Skip to content
Saturday, August 22, 2026 · Global Edition
L4 News
BLOCKCHAIN · WEB3 · ASSETS
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
security

What is a SIM swap attack, and how does it drain a crypto wallet?

A SIM swap hijacks your phone number, not your seed phrase — but for accounts protected only by a text message, that's often enough to unlock everything.

What is a SIM swap attack, and how does it drain a crypto wallet?

A SIM swap attack is when a criminal tricks or bribes a mobile carrier into moving your phone number onto a SIM card the criminal controls. Once that happens, they receive your calls and texts — including the one-time codes used to reset passwords and log into crypto exchanges and email accounts. It's a real and growing way crypto gets stolen, and it works even if you never click a bad link.

How does a SIM swap attack actually work?

A SIM swap doesn't touch your phone directly. An attacker contacts your mobile carrier posing as you, asking for your number to be moved to a new SIM card, or bribes an employee to move it for them. The moment the transfer goes through, your phone loses signal, and every call or text meant for your number now reaches the attacker's device instead.

According to the FBI's Internet Crime Complaint Center (IC3), attackers pull this off three main ways. The first is social engineering: calling carrier support and impersonating the victim using personal details gathered from data breaches or social media. The second is an insider threat — paying a carrier employee to make the swap directly, no impersonation needed. The third is phishing: tricking the victim into installing malware or handing over account credentials that make the switch easier to push through.

Why does a stolen phone number put a crypto wallet at risk?

Because so many accounts still treat "whoever controls this phone number" as proof of identity. A crypto exchange login, a linked email account, or a "forgot password" flow that texts a one-time code all assume the code reaching that number is reaching you. A SIM swap breaks that assumption completely, and the attacker never needs your password to start — they can often generate a new one themselves.

From there, the path to an exchange account is direct: reset the account password using the hijacked phone number or a linked email that uses the same number for its own recovery, approve the SMS-based login code, and withdraw. A wallet held on an exchange, secured only by a password and a text message, is exposed the moment the number moves. A wallet where the private keys live offline, on hardware the attacker never touches, is not.

How much has SIM swapping actually cost people?

IC3 data shows the losses climbing fast. Between 2018 and 2020, the bureau logged 320 SIM-swapping complaints totaling about $12 million in losses. In 2021 alone, that jumped to 1,611 complaints and more than $68 million lost — a roughly fivefold increase in a single year, based on reports from victims in the United States. Those figures cover reported cases only; the bureau has said actual losses are likely higher, since not every victim files a complaint.

Is SMS-based two-factor authentication safe to use?

It's better than no second factor at all, but it's the weakest common option because it depends on something — your phone number — that can be moved without your consent. The National Institute of Standards and Technology (NIST) defines multi-factor authentication as combining at least two of three kinds of evidence: something you know, like a password; something you have, like a physical device; and something you are, like a fingerprint. NIST recommends using MFA "whenever possible, especially when it comes to your most sensitive data — like your primary email, your financial accounts, and your health records."

A text message sits in an awkward spot: it counts as "something you have," but only for as long as the number stays yours. The FBI's own recommendation points away from it directly, urging people toward multi-factor authentication that relies on biometrics or a physical security key instead of a code sent by text — precisely because a phone number can be reassigned by someone else's phone call to a carrier, not just yours.

What actually protects a crypto wallet from a SIM swap?

No single step makes an account swap-proof, but a few choices remove the phone number from the equation entirely.

Protection methodExposure to a SIM swap
SMS text codes as the only second factorHigh — the code goes straight to the attacker's SIM
Authenticator app (codes generated on the device, not sent by text)Low — tied to the physical phone, not the phone number
Physical security keyVery low — requires the physical key in hand
Self-custody hardware wallet holding the private keysVery low for the wallet itself — a stolen number can't sign a transaction it never sees

For exchange accounts, that means switching from SMS codes to an authenticator app or a physical security key wherever the exchange allows it, and asking the mobile carrier to add a port-out PIN or account lock that a phone call alone can't bypass. IC3 also recommends limiting how much financial information gets shared on social media, since attackers use those details to sound convincing to carrier support, and using unique, complex passwords so one leaked password can't be reused against an email or exchange login.

Self-custody isn't a shortcut around all risk, either. Moving funds off an exchange into a wallet you control removes the SIM-swap path, but it shifts responsibility onto keeping the seed phrase and hardware device safe — lose both of those, and the funds are just as unreachable.

What should you do if you think you've been SIM swapped?

Act on the phone losing service, not just on a suspicious message. If your phone suddenly shows no signal or "SOS only" and you didn't change carriers or devices, call your carrier from another line immediately to ask whether a SIM swap was requested, and have them lock the account. Then log into any exchange, email, or financial account tied to that number from a trusted device, change the passwords, and switch on non-SMS multi-factor authentication.

The Federal Trade Commission's identity-theft resources point victims toward filing a report through the agency's official complaint system, which can support a police report and any bank or exchange fraud claim. IC3 collects reports the same way, through ic3.gov, and both agencies use aggregated reports like these to track how the scam is evolving.

For a related crypto news perspective, read What is a pig butchering scam, and how does it target crypto newcomers?.

Rekha Patel

Independent editorial contributor focused on agriculture, food production, rural business, sustainability.

Rekha Patel follows the seasonal work behind agriculture, farm technology, and the products that eventually reach a shelf.

More about Rekha Patel

Sources

  1. FBI Internet Crime Complaint Center (IC3), Public Service Announcement I-020822-PSA
  2. FBI Internet Crime Complaint Center (IC3), Public Service Announcement I-020822-PSA
  3. National Institute of Standards and Technology (NIST), "Back to Basics: Multi-Factor Authentication (MFA)"
  4. Federal Trade Commission, "Identity Theft and Online Security"