SIM-Swap Attack
A SIM-swap attack is a type of identity fraud in which a criminal takes control of a victim's mobile phone number by convincing or manipulating a mobile carrier into transferring the number to a SIM card or eSIM controlled by the attacker. Once the number has been transferred, the attacker may receive the victim's calls and SMS messages.
✦ Key Insight
SIM swapping is particularly dangerous for crypto users because many exchanges, email accounts, banks, and online services still use SMS messages for password resets or two-factor authentication. If an attacker controls your phone number, they may be able to: Receive SMS authentication codes Reset account passwords Access email accounts Take over exchange accounts Approve withdrawals Impersonate you Bypass some account-recovery systems Crypto transactions can be difficult or impossible to reverse, making account takeover especially costly.
✕ Common Misconceptions
Using SMS as the only second authentication factor
Ignoring sudden loss of phone service
Publishing too much personal information online
Using the same email for public and financial accounts
Failing to secure the mobile-carrier account with a PIN
Assuming 2FA always protects against account takeover
Leaving withdrawal protections disabled
Detailed Explanation
How It Works
A typical SIM-swap attack may involve several stages.
First, the attacker collects personal information about the target through phishing, leaked databases, social media, or previous data breaches.
The attacker then contacts the victim's mobile carrier and impersonates them.
If the carrier accepts the request, the phone number is moved to a SIM or eSIM controlled by the attacker.
The victim's phone may suddenly lose mobile service.
The attacker can then request password resets or authentication codes for accounts linked to that phone number.
FAQs
How do I know if I have been SIM-swapped?
A sudden unexplained loss of cellular service can be a warning sign, particularly if account-reset notifications follow.
Does an authenticator app prevent SIM swapping?
It reduces reliance on SMS, so taking over the phone number alone would not provide the authenticator codes.
Can a SIM swap steal a self-custody wallet?
Not directly if the wallet's private keys or recovery phrase are securely stored, but linked email, cloud backups, or exchange accounts could still be targeted.
