Attacks
Somebody moves your phone number to their SIM, then resets everything that trusts your number. An attacker convinces your mobile carrier to port your number to a SIM they control, sometimes by social engineering a support agent and sometimes by paying an employee. Once they have the number they receive your SMS codes, which is enough to reset passwords and drain accounts on any exchange that trusts SMS two factor.
What it is
An attacker convinces your mobile carrier to port your number to a SIM they control, sometimes by social engineering a support agent and sometimes by paying an employee. Once they have the number they receive your SMS codes, which is enough to reset passwords and drain accounts on any exchange that trusts SMS two factor.
How it plays out
They gather your details first
From breaches, from your social media, and from what you have posted about owning crypto.
They contact the carrier as you
And request a SIM replacement or a port to a new provider.
Your phone loses service
That is the moment it happens, and it is the only warning you get.
They reset accounts
Email first if it uses SMS recovery, then every exchange behind it.
What gives it away
- Your phone loses signal suddenly and stays dead while others nearby work.
- Password reset emails you did not request.
- Being unable to log in to an account that worked yesterday.
How to not be caught by it
- Move every account off SMS two factor and onto an authenticator app or a hardware key.
- Add a port out PIN or a port freeze with your carrier. Every major carrier offers one.
- Use an email address for exchanges that is not published anywhere and does not use SMS recovery.
- Stop posting about holding crypto under a name and location that can be tied to you.
- Keep meaningful holdings in self custody, so an exchange takeover is not a total loss.
If it already happened
- Call the carrier from another phone and report the SIM swap immediately.
- Lock exchange accounts and withdrawals from a device that is still logged in.
- Change the email password first, then every account that used SMS recovery.
- Report it. SIM swaps are prosecuted and carriers have been held liable.
Common questions
How common is sim swap attacks?
Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.
Can the money be recovered?
Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.
Does a hardware wallet stop this?
It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.
Where to go next
Check your setup before you need to
An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.