A Comprehensive Guide on SIM Swap Attacks on Crypto Community

Introduction to SIM Swap Attacks And Their Relevance In The Crypto Industry
In 2022, a SIM swapper was sentenced to 18 months in prison for stealing more than $20 million in cryptocurrency through a single phone number takeover. No malware, no exchange hack, no cracked password. Just a phone call to a carrier and a convincing enough story.
That is the uncomfortable truth about SIM swapping: it is one of the least technical attacks in the crypto threat landscape, and consistently one of the most devastating. By hijacking your phone number, an attacker inherits every text message and call meant for you, including the one-time codes that banks, exchanges, and wallets treat as proof of identity.
This guide covers how SIM swap attacks work, why crypto holders are disproportionately targeted, what it has actually cost real people and companies, and the specific steps that reduce your exposure. The attack history below runs through 2023; for the latest reported figures, see our SIM swap fraud statistics for 2026.
Key Takeaways
- SIM swapping is not a crypto-only threat. Any account tied to your phone number, including email, banking, and social media, is exposed, not just wallets and exchanges.
- SMS-based two-factor authentication is the weakest widely used form of two-factor authentication, because it depends on the exact thing attackers are hijacking: your phone number.
- Hardware security keys (like a YubiKey) and authenticator apps are not tied to your phone number, which makes them significantly harder for an attacker to defeat than SMS codes.
- Speed matters. The sooner you notice a signal drop or unexpected account activity, the less an attacker can drain before you regain control.
Is your cellphone vulnerable to SIM Swap? Get a FREE scan now!
Please ensure your number is in the correct format.
Valid for US numbers only!
What Is a SIM Swap Attack?
A SIM swap attack is unauthorized access to your mobile number, achieved by convincing your carrier to move that number onto a SIM card the attacker controls. Once that transfer completes, the attacker receives your calls and texts instead of you, which hands them the ability to intercept the SMS codes and callback verifications that protect your email, banking, and cryptocurrency accounts.
Attackers rarely start cold. Most build a profile of the target first: full name, date of birth, billing address, the last four digits of an SSN, answers to common security questions. That information comes from data breaches, social media, phishing, or occasionally an insider at the carrier itself. Armed with it, the attacker contacts the carrier impersonating you and requests the transfer.
The consequences escalate quickly once the number moves. Crypto wallets secured only by SMS-based two-factor authentication are the most common casualty, but email and social accounts tied to the number are just as exposed.
How a SIM Swap Attack Actually Unfolds
The mechanics are consistent across almost every reported case, which is exactly what makes the attack repeatable at scale.
1. Hackers gather personal information. The attacker compiles enough identifying detail, often from leaked credential databases or public social profiles, to pass a carrier's identity check.
2. They target the mobile carrier. Posing as you, the attacker contacts your carrier (by phone, chat, or occasionally with help from a compromised insider) and requests that your number be ported to a new SIM.
3. Your SIM card is deactivated. Once the carrier approves the request, your existing SIM loses service. This is usually the first visible sign something is wrong: calls and texts simply stop arriving.
4. The replacement SIM goes live. The attacker's new SIM activates with your number attached, giving them your incoming calls and texts from this point forward.
5. They take over your accounts. With SMS-based verification now routing to them, the attacker resets passwords and bypasses two-factor authentication on email, exchange, and banking accounts tied to that number.
6. They move fast on the payout. Because victims typically notice within hours, attackers prioritize draining hot wallets and exchange balances immediately, often before the victim has finished getting the carrier back on the phone.
Why Attackers Target Crypto Holders Specifically
The primary driver is financial: a successful SIM swap can hand an attacker direct access to exchange accounts and wallets, and unlike a bank wire, a completed crypto transaction cannot be reversed or clawed back. That asymmetry, instant and irreversible payout against a relatively low-effort attack, is what makes crypto holders a preferred target over, say, a typical retail banking customer.
A second motive is identity theft and extortion: the same number gives access to email and social accounts, which attackers use to impersonate the victim, run follow-on scams against their contacts, or hold accounts for ransom.
A smaller but more alarming category is targeted surveillance against executives, founders, and public figures in the crypto industry, where the goal is reading private communications or hijacking an influential account rather than an immediate payout.
What's Actually at Stake
Financial risk: Direct theft from hot wallets and exchange accounts is the headline risk, but victims also face fraudulent loans or credit opened in their name using the stolen identity information, and the cost of professional help recovering accounts and reporting the incident.
Personal risk: Attackers who hold your number can reset passwords across your digital life, exposing private messages, photos, and contacts, and in targeted cases, using that access to track or harass the victim directly.
Reputational risk: A hijacked social account gets used to run scams against your own followers and contacts. For founders, executives, or anyone with professional visibility, that damage can outlast the financial loss by a wide margin.
How SIM Swap Fraud Has Evolved
Early SIM swaps leaned almost entirely on social engineering a call-center agent. As carriers added friction, attackers adapted.
Insider assistance: Some of the largest reported losses trace back to a bribed or complicit carrier employee who processed the transfer directly, bypassing identity checks altogether.
More convincing social engineering: Attackers now arrive with enough stolen personal data to answer verification questions correctly on the first attempt, rather than guessing or fumbling through the call.
Automation and scale: Rather than hand-picking targets one at a time, some operations run scripted or semi-automated attempts against lists of known crypto holders, treating SIM swapping as a volume business.
Why This Is So Hard to Stop
Low public awareness: Most people still think of phone numbers as a convenience, not a security credential, so they are not watching for the warning signs until service drops unexpectedly.
The attack keeps changing: As one carrier verification method gets hardened, attackers shift to a different weak point, whether that's a different carrier, a different support channel, or a newly leaked data source.
Fragmented response: Carriers, exchanges, and law enforcement each see only a slice of the attack, which slows both detection and prosecution.
Human psychology: Social engineering works because support agents are trained to be helpful under pressure, and a confident, well-prepared attacker can exploit that far more reliably than any technical exploit.
Why Crypto Users Specifically Are Exposed
Irreversibility: Once a crypto transaction confirms, there is no bank to call for a reversal. That finality is the whole point of the technology, and exactly what makes a successful attack so costly.
Heavy reliance on the phone: Exchanges and wallet services lean on SMS-based two-factor authentication precisely because it is convenient, which is also what makes a hijacked number so valuable to an attacker.
An awareness gap: Many holders secure their seed phrase carefully but never consider that their phone number is an equally critical piece of their security stack.
Rising asset values: As portfolios grow, so does the incentive for an attacker to spend real effort profiling a specific, high-value target rather than attempting a scattershot approach.
SIM Swap Protection
Get our SAFE plan for guaranteed SIM swap protection.
A Timeline of High-Profile Crypto SIM Swap Attacks
The incidents below are drawn from public reporting, court filings, and victim accounts between 2017 and 2023. They are not a complete record, but they illustrate how consistently the same attack pattern has worked against targets ranging from individual investors to venture firm co-founders. For more recent, statistics-level data, see our dedicated SIM swap fraud statistics page for 2026.
Four Cases Worth Reading in Full
Blockchain Capital co-founder, $6.3 million (August 2023)
Bart Stephens, co-founder of venture firm Blockchain Capital, filed a legal complaint alleging a SIM swap attack drained at least $6.3 million in Bitcoin, Ethereum, and other tokens from his hot wallet. According to the complaint, the attacker used personal information sourced online and from the dark web to get his carrier to reassign his number, then reset his wallet credentials. A vigilant colleague stopped a second, larger attempt on his cold storage before it succeeded. His carrier reportedly notified him of the SIM swap a full day after the theft had already happened.
A coordinated takeover ring targeting crypto accounts on X (mid-to-late 2023)
Blockchain investigator ZachXBT linked more than eight account takeovers, including crypto creator Cole (@ColeTherium), to a single group using SIM swaps to hijack X accounts and push fake token airdrops. The same group was tied to attacks on Ben "Bitboy" Armstrong, Mira Murati, Peter Schiff, and Steve Aoki. In Cole's case, the attacker convinced AT&T to transfer his number, used the hijacked account to promote a fake token, and the group's broader campaign is estimated to have moved close to $1 million in stolen assets.
Vitalik Buterin's X account (September 2023)
Ethereum co-founder Vitalik Buterin's account was compromised and used to post a fake NFT-claim link. ZachXBT estimated roughly $691,000 was drained from users who connected their wallets expecting a legitimate mint, a reminder that even accounts with enormous followings are not exempt.
Michael Terpin, roughly $24 million (2018-2019)
One of the earliest and still largest publicly reported cases: investor Michael Terpin lost roughly 1,500 bitcoin, worth tens of millions at the time, to a SIM swap during the January 2018 price run-up. He later pursued both his carrier and the individual attacker in court; one perpetrator received a three-year sentence in 2019.
Full Incident Timeline
Monthly
Yearly
How to Tell You've Been SIM Swapped
- Sudden, total loss of signal with no explanation
- Login attempts on your accounts that you didn't initiate
- Calls and texts stop arriving, even though your phone shows normal signal strength
- Password reset emails or texts you never requested
- Notifications that your account password or recovery info changed
- Unfamiliar charges or crypto transactions appear
- Your carrier's support line can't explain why service dropped
- Friends report strange messages from your social accounts
- Service works fine for everyone else on your plan except you
Any one of these on its own could be a coincidence. Two or more together, especially a signal drop combined with a password-reset notice, is worth treating as an active attack and acting immediately.
How to Protect Yourself
1. Set a PIN or password on your carrier account. This is the single most effective free step: it adds a second check before anyone, including you, can request a SIM transfer.
2. Use app-based or hardware two-factor authentication. Authenticator apps and hardware keys aren't tied to your phone number, so a SIM swap doesn't automatically defeat them the way SMS codes do.
3. Limit what you share publicly. Birthdates, hometowns, and other 'security question' answers are often sitting in plain sight on social media.
4. Monitor accounts regularly. Catching unauthorized activity within minutes rather than hours materially changes how much an attacker can extract.
5. Treat unexpected messages with suspicion. Phishing is frequently the first step in building the profile an attacker needs to pass your carrier's verification.
6. Use strong, unique passwords everywhere. Credential reuse means one breached site can hand an attacker the keys to accounts that have nothing to do with where the leak happened. A password manager and unique, hard-to-guess passwords close that gap.
7. Stay current on how these attacks evolve. The tactics above work against today's playbook; staying informed is how you keep up as it changes.
8. Move your number to a carrier built around this threat. Efani holds every line behind an 11-layer authentication protocol and a mandatory 14-day cooling-off period before any transfer can complete, backed by $5M in SIM swap coverage on every plan.
9. Watch for the early warning signs above. Speed of detection is often the biggest factor in how much damage an attack actually causes.
What to Do If It Happens to You
1. Contact your carrier immediately. Through an alternate phone, chat, or in person if needed, report the unauthorized transfer and request your number be restored.
2. Change passwords on every connected account. Start with email, since it's usually the recovery path into everything else.
3. Enable app-based MFA wherever you still can. Move away from SMS-based verification the moment you regain access.
4. Notify your bank and any exchanges. Give them the chance to freeze activity before further unauthorized transactions go through.
5. File a police report. This creates an official record, which matters for any later dispute with a carrier, bank, or exchange.
6. Keep monitoring after you regain access. Attackers sometimes leave backdoors, like a newly added recovery email, that aren't obvious at first glance.
7. Share what happened. A clear account of what worked and what didn't helps the next person recognize the pattern faster.
Securing Your Crypto Specifically
- Use app-based or hardware MFA instead of SMS wherever a platform allows it
- Move meaningful holdings into a hardware wallet rather than leaving them on an exchange
- Keep wallet software and firmware current
- Treat unsolicited crypto-related messages as phishing until proven otherwise
- Never reuse passwords across exchanges, wallets, or email
- Check account activity on a regular schedule, not just when something looks off
- Stay current on how SIM-swap and phishing tactics are evolving
- Avoid phone number-based 2FA on any account holding meaningful value
- Consider a separate device used only for crypto activity
Anyone holding a large position should also look at protection purpose-built for high-value targets, which adds specialist escalation on top of these standard controls.
Where This Is Headed
Attacks keep getting more sophisticated: Automation and better-sourced personal data are lowering the effort required for each attempt.
Targeting is expanding beyond high-profile individuals: What started as an attack reserved for the visibly wealthy is increasingly aimed at ordinary holders too.
The problem is spreading globally: As crypto adoption grows in new markets, so does the incentive to target carriers and users there.
The attack surface keeps widening: More services tied to a phone number means more to lose when that number is compromised.
Moving Past SMS-Based 2FA
SMS codes are better than nothing, but they are also the weakest widely used form of two-factor authentication, precisely because they depend on the one thing a SIM swap directly attacks: your phone number. Stronger alternatives include:
- Authenticator apps (Authy, Google Authenticator)
- Hardware security keys (YubiKey and similar)
- A dedicated, non-primary email address used only for recovery
- Cold storage for anything you aren't actively trading
- Biometric authentication where a platform supports it
- Time-based token generators tied to a physical device
Phishing: The Other Half of the Problem
SIM swapping rarely happens in isolation. Most attackers need personal information before a carrier call will succeed, and phishing is one of the most reliable ways to get it. Treat unsolicited messages with suspicion, verify a site's URL character by character before entering credentials, and type addresses directly rather than clicking through links in email or text. Report anything unusual to your carrier immediately rather than waiting to see what happens.
How the Industry Is Responding
Biometric and behavioral authentication: Carriers and platforms are increasingly layering in verification that doesn't rely on something an attacker can simply recite over the phone.
Zero Trust principles: The core idea, verify every request regardless of where it originates, is increasingly being applied to SIM transfer requests specifically, not just corporate network access.
Cross-industry collaboration: Carriers, exchanges, and financial institutions are starting to share intelligence in closer to real time, which shortens the window an attacker has to act before accounts get frozen.
Regulatory pressure: Regulators in multiple markets are pushing carriers toward stricter identity verification before any SIM transfer is approved.
Conclusion
SIM swapping endures because it targets a layer most people never think to defend: the phone number itself. Your seed phrase can be flawless and your exchange password unguessable, and none of it matters if your carrier will hand your number to anyone who tells a convincing enough story.
The good news is that the defense is largely within your control. A carrier PIN, app-based two-factor authentication, and a healthy skepticism toward unsolicited messages close off most of the easy paths an attacker relies on. For anyone holding meaningful value, whether in crypto or otherwise, closing that gap at the carrier level rather than patching around it afterward is the more durable fix. That is precisely the layer Efani is built to protect.
Glossary
SIM Swap Attack: Fraud where an attacker tricks a carrier into moving a victim's phone number onto a SIM the attacker controls.
Two-Factor Authentication (2FA): A login method requiring two different proof factors, typically something you know plus something you have.
Multi-Factor Authentication (MFA): Authentication requiring more than one proof of identity before granting access.
Social Engineering: Manipulating a person, rather than a system, into divulging information or taking an action that compromises security.
Hot Wallet: A crypto wallet connected to the internet, convenient for transacting but more exposed to online attacks.
Cold Storage: Keeping crypto holdings offline, away from internet-connected systems and their associated risks.
Seed Phrase: The word sequence used to back up and restore access to a crypto wallet.
Phishing: A deceptive attempt, usually by email or text, to trick someone into handing over sensitive information.
Zero Trust: A security model that verifies every access request by default rather than assuming trust based on network location.
Port-Out Fraud: A related scheme where a number is fraudulently transferred to a different carrier entirely, rather than a new SIM on the same carrier.
Sources
- ZDNet: FBI warns SIM-swapping attacks are rocketing
- CoinDesk: Friend.tech users targeted by SIM swap attack
- Aon Cyber Labs: A look into recent SIM swap attack trends
- PCMag: FBI sees huge increase in SIM-swapping attacks




