Phone only
How to buy bitcoin on a phone
You do not need a computer. The entire process works on a phone, and the identity check is usually easier there because the camera flow is smoother. The one genuinely awkward part is two-factor when the phone is your only device.
Yes, all of it. Registration, identity verification, funding, ordering and checking your balance all work on a phone. Most people who buy for the first time do it this way.
The identity check is often easier on a phone, because the document photos and the liveness video use the camera directly rather than asking you to upload files.
App or mobile browser?#
Both work and it is the same account either way. The differences are practical rather than fundamental.
| Official app | Mobile browser | |
|---|---|---|
| Identity check | Smoother — direct camera access | Works, but the camera step is clumsier |
| Risk of a fake | Lower if you install from the official app store | Higher — a wrong address bar is easy to miss on a small screen |
| Notifications | Can alert you to security events | None |
| Storage | Takes space | Nothing to install |
Our suggestion: use the app for verification, and either afterwards. The camera flow is the one place where the app is meaningfully better.
Installing without getting the wrong thing#
App stores contain lookalikes. Three checks before you tap install:
-
Search the store yourself
Do not follow a link to an app listing. Open the store and search inside it.
-
Check the developer name
Not the app name — the developer line underneath. Clones copy the name and the icon; the developer field is harder to fake convincingly.
-
Check the download and review count
The genuine app from a major exchange has millions of downloads and years of reviews. A clone has thousands and a short history.
Because of app-store restrictions in some regions, major exchanges do distribute an Android installer (an .apk) from their own domain. So “never install an APK” is too blunt to be useful — the real distinction is where it came from.
Fine: an installer from the official domain you typed in yourself, or the app from your phone’s official store.
Not fine, ever: an installer from a link somebody sent you, from a search ad, from a tutorial site, or from any third-party download mirror — however convincingly it is framed as “the official build for your region”. The same goes for anything asking you to install a “configuration profile”.
Because a malicious build is indistinguishable from the real one once installed, the domain check is the whole defence here.
The flow on a phone#
Same eight stages as the full walkthrough, with these phone-specific notes:
-
Registration
Watch the country-code dropdown if you register by phone number — on a small screen it is easy to leave it on the default. This is the most common cause of a code that never arrives.
-
Identity verification
Do this in daylight near a window. Put the document on a table rather than holding it — hand-held photos are where fingers cover corners and shadows appear. Grant camera permission when asked; refusing it silently breaks the liveness step.
-
Security setup
Do this before funding. See the section below for the one-device problem.
-
Funding
Bank transfers usually mean switching to your banking app and back. Copy the reference the platform gives you and paste it rather than retyping — and put nothing else in the reference field.
-
Ordering
The one real hazard is the small screen. See small-screen traps.
Two-factor when the phone is your only device#
This is the genuinely awkward part, and most guides skip it.
The standard advice is to use an authenticator app rather than SMS, and that advice is right. But if your only device is the phone, then the exchange app and the authenticator app are on the same device — and if you lose the phone, you lose both at once.
Losing access to two-factor is one of the more common ways people lose an account permanently. Recovery is possible but slow, and sometimes it is not possible at all.
What actually helps, in order of how much:
- Write the backup codes on paper. When you set up two-factor you are shown a recovery key or a set of backup codes. Write them down and put them somewhere physical. This single step solves most of the problem.
- Do not only screenshot them. A screenshot lives in the photo library on the same phone you might lose, and photo libraries sync to cloud accounts that can themselves be compromised.
- Use an authenticator that supports its own encrypted backup, if you are comfortable with that trade-off. It means recovery is possible from a new device, at the cost of trusting that backup.
- Bind your phone number as well as the app. Two independent channels means a problem with one still leaves you a route.
Using SMS-only two-factor is still considerably better than no two-factor. If the authenticator app genuinely will not work for your situation, do not let that become a reason to skip the step entirely.
Small-screen traps#
Three things go wrong on phones specifically, all for the same underlying reason: less is visible at once.
-
Landing on the derivatives screen without noticing
On desktop the leverage controls are visible alongside everything else. On a phone, tabs are compressed and you can be one tap away from a futures screen that looks superficially similar. Check for a leverage multiplier before you enter any amount — see the first common mistake.
-
Mis-typing the amount
Number keypads with no visual grouping make an extra zero easy to miss. Read the total back before confirming, not just the amount you typed.
-
Not seeing the full address bar
Mobile browsers truncate URLs. A phishing domain can be hidden past the edge. If you are in a browser rather than the app, tap the address bar to expand it and read the end of the domain.
Common questions#
Is buying on a phone less secure than on a computer?
Not inherently. A phone that is up to date, locked with a passcode, and only running apps from the official store is a reasonable environment. The bigger risks — phishing links and fake support — apply equally on both.
Can I start on a phone and finish on a computer?
Yes. It is the same account and it syncs. Many people verify on the phone because of the camera, then use a browser afterwards.
The camera will not open during verification.
Camera permission was declined at some point. Grant it in your phone’s settings for that app or browser, then restart the verification flow.
Should I use my phone’s fingerprint or face unlock for the app?
It is a reasonable convenience, but treat it as a replacement for typing your password — not as a replacement for two-factor. Keep two-factor on regardless.
Last updated: 25 August 2026. App interfaces change frequently — where this page and your screen disagree, trust your screen, and please tell us. Not investment advice.
Related
- The full walkthrough All eight stages in order
- The verification code never arrives Including the country-code trap
- Verification keeps failing Fixes by error message