How SIM swapping can lead to crypto losses
A strong defense starts with a properly backed-up seed phrase, but that does not protect an exchange account. The fraudster first targets the mobile number. They persuade the carrier to transfer the line, exploit a portal or corrupt an intermediary. The victim’s phone then loses network access while the new SIM receives calls and SMS messages.
With control of the number, the attacker looks for associated services. Data leaks, public profiles and old emails help identify the platform being used. The attacker initiates a password reset, intercepts the SMS code and then attempts to change the authentication method and withdrawal address.
Email often plays a central role. If the account also uses SMS as a recovery method, taking control of the number can open several doors. The fraudster may then delete alerts or create forwarding rules to conceal their actions.
A properly protected non-custodial wallet does not depend on a phone number to sign a transaction. However, a mobile application may contain the seed, a cloud backup or a recoverable access code. SIM swapping can therefore serve as a starting point rather than a direct cryptographic key.
Warning signs that require an immediate response
A sudden loss of network service is the best-known warning sign. The phone displays “no service” even though coverage is normal in the area and other subscribers are connected. Restarting the device does not help. In this situation, do not wait several hours before contacting the carrier from another device.
Unexpected password-reset emails, notifications about password changes or 2FA codes received without any action also indicate an attempted takeover. An alert about a newly added device or API key warrants the same urgency.
On a crypto platform, monitor address changes, pending withdrawals, the disabling of an authentication factor and the creation of a whitelist. Some services impose a delay after a security change. That delay can save the funds if the user reacts quickly enough.
Missing messages do not clear the account. Access to the email account allows an attacker to delete alerts. From a secure device, check active sessions, login history, forwarding rules and recognized devices.
Why SMS is not enough as a second factor
SMS adds a barrier compared with a password alone, but it depends on administrative control of the phone number. Someone who persuades the carrier can receive the codes without possessing your phone. Weaknesses in telecom networks and support procedures increase this risk.
CISA notably recommends FIDO keys and a carrier-account PIN to reduce exposure to SIM swapping. A FIDO2/WebAuthn security key is more resistant to phishing because it verifies the domain before approving the login. A fraudster cannot copy a code and replay it on a fake website.
A TOTP app generates codes locally and avoids transmission by SMS. It remains vulnerable to real-time phishing: the user may enter the code on a fake page that immediately forwards it. A FIDO key therefore offers stronger protection when the service supports it.
Passkeys are another option tied to a device or secure manager. Their recovery process requires careful review. If the cloud account synchronizing the passkeys still depends on the compromised number, the benefit is reduced.
Lock down your mobile carrier account
Request a separate PIN or password for any change to the line. Avoid a code based on a date of birth or public information. Some carriers offer a “port freeze,” a transfer block or enhanced verification in-store.
Remove weak security questions when an alternative is available. A maiden name, school or place of birth can sometimes be found in compromised databases. A unique, non-reused secret phrase reduces this risk.
Check who is authorized on a family or business account. A poorly protected secondary account holder may enable changes to the primary line. Companies should document who can order an eSIM, replace a device or contact support.
Using a less exposed number for sensitive accounts can limit targeting. This line should not appear on social media, public listings or commercial forms. It does not replace strong authentication, however.
Secure your email before your crypto platform
Start with a long, unique password stored in a reputable manager. Enable a security key or passkey, then remove SMS as a recovery method when the provider allows it. Keep backup codes offline in a protected location.
Review your recovery addresses. An old, forgotten email account may provide a weaker route in. Also check third-party applications, app passwords, sessions and automated rules.
A dedicated address for financial services reduces exposure. It should not be used for newsletters, forums or minor registrations. Its name should not exactly reproduce your public identity.
A password manager also helps detect a spoofed domain: it will not fill in credentials on a different address. This protection complements manual URL checks but does not replace them.
Strengthen an exchange account
Enable the strongest factor available. A physical FIDO key, ideally with two copies stored separately, provides a solid foundation. If the platform only offers TOTP, protect the app and store its recovery key away from the primary phone.
Create a withdrawal-address whitelist and impose a delay on any change. Add an anti-phishing code to emails if the exchange offers one. Disable unused API keys and limit the permissions of those that remain.
Funds intended for savings do not need to remain on a platform. Withdrawing to a wallet controlled by the user reduces exposure through the account, but transfers responsibility for the keys. The criteria for choosing a crypto platform also help assess the protections available before leaving significant amounts there.
Do not keep backup codes in the same email account as your alerts. Also avoid taking a screenshot saved in a synchronized gallery. A paper copy or encrypted offline storage limits simultaneous compromise.
What to do during an attack
Call the carrier immediately from another phone. Request that the line be frozen, the transfer canceled and a fraud note added to the account. Record the time, case number and identity of the service representative contacted.
Using a trusted device and secure network, change the password for the primary email account. Revoke sessions, remove unknown rules and replace recovery methods. Then move on to financial platforms according to the urgency of the accessible assets.
Contact the exchange through its official channel, never through a private message received after a public post. Request a withdrawal freeze and provide the requested evidence. Legitimate support will never ask for a seed phrase or a “verification” transfer.
If a non-custodial wallet may be compromised, transfer the funds to a wallet created on a clean device with a new seed. This operation should avoid addresses provided by a stranger. For a multisig wallet, follow the planned rotation procedure.
Keep emails, SMS messages, screenshots, TXIDs, addresses, login logs and communications with the carrier. Report the incident to the relevant authorities. A confirmed transaction generally cannot be reversed, but the evidence can support an investigation and help identify a route through a regulated platform.
False solutions to avoid
Changing only the exchange password is not enough if the email account and phone number remain compromised. Restoring the line without replacing recovery methods also leaves a door open. The response must cover the entire identity chain.
A VPN does not block SIM swapping. It protects part of the network traffic, not the administrative transfer of a phone number. An authentication app installed on the same compromised device may also lose its advantage.
Increasing the number of SMS alerts does not provide structural security. When the attacker controls the line, they receive those messages themselves. Prefer notifications sent through several independent channels.
Finally, immediately publishing every detail on social media can help the fraudster and attract fake support agents. Share the information first with the carrier, platforms and authorities, then communicate without revealing recovery details.
Build lasting protection
Keep two FIDO keys: a primary key and a backup. Test them without deleting the previous method until confirmation. Store recovery codes in two separate physical locations.
Schedule a quarterly review of sessions, authentication factors, whitelists and recovery details. A change of phone, carrier or colleague should trigger an immediate review.
For a team, separate the person who initiates a withdrawal from the person who approves it. Use multiple named accounts rather than a shared login. Reading smart contract permissions also supports this governance for wallets that interact with decentralized applications.
Security should never depend on a single barrier. The carrier lock slows the transfer, the FIDO key protects the login, the whitelist limits withdrawals and the non-custodial wallet removes some funds from the account. Even if one layer fails, the others should preserve time and reduce the damage.
SIM swapping primarily exploits account recovery and urgency. Treat an unexplained loss of network service as an incident, contact the carrier immediately, then secure the email account and platforms. Over the long term, remove SMS from critical access, compartmentalize identities and test your procedures before you need them.