Wallet safety / Updated 2026-07-23

SIM-Swap Attacks: When Your Phone Number Becomes the Key to Your Crypto

A SIM-swap attack hijacks your phone number to defeat SMS codes and reset your crypto accounts. Learn how it works and how to move off SMS 2FA before it happens.

How this guide is checked

Official sources first, no wallet connection, no guaranteed returns.

Reviewed on 2026-07-23 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.

Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.

SIM swap crypto matters because Your exchange login feels safe because a code texts to your phone. A SIM-swap attack is the quiet method that turns that same phone number against you.

This guide explains how attackers steal your number, why SMS codes fail, and the concrete upgrades that make the attack far harder to pull off.

You will learn what a SIM swap is, why crypto accounts are prime targets, and how to move to app-based and hardware two-factor authentication.

What is a SIM-swap attack?

A SIM swap — also called SIM hijacking or a port-out scam — is when an attacker convinces your mobile carrier to move your phone number onto a SIM card they control. They do not touch your physical phone; they impersonate you to the carrier using personal details gathered from data breaches and social media, or in some cases bribe or trick a carrier employee. Once the number is theirs, your phone silently loses service and every call and text meant for you now arrives on their device.

That matters because so many accounts treat your phone number as proof of identity. Text-message two-factor codes, 'forgot password' resets sent by SMS, and account-recovery flows all assume that whoever receives the text is you. When the attacker controls your number, they receive those codes and reset links, and they can walk straight into your email, then into anything your email can reset — including crypto exchange accounts.

The FBI's Internet Crime Complaint Center has flagged SIM swapping specifically as a technique criminals use to reach 'bank accounts, virtual currency accounts, and other sensitive information,' reporting 1,611 complaints with more than $68 million in losses in a single year, up sharply from earlier periods. It is not an exotic threat; it is a well-worn playbook.

Checklist

  • A SIM swap moves your phone number to an attacker's SIM.
  • It uses impersonation, breached data, or a bribed insider.
  • Your phone quietly loses service when it happens.
  • The attacker then receives your SMS codes and reset links.

Why crypto accounts are a prime target

Attackers follow irreversibility. When they drain a bank account, there is a chance of reversal, holds, and clawbacks. When they move crypto out of an exchange or wallet, the transfer is final and the funds are pseudonymous, which makes recovery extremely difficult. That asymmetry is why crypto holders are singled out for SIM swaps: the payoff is large and, once taken, largely permanent.

The typical chain runs through your email. The attacker takes your number, uses SMS recovery to reset your email password, then uses your email to reset or approve access to your exchange account — often defeating SMS-based two-factor along the way because those codes now come to them. The FTX case that security researchers dissected showed how a coordinated SIM swap can precede a large crypto theft, and civil cases have gone further: in 2025 an arbitrator ordered a major carrier to pay a multi-million-dollar award after finding that weak authentication 'enabled the theft of cryptocurrency.'

The lesson is not that phones are dangerous but that a phone number is a fragile foundation for high-value security. It was designed to route calls, not to guard savings. Any crypto account that can be accessed or recovered through a text message inherits the weakness of the carrier's willingness to move that number — a decision made by a customer-service rep you will never meet.

Move off SMS: the upgrades that matter

The single highest-impact change is to stop relying on text-message codes for anything valuable. Replace SMS two-factor authentication with an authenticator app (such as the TOTP codes generated by apps like Aegis, Google Authenticator, or a password manager's built-in authenticator), which generates codes on your device and does not depend on your phone number at all. For your most important accounts — primary email and any exchange — go a step further with a hardware security key using the FIDO2 standard, which is the strongest widely available option because the login is cryptographically bound to the physical key and cannot be phished or intercepted by a stolen number.

Then harden the phone number itself so it is harder to steal in the first place. Call your mobile carrier and add a port-freeze or number-lock plus a separate account PIN or passcode required for any SIM change — protections that U.S. carriers are now required to offer under FCC rules adopted specifically to curb SIM-swap and port-out fraud, which also require carriers to notify you immediately when a SIM change is requested. Remove your phone number as a recovery method on critical accounts wherever the platform allows an app or key instead, so a stolen number no longer unlocks anything.

Finally, reduce the raw material attackers use. The personal details that let someone impersonate you to a carrier come from breaches and oversharing, so be sparing about posting your phone number and answers to common security questions publicly. None of this is financial advice; it is account hygiene that lowers the odds that your number — and the accounts chained to it — can be taken by a stranger on the phone.

Checklist

  • Replace SMS codes with an authenticator app on every valuable account.
  • Use a FIDO2 hardware security key for email and exchange logins.
  • Add a carrier port-freeze and a separate account PIN.
  • Remove your phone number as a recovery option where you can.
  • Turn on alerts for logins and withdrawals.

Warning signs and what to do if it happens

A SIM swap in progress has a distinctive symptom: your phone abruptly loses all cellular service — no calls, no texts, no data — often with a 'no SIM' or 'SOS only' indicator, even though you are in a normal coverage area and did nothing to your device. You may also get a carrier notification about a SIM change or port-out you did not request, which the FCC now requires providers to send. Treat any of these as a possible attack, not a glitch, especially if it happens alongside unexpected password-reset emails.

If you suspect it is happening, move fast on a different device or connection. Contact your mobile carrier immediately to report the swap and reclaim your number, then, from a device you trust, change the passwords on your email and financial accounts and revoke active sessions. Prioritize your primary email first, because it is the master key that most other resets flow through. Where you can, freeze withdrawals or add holds on exchange accounts while you regain control.

Afterward, report the incident to the FBI's IC3 and the FTC, and assume the attacker gathered whatever your accounts exposed. Rebuild your two-factor setup on app-based or hardware methods rather than restoring SMS, so the same door does not reopen. As with every crypto loss, ignore anyone who surfaces afterward promising guaranteed fund recovery for a fee — that is a predictable second scam, not a rescue.

Authority sources used

Outbound links are included for verification and entity authority, not decoration.

FAQ

Is text-message (SMS) two-factor authentication better than nothing?

Yes — SMS two-factor is meaningfully better than a password alone, and you should not turn it off if it is the only second factor an account offers. It stops casual attackers who have only your password. The important caveat is that SMS is the weakest form of two-factor because it depends on your phone number, and a SIM-swap attacker who hijacks that number receives your codes directly, bypassing the protection entirely. So the right framing is a ladder, not on-versus-off: SMS beats nothing, an authenticator app beats SMS because it is tied to your device rather than your number, and a FIDO2 hardware security key beats an app because the login is cryptographically bound to a physical key that cannot be phished or intercepted. For your highest-value accounts — primary email and any crypto exchange — climb as high up that ladder as the platform allows, ideally to a hardware key. Keep SMS enabled only where no stronger option exists, and remove your phone number as a recovery method wherever an app or key can replace it.

How would I know a SIM swap is happening to me?

The clearest sign is a sudden, unexplained loss of all cellular service on your phone — no calls, texts, or mobile data, sometimes showing 'no SIM' or 'SOS only' — while you are in an area with normal coverage and did nothing to your device. That happens because when your number is moved to the attacker's SIM, your own SIM stops working. You may also receive a message from your carrier about a SIM change, port-out request, or account update you did not initiate; U.S. carriers are now required to send such notifications. Another red flag is a wave of password-reset or login-alert emails you did not request, which can indicate an attacker using your hijacked number to reset accounts. If you notice any of these, especially in combination, treat it as a possible attack rather than a technical glitch: contact your carrier immediately from another phone or connection to check and reclaim your number, and from a trusted device start changing passwords on your email and financial accounts, beginning with your primary email.

Can a SIM swap drain a self-custody wallet, or only exchange accounts?

The direct risk is greatest for accounts that use your phone number for login or recovery — primarily exchange accounts, along with the email that can reset them — because those are what a stolen number unlocks. A true self-custody wallet, where you alone hold the seed phrase, is not accessed by a text-message code, so a SIM swap by itself cannot move those funds; the attacker would still need your seed phrase or private keys. That is one of the real security advantages of self-custody. The caveat is that a SIM swap often leads to a broader compromise: once attackers own your email, they can hunt for anything you stored insecurely, including a seed phrase saved in email, cloud notes, or a photo — which is exactly why those should never live in synced digital storage. So the honest answer is that a SIM swap primarily threatens phone-number-linked accounts, but its downstream access to your email can expose a carelessly stored recovery phrase. Keep seed phrases strictly offline, and the SIM-swap path to your self-custodied funds stays closed.

What is the difference between an authenticator app and a hardware security key?

Both are stronger than SMS because neither depends on your phone number, but they differ in how they resist attacks. An authenticator app generates time-based codes (TOTP) directly on your device, so a SIM-swap attacker who steals your number never receives them — a major improvement over SMS. Its remaining weakness is phishing: if a fake login page tricks you into typing your current code, an attacker can relay it in real time. A FIDO2 hardware security key closes that gap. It is a small physical device you tap or plug in, and the login is cryptographically tied to the real website's address, so it simply will not authenticate to a lookalike phishing site, and there is no code to type or intercept. For that reason a hardware key is the strongest widely available second factor and is well suited to protecting a primary email account and a crypto exchange login. A practical setup is to use a hardware key on your most valuable accounts and an authenticator app everywhere else, keeping SMS only where nothing better is offered.

How do I make my phone number harder to steal in the first place?

Call your mobile carrier and ask for the specific anti-SIM-swap protections they are now required to offer: a port-freeze or number-lock that blocks your number from being moved to another SIM or carrier without extra verification, plus a separate account PIN or passcode that must be provided for any change to your account. Confirm that the carrier will notify you immediately if a SIM change or port-out is ever requested, a safeguard mandated by FCC rules adopted to curb this exact fraud. Beyond the carrier, shrink the personal information attackers use to impersonate you: avoid publicly posting your phone number, and do not use guessable answers to security questions that appear in data breaches or on your social media. Then reduce your number's power by removing it as a login or recovery method on critical accounts wherever an authenticator app or hardware key can take its place, so even a successful swap unlocks less. None of these steps is foolproof alone, but together they make you a much harder and less rewarding target.