Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileself-custody failures

SIM Swap Attacks and Why SMS Two-Factor Is Not Enough

An attacker convinces your mobile carrier to move your number to their device. Every SMS code you rely on is then theirs.

Priya Raman · 2 min read

This attack does not touch your wallet, your computer or your passwords. It targets the weakest institution in the chain, which is your mobile carrier.

How it works

Step one. The attacker gathers enough personal information to pass a carrier’s identity check. Name, address, date of birth, sometimes the last digits of a payment card. Most of this is available from previous data breaches.

Step two. They contact the carrier, claim to have lost the phone, and request the number be transferred to a new SIM in their possession. Carriers vary enormously in how rigorously they verify this.

Step three. Your phone loses service. This is the only warning you get, and it usually looks like a network problem.

Step four. The attacker requests password resets on your email account. The reset code arrives by SMS, to them.

Step five. With email control, they reset exchange account passwords. SMS two-factor codes also arrive to them.

Step six. They withdraw.

The whole sequence typically completes in under an hour, frequently at night.

Why SMS was ever used for this

Because it was better than nothing and everyone has a phone. The security model assumes the phone number belongs to you, and that assumption is enforced by a customer service process rather than by cryptography.

What to use instead

An authenticator application. Codes generated on your device, not transmitted anywhere. A stolen phone number gains the attacker nothing.

A hardware security key. A physical device required to log in. This defeats both SIM swapping and phishing, because the key verifies the site’s identity before responding.

Passkeys. Increasingly supported, bound to your device, not transferable by a carrier.

Where an exchange offers only SMS, that is a meaningful reason to prefer a venue that supports application-based or hardware two-factor, such as an exchange you can actually contact. The authentication options a platform supports tell you a great deal about how seriously it takes account security.

Additional measures worth taking

A carrier port-out PIN. Most carriers offer a separate code required before any number transfer. It is not enabled by default and takes five minutes to set up.

A dedicated email address for financial accounts. Not used anywhere else, not published, protected by a hardware key.

Remove your phone number from account recovery where possible. A number left as a fallback recovery option defeats stronger methods on the same account.

Withdrawal address allowlists. Many exchanges let you designate approved withdrawal addresses, with a delay before new ones become usable. This converts an instant theft into a window in which you can react.

The warning sign

Sudden loss of mobile service with no explanation, particularly outside business hours.

If that happens and you hold anything meaningful, treat it as an attack in progress. Use another device to change your email password, revoke sessions, and contact your carrier from a different line immediately.

The uncomfortable conclusion

You do not control the weakest link. A carrier employee can undo your security arrangements in a five-minute phone call, and no amount of password hygiene on your side affects that.

The only real defence is to make the phone number irrelevant to your accounts, which means authenticator applications or hardware keys everywhere, and a port-out PIN as a backstop.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

sim-swaptwo-factoraccounts

Related cases