Technical Definition

SIM-Swap Attack

A SIM-swap attack is a type of identity fraud in which a criminal takes control of a victim's mobile phone number by convincing or manipulating a mobile carrier into transferring the number to a SIM card or eSIM controlled by the attacker. Once the number has been transferred, the attacker may receive the victim's calls and SMS messages.

By Crypto University Editorial
Two-Factor AuthenticationPhishingData Breach

Key Insight

SIM swapping is particularly dangerous for crypto users because many exchanges, email accounts, banks, and online services still use SMS messages for password resets or two-factor authentication. If an attacker controls your phone number, they may be able to: Receive SMS authentication codes Reset account passwords Access email accounts Take over exchange accounts Approve withdrawals Impersonate you Bypass some account-recovery systems Crypto transactions can be difficult or impossible to reverse, making account takeover especially costly.

Common Misconceptions

Using SMS as the only second authentication factor

Ignoring sudden loss of phone service

Publishing too much personal information online

Using the same email for public and financial accounts

Failing to secure the mobile-carrier account with a PIN

Assuming 2FA always protects against account takeover

Leaving withdrawal protections disabled

Detailed Explanation

How It Works

A typical SIM-swap attack may involve several stages.

First, the attacker collects personal information about the target through phishing, leaked databases, social media, or previous data breaches.

The attacker then contacts the victim's mobile carrier and impersonates them.

If the carrier accepts the request, the phone number is moved to a SIM or eSIM controlled by the attacker.

The victim's phone may suddenly lose mobile service.

The attacker can then request password resets or authentication codes for accounts linked to that phone number.

FAQs

How do I know if I have been SIM-swapped?
A sudden unexplained loss of cellular service can be a warning sign, particularly if account-reset notifications follow.

Does an authenticator app prevent SIM swapping?
It reduces reliance on SMS, so taking over the phone number alone would not provide the authenticator codes.

Can a SIM swap steal a self-custody wallet?
Not directly if the wallet's private keys or recovery phrase are securely stored, but linked email, cloud backups, or exchange accounts could still be targeted.

In Practice

A crypto trader uses SMS 2FA for an exchange account. An attacker obtains the trader's name, phone number, email address, and other personal details from a leaked customer database. The attacker successfully transfers the phone number to another SIM, resets the trader's email password, then uses SMS verification to access the exchange account.

Dig Deeper