being highly comfortable with digital devices, this group appears to prioritize ease of use over robust account management.

By contrast, every respondent in their 60s has enabled 2FA in some form, reflecting a notably cautious approach to account management. Despite finding the technology challenging, this group appears to take warnings from public institutions and the media seriously and act on them. The fact that younger holders, in pursuing mobile convenience, neglect the basics of security represents a significant risk going forward.

Younger holders who gather information through social media and YouTube tend to be highly attuned to trending tokens and profitability, but many lack sufficient knowledge of protective measures. Across every generation, it is important to recognize that holding crypto assets is fundamentally different from managing a bank account. Rather than treating convenience and security as a trade-off, the time has come for every generation to build the literacy needed to achieve both.

The “Hassle Barrier” Blocking Setup: How Psychological Bias Creates Vulnerable Habits

Hassle and Convenience Are the Biggest Barriers; Unclear Setup Instructions Also Cited by About 36%

Response

Respondents

Share

It seemed like it would be a hassle

22

37.29%

I wasn't sure how to set it up

21

35.59%

I felt logging in would become inconvenient

19

32.20%

I wasn't aware that 2FA was even important

14

23.73%

I didn't think I would be a victim

12.0

20.34%

None of the above apply

11

18.64%

The survey found that the biggest barrier for holders who have not set up 2FA is psychological cost. The top reason cited was “it seemed like it would be a hassle” (approx. 37.3%), followed by concerns about convenience such as “logging in would become inconvenient” (approx. 32.2%). This reveals that many users view strengthening their security as a burden that undermines their day-to-day convenience.

Meanwhile, “I wasn’t sure how to set it up” reached approximately 35.6%, showing that technical barriers are also a factor that cannot be ignored. The authentication apps and physical devices offered by Crypto Asset Exchange Service Providers often appear complex to beginners. This knowledge gap creates a negative cycle in which essential protective measures keep getting postponed. Alongside UI/UX improvements, clear, concrete guidance to lower the setup barrier is needed.

Even more concerning is the unfounded normalcy bias behind “I didn’t think I would be a victim” (approx. 20.3%). Cyberattacks indiscriminately target vulnerable points regardless of a holder’s asset size or identity. Including the segment that “wasn’t aware [2FA] was even important” (approx. 23.7%), many holders continue operating with a low degree of risk awareness. It is important to recognize that this kind of psychological complacency is precisely the biggest opening attackers exploit.

60% of Non-Adopters Admit Feeling Anxious — A Dilemma Between Awareness and Inaction

Response

Respondents

Share

Somewhat anxious

24

40.68%

Not very anxious

18

30.51%

Not anxious at all

9

15.25%

Very anxious

8

13.56%

Analyzing the psychological state of holders who have not set up 2FA reveals a situation full of contradiction. Combining those who answered “somewhat anxious” or “very anxious,” the share exceeds half, reaching approximately 54.2%. In other words, the majority of these users are aware that their accounts are vulnerable but, for one reason or another, remain stuck in a “dilemma” — unable to take protective action.

This “conscious vulnerability” represents a significant potential risk for the crypto asset market. Behind the failure to act despite feeling anxious lies not only the hassle and lack of knowledge described earlier, but also an absence of a concrete picture of what victimization would actually look like. Holders may feel a vague fear of “something bad happening,” but they haven’t fully internalized when or how it might happen to them personally. As a result, security ends up being treated as a low-priority task and left unaddressed.

On the other hand, those who answered “not very anxious” or “not anxious at all” together account for more than 40%. This group is likely split between holders who are confident in their own precautions (such as password management) and those who simply underestimate the risk itself. However, going without 2FA when handling crypto assets is genuinely risky in today’s cyber environment. A two-pronged approach is needed: helping anxious holders take that first step, and educating unconcerned holders about the real threats they face.

Heavier Social Media Reliance Correlates With Higher Non-Adoption — Access to Accurate Primary Sources Is Key

Information Source

Enabled on All

Enabled on Some Only

Not Enabled

Don't Know

Total

Social Media

52 (36.88%)

60 (42.55%)

22 (15.60%)

7 (4.96%)

141

Exchange/Official Announcements

53 (47.32%)

49 (43.75%)

7 (6.25%)

3 (2.68%)

112

News Sites

71 (43.83%)

68 (41.98%)

17 (10.49%)

6 (3.70%)

162

Specialist Crypto Media

54 (47.79%)

46 (40.71%)

11 (9.73%)

2 (1.77%)

113

There is a correlation worth noting between the information channels holders rely on and their 2FA adoption rate. Holders whose primary information source is exchanges or official service announcements have an extremely low non-adoption rate of about 6.3%. This can be seen as a result of directly encountering primary-source information from official sites — setup recommendations and warnings about incidents — which appropriately cultivates a sense of urgency. It is a clear example of how the habit of obtaining accurate information translates directly into protecting one’s assets.

By contrast, holders who mainly rely on social media (such as X and YouTube) show a non-adoption rate of about 15.6% — more than double that of holders who reference official announcements. Social media is flooded with price predictions and news about new tokens, while discussions of unglamorous, effortful topics like security setup tend to be overlooked. In prioritizing speed of information and “knowledge for making money,” holders are likely missing out on the fundamental knowledge needed to protect their assets. Relying too heavily on secondary sources can create blind spots in how holders manage their accounts.

Surviving in the crypto asset world requires the ability to critically evaluate the quality of information. Basic measures like 2FA are “survival skills” that should be prioritized above flashy success stories. There’s no need to dismiss the convenience of social media information, but for important security decisions, holders should always consult official documentation. Correcting the imbalance in information sources and reassessing risk from multiple angles is the first step toward building a safe operating environment.

Security Incident Reports Are the Biggest Trigger for Action: Moving From Passive to Proactive Protection

Awareness of Incidents Drives Setup; Exchange Recommendations Also Show a Meaningful 35% Effect

Response

Respondents

Share

Heard about security incidents or victim accounts

123

52.56%

Was guided to during initial account setup

110

47.01%

Learned it was important from those around me or social media

86

36.75%

Was strongly recommended by an exchange

82

35.04%

No particular reason, just set it up

26

11.11%

None of the above apply

10

4.27%

The survey revealed that the biggest motivator for crypto asset users to enable 2FA is news of actual security incidents happening elsewhere. About 52.6% of users who have set up 2FA cited security incidents or examples of victimization as their trigger. This reflects the reality that many holders only take action once they develop a concrete sense of danger — the thought that “this could happen to me too.” Learning from other people’s losses, a psychology close to a defensive instinct, is a powerful motivator.

System-side prompts also play an important role, with “guidance during initial setup” cited by a high 47.0% of respondents. Guiding users at the point when their engagement is highest — the moment they start using a service — is an effective way to prevent gaps in setup. On the other hand, only about 35.0% cited a “strong recommendation” from an exchange as their trigger, suggesting that passive guidance alone is not enough. Platforms need to issue regular, effective alerts to maintain ongoing security.

About 36.8% recognized the importance of 2FA through social media or the people around them, showing that community-level awareness efforts are also having some effect. However, the fact that about 11.1% said they “set it up for no particular reason” suggests that a certain segment already treats security as a basic, taken-for-granted practice. The ideal outcome is an environment where every user adopts 2FA as a natural step, without relying on fear or coercion. Making voluntary protective awareness the standard is key to strengthening the resilience of the market as a whole.

Over Half Are Alert to Phishing, But Password Management Remains a Weak Point

Response

Respondents

Share

Watching out for phishing scams

154

52.56%

Storing private keys (signature keys)/seed phrases securely

136

46.42%

Not reusing passwords

92

31.40%

Not doing anything in particular

44

15.02%

Don't know

22

7.51%

Looking at security measures beyond 2FA reveals an imbalance in awareness of specific threats. “Watching out for phishing scams” reached about 52.6%, suggesting that awareness of fake websites and suspicious emails is fairly widespread. Holders appear to have built up reasonable defenses against these “visible threats,” which are frequently flagged on social media and elsewhere. However, because phishing defense depends primarily on individual vigilance, it is difficult to eliminate human error entirely.

By contrast, “not reusing passwords” — a fundamental security practice — is followed by only about 31.4% of respondents, a low figure. Holders should recognize that even with 2FA enabled, if the underlying password is breached through a credential-stuffing attack, one layer of protection is lost. Reusing the same password across services for the sake of convenience is an extremely risky habit when handling crypto assets. Steps that physically eliminate human error — such as using a password manager — are essential alongside 2FA.

It is also a fact that cannot be overlooked that about 15.0% of respondents answered “not doing anything in particular.” This figure is almost identical to the 2FA non-adoption rate, showing that a certain number of holders have essentially given up on security measures altogether. Crypto assets have no central administrator, so once they are stolen, there is no official recourse to recover them. Holders need to reaffirm the principle of self-custody: that they themselves are the final line of defense for their own assets.

Households Earning ¥10 Million or More Prioritize Private Key Management — A Gap in the Quality of Protection

Household Income

Does Not Reuse Passwords

Watches for Phishing

Secure Private Key Storage

Doing Nothing

Total

Under ¥4 million

30 (29.70%)

55 (54.46%)

42 (41.58%)

20 (19.80%)

101

¥4-6 million

23 (28.75%)

41 (51.25%)

32 (40.00%)

14 (17.50%)

80

¥6-8 million

21 (42.00%)

27 (54.00%)

28 (56.00%)

5 (10.00%)

50

¥8-10 million

9 (37.50%)

14 (58.33%)

12 (50.00%)

1 (4.17%)

24

¥10-12 million

4 (30.77%)

8 (61.54%)

11 (84.62%)

1 (7.69%)

13

¥12 million or more

3 (33.33%)

5 (55.56%)

7 (77.78%)

1 (11.11%)

9

Prefer not to answer

2 (12.50%)

4 (25.00%)

4 (25.00%)

2 (12.50%)

16

A cross-tabulation of security measures by household income found that higher-income households focus more heavily on secure management of private keys (signature keys) and seed phrases. Among households earning ¥10 million or more, roughly 80% prioritize private key storage, showing standout protective awareness compared with every other bracket. In this segment, which likely holds a larger absolute volume of assets, holders appear to deeply understand that managing the key information underpinning their assets should be their top protective priority.

By contrast, among households earning under ¥4 million, only about 41.6% prioritize private key storage, while “doing nothing” is notably high at about 19.8%. This suggests that differences in financial margin or asset size may influence how much time holders invest in learning about security. However, the risk of crypto asset theft exists equally regardless of income, and for holders with smaller assets, a single incident can arguably have a greater impact on their livelihood. The right answer for every holder is to maintain a uniformly high security standard, rather than scaling protection to the size of one’s holdings.

Notably, the middle-income bracket earning between ¥6 million and ¥10 million shows a comparatively high rate of “not reusing passwords,” at around 40%. This group appears to have strong practical literacy and a tendency to follow basic rules faithfully. Across every income bracket, awareness of phishing has spread to some degree, but a gap still remains in how thoroughly holders follow through with complementary “technical protections.” Every bracket needs to recognize that acquiring the skills to protect one’s assets is an essential part of investing.

Making Risk Visible Is Key to Adoption: Information Needs Differ Between Beginners and High-Value Holders

About Half Want a Clear Explanation of the Risks — Holders Seek Conviction Beyond Mere Convenience

Response

Respondents

Share

A concrete explanation of the risks of not setting it up

139

47.44%

Information that clearly explains the setup steps

85

29.01%

A checklist for beginners

45

15.36%

Don't feel it's particularly necessary

24

8.19%

Asked what kind of information would encourage them to set up 2FA, about half of respondents cited a concrete explanation of the risks of not doing so. This shows that simply presenting the operational steps is not enough — holders lack the conviction that comes from understanding why the effort is worthwhile in the first place. They are hungry for accurate information about what is at stake if they sacrifice convenience, and what could concretely happen if they leave 2FA unaddressed.

Meanwhile, requests for clearer setup instructions also make up a meaningful share, at about 29.0%. The authentication process unique to crypto assets remains a psychological barrier for many users, making UX improvement an urgent priority. Providing visual manuals and intuitive operating guides that lower the setup barrier can serve as a powerful push for holders who have not yet set up 2FA. Elevating security awareness from a burden to a standard practice requires both high-quality information and strong accessibility.

The fact that fewer than 10% said they don’t feel additional information is necessary is evidence that most holders sense room for improvement in their current security practices. Platforms should not leave users’ anxieties unaddressed and should continue providing information that channels that sense of urgency into appropriate protective action. Advancing risk visibility and simplifying procedures in parallel is the most direct roadmap for raising security standards across the market.

Higher-Value Holders Prioritize Detailed Risk Information; Under-¥10,000 Holders Prioritize Setup Steps

Investment Amount

Risk Explanation

Setup Steps

Checklist

Not Needed / Other

Under ¥10,000

31 (28.97%)

44 (41.12%)

19 (17.76%)

13 (12.15%)

¥100,000 to under ¥500,000

80 (62.02%)

30 (23.26%)

15 (11.63%)

4 (3.10%)

¥500,000 or more

25 (64.10%)

8 (20.51%)

6 (15.38%)

0 (0.00%)

The type of information holders want in relation to 2FA setup differs markedly depending on the size of their holdings. Among high-value holders with more than ¥500,000 invested, about 64.1% cited a concrete risk explanation as their top priority, reflecting a strong desire to sharpen their understanding of what victimization actually looks like. Holders who understand the pain of losing assets tend to seek rational measures grounded in that fear, and it is detailed threat analysis — not general reassurance — that triggers action for this group.

By contrast, among holders investing less than ¥10,000, clear setup instructions were the top request, at about 41.1%. For this group, it is not the security risk itself but rather the time and complexity involved in setup that poses the biggest source of stress to continued use. To protect beginners and small-amount users, creating an environment where they can set up 2FA without confusion — rather than lecturing them on complex risk theory — is likely the more effective approach.

The mid-tier segment places similar emphasis on risk explanations as the high-value segment, suggesting that as holdings grow, interest shifts from “how” to “why.” Personalizing information based on investment amount is an essential approach to raising security standards across a broad user base. Building a system that delivers the right information at the right time as holders grow from small to mid-size to large holdings will help secure the safety of the market as a whole.

Checklists Are Most Effective for Beginners: A Step-by-Step Approach Is the Fastest Path to Higher Literacy

Investment Experience

Risk Explanation

Setup Steps

Checklist

Not Needed / Other

Less than 6 months

11 (26.19%)

18 (42.86%)

9 (21.43%)

4 (9.52%)

6 months to under 1 year

51 (53.68%)

31 (32.63%)

9 (9.47%)

4 (4.21%)

1 to under 3 years

42 (54.55%)

17 (22.08%)

12 (15.58%)

6 (7.79%)

3+ years

35 (52.24%)

15 (22.39%)

11 (16.42%)

6 (8.96%)

Analyzing the relationship between years of investment experience and information needs shows that beginners with less than 6 months of experience rely heavily on setup instructions and checklists. In particular, the share requesting a checklist reaches about 21.4%, the highest of any experience group, revealing a clear desire for comprehensive yet simple guidance. Clearly spelling out exactly what to do, and in what order, to ensure safety is the fastest way to dispel beginners’ anxiety.

By contrast, among intermediate and veteran holders with a year or more of experience, over half consistently prioritize risk explanations, and their needs appear to become fixed at that point. While these holders grow comfortable with basic operations as they gain experience, they appear to struggle to keep their knowledge updated on constantly evolving hacking techniques and new vulnerabilities. To prevent complacency born of familiarity, continually providing risk information based on the latest attack cases can go a long way toward maintaining veteran holders’ protective awareness.

What’s needed is a step-by-step literacy path in which beginners quickly complete basic setup using a checklist and then gradually absorb more advanced risk information. Information needs exist at every level of proficiency, and providing guidelines tailored to each stage is key to closing security gaps. A support system that compensates for inexperience, combined with up-to-date information that keeps experienced holders from becoming overconfident, is the lifeline that will help holders protect their assets.

Summary

This survey revealed a serious gap between crypto asset holders’ awareness of two-factor authentication (2FA) and their actual practices. While overall 2FA adoption is close to 80%, fewer than 40% of holders have completed setup across every service they use, meaning many users continue operating with a security hole in their setup. In particular, the tendency to prioritize “hassle” and “convenience” and complete setup on only some services is nothing other than leaving vulnerable openings for attackers.

Behind the failure to set up 2FA lies not only physical barriers — unclear instructions and the hassle of logging in — but also a strong, unfounded normalcy bias: the belief that “I won’t be a victim.” However, the finding that more than half of non-adopters feel anxious about their current situation symbolizes the dilemma faced by holders who recognize the need for protection but cannot bring themselves to act. Resolving this “conscious vulnerability” requires more than simply providing operating instructions — it calls for an approach that makes the concrete risk scenarios of going without 2FA visible and gives users a strong sense of conviction.

The fact that information needs differ by investment experience and asset size also offers an important lesson for future education efforts. Providing beginners with a simple checklist for completing setup without hesitation, and providing high-value and veteran holders with detailed risk analysis grounded in the latest threats, can help raise literacy at every stage. Fulfilling the principle of “self-responsibility” when handling crypto assets means thoroughly implementing technical safeguards and never neglecting the ongoing work of learning to protect one’s assets.

Survey Overview

Survey date: February 24, 2026
Survey method: Internet survey
Survey subjects: Men and women residing in Japan (people currently or previously investing in crypto assets)
Valid responses: 293
Conducted by: Clabo Inc.

Survey Questions

  • Have you ever used virtual currency (crypto assets)?
  • Have you set up 2FA (two-factor authentication) on your crypto exchange or wallet?
  • What are your reasons for not setting up 2FA? (Select all that apply)
  • What was your main reason for deciding to set up 2FA? (Select all that apply)
  • How anxious do you currently feel about not having 2FA set up?
  • Besides 2FA, what other security measures do you take for your crypto assets?
  • Which best describes your crypto investment experience?
  • Which best describes your current crypto investment amount?
  • Where do you primarily get information about crypto assets and security?
  • What kind of information about 2FA would make it easier for you to set it up?

This article is for informational purposes only and does not constitute financial or investment advice. Please consult a qualified professional before making investment decisions.