A SIM swap transfers your phone number to an attacker’s SIM. Your phone loses signal; theirs starts receiving your calls and texts, including one-time codes and account recovery messages. Everything that treats your number as proof of identity now believes the attacker is you.

Crypto holders are disproportionately targeted because the payoff is immediate and irreversible. There is no chargeback on a withdrawal.

How the attack runs

It starts with research: your number, your email address, and enough personal detail to pass a carrier’s identity check — most of which is available from old data breaches and your own public posts.

Then the port. Either the attacker social-engineers a call-centre agent, or they pay an insider. Both happen routinely, and the second is why “but I have a good password” is not relevant — nothing about your account behaviour is involved.

Then the cascade, and the order is always the same: email first, because it is the recovery channel for everything else. Reset the email password using an SMS code, then work through the accounts whose reset links land in that inbox. Exchange, password manager, cloud backups. Withdrawals go out within minutes, usually while the victim is still on hold with their carrier.

Why SMS codes are the problem

A second factor is supposed to be something an attacker cannot obtain remotely. A phone number can be moved by a customer-service employee at a company you have no relationship with beyond a monthly bill. It is not a second factor; it is a shared secret held by thousands of strangers.

Everything else here follows from that.

The migration, in the order that matters

Order is the whole point. Hardening your exchange while your email still resets by SMS moves nothing — the attacker simply takes the email and resets the exchange from there.

  1. Email first. Move it to an authenticator app or, better, a hardware security key. Then remove your phone number as a recovery method entirely, and check the account’s recovery settings rather than assuming — a “backup phone” left in place undoes the work. Review active sessions and connected apps while you are there.
  2. Password manager second. Same treatment. It holds the keys to everything below it.
  3. Exchanges third. Authenticator app or passkey, SMS disabled where the platform allows it. Then add the two controls that limit the damage even if authentication fails: a withdrawal address whitelist, and a time delay on newly added addresses. The delay is what converts an instant, total loss into an alert you can act on. Our exchange security checklist covers the rest of those settings.
  4. Carrier fourth. Ask for a port-out PIN or number lock — the names differ, the function is the same. Confirm it is actually recorded on the account, and be aware it raises the bar rather than removing the risk, since an insider can bypass it.
  5. Reduce exposure. Take your number off public profiles and old listings. People with meaningful holdings often keep a separate number used only for financial accounts and given to nobody — a number that never appears anywhere is a number nobody knows to port.
  6. Self-custody as the endpoint. No amount of account hardening protects assets held on a platform you do not control. Funds on a hardware wallet are untouched by any of this.

Treat sudden signal loss as an incident

Phones lose signal for boring reasons, but the cost of over-reacting is a wasted ten minutes and the cost of under-reacting is everything. If your signal disappears and nobody around you has the same problem:

  • From another device, check your email for login or password-reset notifications, and sign out of all sessions.
  • Freeze or disable withdrawals on any exchange account you can still reach.
  • Call the carrier from a different line and ask directly whether the number has been ported.
  • If it has, keep records — the timeline matters for both the carrier and any report you file.

The uncomfortable summary: two-factor authentication by SMS is better than nothing and worse than almost anything else. If you change one thing this month, take your phone number off your email account.

Nothing here is financial advice. See our risk disclaimer.