Demo build. This is a software product for sale — not an investment, token sale, or financial service. Coins shown run on testnet and have no monetary value. Buyers are responsible for their own licensing, compliance and any mainnet launch.

Demo pool testnet only no real mining revenue
BTC testnet XMR testnet ETC testnet RVN testnet KAS testnet GCC testnet

2FA setup and recovery codes.

The fastest path from "I have a GPU or ASIC" to "shares are landing" on the testnet demo. Five steps.

01 Why the dashboard requires 2FA

The operator dashboard is the console you run to manage your pool and chain, so it is the account I treat as most worth protecting. Two-factor authentication (2FA) adds a second proof of identity on top of your password, so a leaked or guessed password is not enough to sign in on its own.

The dashboard supports time-based one-time passwords (TOTP) from any standard authenticator app — Google Authenticator, Authy and 1Password all work. Once enrolled, 2FA is required for sensitive actions as well as login: changing payout settings and creating API keys both prompt for a fresh code before they take effect.

02 Enable an authenticator app

Open Settings → Security in the dashboard and choose Enable two-factor authentication. The steps are:

  1. The dashboard shows a QR code and a matching text secret. Open your authenticator app and scan the QR code, or type the secret in by hand if you cannot scan.
  2. Your app starts generating a fresh 6-digit code every 30 seconds.
  3. Enter the current 6-digit code back into the dashboard to confirm the two clocks agree.
  4. Once the code is accepted, 2FA is active on your account.

03 Save your recovery codes

When 2FA is enabled the dashboard issues 10 single-use recovery codes. Each one logs you in once if you ever lose access to your authenticator app, and is then consumed.

  • Store them somewhere you can reach without your phone — a password manager entry, or printed and kept somewhere safe.
  • Do not keep them only on the same device that holds your authenticator app; if you lose that device you would lose both factors at once.
  • Treat each code like a password. Anyone who has one plus your password can sign in.

You can regenerate a fresh set at any time from Settings → Security, which immediately invalidates the old set. Do that if you suspect the codes have been seen by anyone else.

04 Lost your device

If your phone is lost, stolen or wiped, you can still get back in:

  1. At the login prompt, choose Use a recovery code instead of entering a 6-digit code.
  2. Enter one of your saved recovery codes. That code is now spent.
  3. Once you are back in, go to Settings → Security, remove the old authenticator and re-enrol a new one by scanning a fresh QR code on your replacement device.
  4. While you are there, regenerate your recovery codes so any that were stored on the lost device no longer work.

05 Add a hardware security key

For dashboard login you can also register a hardware security key using FIDO2 / WebAuthn — a USB, NFC or platform authenticator (for example a YubiKey, or a built-in fingerprint or face sensor). A hardware key is phishing-resistant: it only responds to the genuine dashboard origin, so it cannot be tricked into authenticating to a lookalike site.

Add one under Settings → Security → Security keys, then follow your browser’s prompt to touch or insert the key. You can register more than one — keeping a backup key is sensible so a single lost key does not lock you out. A registered key can be used in place of a TOTP code at login.