Why Anyone Would Steal a Reddit Account
It sounds odd until you see the market: aged Reddit accounts with karma sell openly to spammers, because Reddit's filters trust accounts with history. Stolen accounts push crypto scams, astroturf product reviews, and manipulate votes. Moderator accounts are bigger prizes: one hijacked mod can deface a community of millions. And since most people reuse passwords, Reddit accounts fall constantly to credential stuffing replays of old breach data.
How to Turn On Reddit 2FA
On the website:
- Log in and click your avatar → User Settings.
- Open the Safety & Privacy tab (or Account, depending on layout).
- Find Use two-factor authentication and toggle it on.
- Confirm your password.
- Reddit shows a QR code. Scan it with any authenticator app (Google Authenticator, Authy, Aegis, 2FAS).
- Enter the six digit code to confirm.
In the mobile app: tap your avatar → Settings → Account Settings → Two-factor authentication.
Save the Backup Codes
Right after setup, Reddit displays backup codes: single use codes for the day your phone is gone. Download or copy them into your password manager now, because Reddit shows them exactly once at full convenience (you can regenerate later, but only while logged in). Our storage guide covers where they should live.
Reddit only supports authenticator apps for 2FA, not SMS. Unusual, and actually good: it means the weakest 2FA method isn't even an option. If you want to know why that's a feature, read our SMS 2FA breakdown.
What the QR Code Contains (For the Curious)
Reddit's setup QR is a standard otpauth URI holding a Base32 secret: the seed from which every future code grows. You can inspect any setup QR with our QR decoder, and watch a secret generate live codes in our free TOTP generator. Treat screenshots of that QR like a password: anyone holding it can clone your codes.
For Moderators: Extra Duty of Care
- Every mod of your subreddit should have 2FA. One unprotected mod account is the whole community's weak point. Reddit lets you require it: check your subreddit's moderator requirements.
- Audit your mod list for inactive accounts: dormant mods with old passwords are the favourite entry point.
- Check app authorizations (Settings → Privacy → Manage third-party app authorization): old bots and tools with account access accumulate over years.
Round Out Your Reddit Security
- Verify your email address. Unverified accounts are nearly impossible to recover.
- Unique password, rotated if it ever appeared in a breach: generate one with our password generator and check your exposure at haveibeenpwned.com. Post-breach steps live in our breach response plan.
- Watch for fake Reddit login pages linked from DMs ("you've been reported, appeal here"). The domain is the tell: our phishing guide trains the eye.
Frequently Asked Questions
I lost my authenticator and backup codes. Can Reddit help?
Reddit's help center has a 2FA lockout form, and recovery requires proving ownership through your verified email. It can take a while and isn't guaranteed, so backup codes remain the reliable path. If you still have a logged in session anywhere (old browser, app), use it now to disable and re-enable 2FA.
Does 2FA log me out of my devices?
No, existing sessions continue. If you're enabling 2FA because something felt off, also change your password, which does revoke other sessions.
Can I use 2FA on multiple Reddit accounts?
Yes: each account gets its own entry in your authenticator app. If you run alt accounts, protect them all: spammers love a forgotten alt with a reused password.
Why does Reddit reject my six digit code?
Almost always phone clock drift: TOTP codes depend on accurate time, so set date and time to automatic. Also make sure you're reading the entry labelled Reddit for the right username. Full troubleshooting in our code invalid guide.
Does old.reddit.com support 2FA logins too?
Yes: 2FA applies to your account regardless of which interface you log in through, including old Reddit, the apps, and third party clients using official login.