Home

Phishing & Wallet Drainers

SIM-Swap Attacks: How Phone Number Hijacking Drains Crypto Accounts

Spot the edge. Swoop in.

Your phone suddenly loses signal, and nothing you do brings it back. Somewhere else, an attacker's device just started receiving your calls and texts, including the SMS codes that guard your email and your exchange account. This guide breaks down exactly how SIM-swap attacks work, why crypto holders are disproportionately targeted, and how to make your accounts worthless to steal this way.

By Swoopr Editorial Team

Published · Updated

AI-assisted content · Swoopr is responsible for the final published article.

Key Takeaways

A SIM swap doesn't touch your wallet, your seed phrase, or your private keys at all. It attacks something most people never think of as a security credential: the phone number itself. Because so many accounts use that number as a recovery and verification channel by default, taking control of it can be enough, on its own, to cascade into every account that trusts it.

Direct answer: A SIM swap happens when an attacker convinces your mobile carrier, through social engineering, bribery, or the help of an insider, to move your phone number onto a SIM card they control. Once that transfer completes, every call and text meant for you, including SMS two-factor codes and account-recovery messages, goes to the attacker instead. From there, they typically reset your email password using SMS recovery, then use email access to break into exchange and financial accounts and drain them.

What a SIM Swap Is, Technically

A phone number, on a technical level, is not permanently bound to a physical SIM card the way most people assume. It's an entry in a carrier's account database that gets mapped, at any given moment, to whichever SIM card the carrier's systems currently associate with it. Porting a number to a new phone, replacing a lost or damaged SIM, or switching carriers all rely on this same underlying flexibility, and all of it is completely normal, legitimate carrier functionality that millions of people use every year without incident.

A SIM swap attack abuses that same flexibility. Instead of the account owner requesting the change, an attacker contacts the carrier, usually by phone or through an online chat channel, and impersonates the victim well enough to convince a representative to move the number to a new SIM card the attacker holds. Once the carrier's system completes the transfer, the victim's original SIM is deactivated, and the attacker's SIM begins receiving every call and every text message sent to that number. This includes SMS-based two-factor authentication codes, "verify it's you" texts, and password-reset links sent via SMS, since all of those simply arrive at whatever SIM the number currently points to. Nothing about this requires access to the victim's phone, computer, email, or any account credential directly; the attack targets the carrier's account-management process, not the victim's devices.

Three broad methods get an attacker to that point. Social engineering is the most common: a caller reads off enough correctly gathered personal details, such as a name, date of birth, billing address, and the last four digits of a Social Security number, to convince a call-center representative they are the account holder, sometimes reporting a lost phone or invoking urgency to discourage extra scrutiny. Bribery is the second: some documented cases involve attackers paying a carrier employee, directly or through a broker who specializes in recruiting insiders across multiple carriers, to perform the swap without any pretense of verification at all. The third is an actual insider, an employee who executes SIM swaps for payment as an ongoing side operation rather than a one-off bribe, sometimes running dozens of fraudulent transfers before being caught. All three routes reach the same outcome: the carrier's systems now believe the attacker's SIM is the legitimate one for that number.

Why Crypto Holders Are Specifically Targeted

SIM swapping is not a mass, automated attack the way a phishing email blast or a dusting campaign is. Every successful swap typically requires real time from a human attacker: researching the target, gathering enough personal information to pass a carrier's verification, and often multiple attempts across different call-center representatives or channels before one succeeds. That labor cost means attackers are selective, and crypto holders sit unusually high on the list of worthwhile targets for a few concrete reasons.

First, crypto holdings are identifiable in ways that a typical bank balance isn't. Public blockchain activity is, by design, visible to anyone: a wallet address tied to a large balance, a series of trades, or participation in a token launch can sometimes be linked back to a real identity through a public forum post, an NFT purchase tied to a social handle, or an exchange withdrawal address that's been shared or doxxed. Second, crypto communities are unusually public about their activity by cultural habit — posts about a big trade, a staking position, or a new wallet setup on X, Discord, or Telegram routinely signal that a specific person has meaningful holdings, effectively self-nominating as a target. Third, and often the most consequential source, exchange KYC (know-your-customer) data from past data breaches has repeatedly leaked names, phone numbers, and account balances tied to real people, giving attackers a ready-made target list with contact information and an estimate of what's worth stealing already attached.

Finally, crypto is uniquely suited to the SIM-swap attacker's actual goal once access is gained: cryptocurrency transactions are irreversible and can be moved across borders and into mixers or other wallets within minutes, with no bank, card network, or government able to claw the funds back the way a fraudulent wire transfer sometimes can be. A stolen crypto exchange balance is, in practical terms, gone the moment it's withdrawn, which makes the return on the labor-intensive SIM-swap process substantially higher than targeting a typical bank account with the same effort.

The Typical Attack Sequence

A SIM-swap-driven account takeover almost always follows the same general shape, even though the specific accounts targeted vary. Understanding the sequence end to end makes clear why a single weak link, SMS-based recovery, is enough to compromise a chain of otherwise unrelated accounts.

Step 1: Reconnaissance

The attacker gathers personal information about the target ahead of time. Sources include past data breaches (which routinely expose full names, dates of birth, addresses, and partial Social Security numbers in bulk), social media profiles, public records, and sometimes direct social engineering of the target themselves through a pretext phone call or phishing message designed purely to extract identity details rather than credentials.

Step 2: Contacting the carrier

Armed with enough personal detail to sound credible, the attacker contacts the victim's mobile carrier, impersonating the victim, and requests that the phone number be transferred or ported to a new SIM card, typically reporting a lost or stolen phone as the reason. If the representative asks security questions, the attacker answers using the gathered personal information; if the carrier requires a PIN and the attacker doesn't have it, they may attempt social engineering to have it reset, try a different representative or channel, or, in bribery and insider cases, bypass the check entirely.

Step 3: The transfer completes

The carrier's system deactivates the victim's SIM and activates the attacker's. The victim typically notices this first as a sudden, unexplained loss of cell service; the attacker's device now receives all calls and SMS messages sent to that number.

Step 4: Email takeover via SMS recovery

The attacker initiates a password reset on the victim's primary email account, selecting SMS as the recovery method where offered. The reset code or link is delivered to the number the attacker now controls, and the email account password is changed, locking the real owner out.

Step 5: Cascading account takeover

With email access secured, the attacker repeats the same pattern against every other account tied to that inbox: crypto exchange accounts, banking apps, and any service where "forgot password" routes a reset link to the compromised email or an SMS code to the compromised number. Any account still using SMS-based two-factor authentication as a second factor is trivially bypassed the same way, since the code simply arrives on the attacker's SIM.

Step 6: Extraction

Once inside the exchange or wallet-connected account, the attacker moves quickly, typically changing account recovery details first to lock the real owner out further, then withdrawing crypto holdings to an address they control. Because crypto transfers settle quickly and can't be reversed once confirmed, this final step is often complete within minutes of gaining exchange access.

Why SMS-Based 2FA Is Fundamentally Weaker Here

Two-factor authentication exists to require something beyond a password: typically something you have, like a device, in addition to something you know. The security promise depends entirely on that "something you have" being genuinely difficult for an attacker to also obtain. SMS-based 2FA quietly breaks that promise in a way that isn't obvious until you look at what actually delivers the code.

An SMS code isn't tied to your phone as a physical object; it's tied to your phone number, which is itself just a routing entry inside your carrier's systems. Whichever SIM card the carrier currently associates with that number receives the text, regardless of whose hands that SIM is in. That's precisely what a SIM swap changes, and it's why SMS 2FA collapses so cleanly under this specific attack: the "second factor" isn't actually a physical possession an attacker has to steal from you, it's a network routing state an attacker can redirect without ever touching your phone.

Authenticator apps (using the TOTP standard — time-based one-time passwords) work fundamentally differently. During setup, the app and the service share a secret key, and from that point forward, the app generates a new six-digit code locally on that specific device every 30 seconds, using the shared secret and the current time, with no network transmission involved in producing the code at all. An attacker who takes over your phone number gains nothing here, because the code was never sent anywhere for them to intercept; it's computed independently on a device they don't control.

Hardware security keys (such as YubiKeys or other FIDO2/WebAuthn-compliant devices) go a step further. Logging in requires physically plugging in or tapping the key, which performs a cryptographic challenge-response tied to that specific physical device and the specific website being logged into, which also makes it inherently resistant to phishing, since a fake login page can't complete the same cryptographic exchange as the real one. Neither an authenticator app nor a hardware key can be reached through the phone network, which means neither can be defeated by a SIM swap under any circumstance, no matter how convincing the attacker's social engineering against the carrier was.

Worked Example: From SIM Swap to Drained Exchange Account

Hypothetical, generic example — for education only. Not based on any specific real individual or incident.

Consider someone who has been visibly active in crypto for a few years: a handful of posts on X discussing token research, a Discord profile in a couple of active trading servers, and, unknown to them, an email address and phone number that leaked years earlier in an unrelated exchange data breach. None of that feels risky day to day, but together it gives an attacker exactly what's needed to start.

The attacker cross-references the leaked exchange data against the social activity, confirming this is a real person with a real, non-trivial exchange balance and a specific phone carrier. Using the leaked data, plus a bit of additional information pulled from public records and a throwaway social-engineering call to the target's own phone earlier that week (posing as a delivery service to "confirm an address"), the attacker assembles enough personal detail to sound legitimate: full name, date of birth, home address, and the last four digits of a Social Security number.

The attacker calls the victim's mobile carrier, reports the phone as lost, and asks for the number to be activated on a new SIM. The representative asks a few standard verification questions; the attacker answers all of them correctly using the gathered information. The transfer goes through. Within minutes, the victim's phone loses signal entirely — no bars, no calls, no texts — while a hundred miles away, the attacker's device lights up with the victim's messages.

The attacker goes to the victim's email provider and requests a password reset via text message. The code lands on the attacker's SIM instead of the victim's dead phone. Email access secured, the attacker searches the inbox for exchange-related messages, finds confirmation emails from a major crypto exchange, and initiates a password reset there too. The exchange sends both an email confirmation link and, since the account has SMS enabled as a 2FA option, a text code; both arrive in channels the attacker now fully controls. Within roughly twenty minutes of the SIM swap completing, the attacker is logged into the exchange account, has changed the password and disabled the only 2FA method the account had configured, and initiates a withdrawal of the full balance to a wallet address under their control. The victim, meanwhile, is still trying to figure out why their phone has no service, having no reason yet to suspect anything beyond a network outage.

The chain that made this possible had exactly one structural weak point repeated three times: SMS as the recovery or verification method for the phone carrier itself, the email account, and the exchange account. Nothing else in the attack, not the leaked data, not the social engineering, not the carrier call, would have mattered if the email and exchange accounts had required an authenticator app or hardware key instead of an SMS code, since a hijacked phone number alone would have produced nothing usable at either step.

Practical Defenses

None of the defenses below require exotic tools, and most take only a few minutes to set up once, with the payoff being that a successful SIM swap against you becomes far less useful to an attacker even if it happens.

Practical checklist

Common mistake

The common mistake is treating "I have 2FA enabled" as sufficient without checking which kind. An account secured only by SMS 2FA is meaningfully weaker against this specific attack than one with no 2FA at all combined with a strong, unique password, precisely because SMS 2FA creates a false sense that the account is well protected while leaving the actual point of failure, the phone number, completely exposed.

Common Mistakes

Beyond the mistake already called out above, a handful of patterns show up repeatedly in SIM-swap cases.

Misconceptions Versus Reality

MisconceptionReality
SIM swaps only happen to celebrities or huge crypto whalesMid-size holders are targeted routinely, especially anyone visibly active in crypto communities; attackers work down a target list built from breach data and public activity, not just a short list of famous names
A SIM swap requires the attacker to physically steal or clone my SIM cardNo physical access to the victim's SIM or device is needed; the attacker convinces the carrier's remote systems to reassign the number to a SIM card they already hold
My phone's screen lock or biometric security protects me from a SIM swapDevice-level security is irrelevant to this attack, since it happens entirely on the carrier's side and never involves accessing the physical phone at all
Having 2FA enabled on my accounts means I'm protected from SIM swappingProtection depends entirely on which type of 2FA is used; SMS-based 2FA is the exact mechanism a SIM swap is designed to defeat, while authenticator apps and hardware keys are not affected by it
A carrier PIN makes a SIM swap impossibleA PIN substantially raises the difficulty and blocks most social-engineering attempts, but it does not stop insider collusion or bribery, so it should be paired with non-SMS 2FA rather than relied on alone
If my phone loses service, it's almost always just a network problemSudden, total, unexplained loss of service is one of the clearest early indicators of an in-progress SIM swap and warrants immediate verification rather than assuming it's a routine outage

Risks, Limitations, and Exceptions

Sources

Frequently Asked Questions

What is a SIM swap?

A SIM swap is an attack where a fraudster convinces a mobile carrier, through social engineering, bribery, or an insider, to transfer a victim's phone number to a SIM card the attacker controls. Once the transfer completes, the attacker's device receives all calls and text messages sent to that number, including SMS-based two-factor authentication codes and password-reset links.

Why are crypto holders specifically targeted for SIM swaps?

SIM swapping is labor-intensive, so attackers reserve it for targets likely to have a meaningful payoff. Crypto holders are identifiable through public wallet activity linked to a real identity, crypto-related social media posts, leaked exchange KYC data from past breaches, and forum or Discord activity discussing holdings, which makes them easier to pick out and prioritize than an anonymous carrier subscriber.

Why is SMS-based two-factor authentication weaker than an authenticator app or hardware key?

SMS codes travel over the phone network to whatever SIM currently carries your number, so if an attacker moves your number to their SIM, the codes go to them instead of you, with no further access to your devices required. Authenticator apps generate codes locally on a specific device using a shared secret established at setup, and hardware keys perform a cryptographic challenge tied to that physical device, so neither can be intercepted by taking over a phone number.

How does a SIM swap actually lead to a drained crypto account?

Once the attacker controls the phone number, they use it to trigger an SMS-based password reset on the victim's email account, gaining access to the inbox. From the email account they trigger password resets on the crypto exchange or wallet-connected accounts, receive SMS 2FA codes on the same hijacked number where needed, and reset or disable additional 2FA on those accounts before withdrawing funds.

How can I tell if I've been SIM-swapped?

The most common early sign is sudden, unexplained loss of cellular service: calls and texts stop arriving, the phone shows no service or an emergency-calls-only status, and this happens without you having changed devices or SIM cards yourself. Unexpected password-reset emails, login notifications from unfamiliar locations, or an inability to log in to email or exchange accounts around the same time are strong corroborating signs.

What's the single most effective defense against SIM swapping?

Moving two-factor authentication for email, exchange, and financial accounts off SMS entirely and onto an authenticator app or hardware security key removes the payoff of a SIM swap for account takeover, since the attacker gains a phone number but no way to generate or intercept the codes those accounts now require.

Do carrier PINs actually stop SIM swaps?

A carrier PIN or passcode raises the bar meaningfully by requiring that code before any SIM change, port-out, or account modification, and it blocks the large share of attempts that rely purely on social engineering a call-center representative. It is not absolute protection, since insider compromise or a rep who skips verification can still bypass it, which is why it should be paired with non-SMS two-factor authentication rather than relied on alone.

Conclusion

A SIM swap succeeds not because an attacker breaks encryption or guesses a password, but because a phone number was trusted as a security credential in the first place, at a carrier, at an email provider, and at an exchange, all at once. The defense is not more vigilance about your phone; it's removing the phone number from the trust chain entirely for the accounts that matter most. Move email, exchange, and any high-value account to an authenticator app or hardware key, lock down your carrier account with a PIN, and stop treating "I have 2FA" as a finished checkbox without asking which kind. Use this page alongside the broader Phishing & Wallet Drainers hub for the account-security habits that apply across social-engineering attacks generally, not just SIM swapping.

Related Reading