Add two-factor authentication
Worth it the moment your app holds anything people care about.
Add optional two-factor authentication. Stack: <stack>. - Use TOTP (an authenticator app) rather than SMS. Say why in one line so I can explain it to users. - Enrolment: show a QR code and the secret as text, then require a correct code before it's switched on. Never enable it on the strength of the QR being displayed. - Recovery codes, generated once, shown once, stored hashed. - Allow a small time window either side for clock drift. Say how much. - Reject reuse of a code within its window, so a captured code is useless. - Rate limit verification attempts. Then: what's my process when someone loses both their phone and their recovery codes?
Answer the lost-everything question before you launch this. Without a process, two-factor turns a support request into a permanently locked account.