SIM swap attacks let criminals hijack your phone number — and with it, your exchange accounts, email, and crypto. The attacker convinces your mobile carrier to move your number to their SIM card, then intercepts the SMS codes used for logins and password resets. Crypto holders are prime targets because stolen funds are irreversible. Here is how SIM swap attacks work and how to defend yourself.
What Is a SIM Swap Attack?
A SIM swap attack is a form of identity theft targeting your mobile phone number. Every phone number is tied to a SIM card, and carriers allow customers to transfer numbers to new SIMs — for example, when you get a new phone. Attackers abuse this legitimate process by impersonating you and persuading carrier support to port your number to a SIM they control.
Once the swap completes, your phone loses service and the attacker’s device starts receiving your calls and texts — including the SMS verification codes that guard your most sensitive accounts.
Why Crypto Holders Are Targets
Phone numbers are deeply embedded in crypto security. Exchanges use SMS for two-factor authentication and password resets, and many people secure their email — the master key to every account — with SMS recovery. A hijacked number can therefore unlock an exchange account, reset the email behind it, and approve withdrawals, all within minutes.
Criminals also know that crypto transfers cannot be reversed. A drained bank account might be recoverable through fraud processes; drained crypto is gone. That finality makes crypto holders the most profitable targets for SIM swappers. High-profile cases have seen attackers steal millions from a single victim in one night, which is why organized groups now specialize in this exact crime.
How a SIM Swap Attack Works
- Information gathering: the attacker collects your name, number, date of birth, and carrier from data breaches, social media, or phishing.
- Impersonation: they contact your carrier posing as you, claiming a lost phone or new device, and request a SIM transfer.
- The port: if carrier verification is weak, your number moves to the attacker’s SIM. Your phone goes dark.
- Account takeover: they trigger password resets on your email and exchange accounts, intercepting SMS codes.
- The drain: with access secured, they withdraw crypto to addresses they control — often within the hour.
Warning Signs of SIM Swap Attacks
- Your phone suddenly shows “no service” or “emergency calls only” without explanation.
- You receive unexpected texts from your carrier about a SIM change or port request you did not make.
- Login alerts or password-reset emails arrive for accounts you did not touch.
- You are locked out of accounts while your credentials still seem correct.
If your phone loses service unexpectedly, treat it as an emergency: contact your carrier from another device immediately.
How to Defend Against SIM Swap Attacks
- Remove SMS-based 2FA everywhere. Replace it with an authenticator app or, better, a hardware security key. SMS should never guard crypto accounts.
- Set a carrier PIN or passcode. Most carriers let you add a PIN required for any account changes, including SIM ports. Enable it and make it strong.
- Ask about port-freeze or number-lock features. Some carriers offer extra protections against unauthorized transfers — request every available safeguard.
- Use a separate email and number for crypto. Keep exchange accounts on an email address and phone number you never publish or share.
- Reduce your exposed personal data. Limit what is visible on social media and consider removing your number from data-broker listings.
- Prefer hardware security keys for exchange and email logins — they cannot be phished or SIM-swapped.
- Monitor your accounts for unfamiliar logins and set up alerts for withdrawals.
If It Happens to You
Call your carrier immediately from another phone and report the unauthorized swap to regain your number. Then secure your email first — it is the key to everything else — followed by exchange accounts: change passwords, revoke active sessions, and move funds to new wallets. Document timelines carefully and file reports with your carrier, local law enforcement, and cybercrime authorities.
SIM Swap Attacks FAQs
Can SIM swapping happen with eSIMs? Yes. eSIM profiles can be transferred through carrier processes just like physical SIMs, so the same defenses apply.
Is an authenticator app enough protection? It removes the SMS interception vector, which defeats the classic SIM swap attack. Hardware security keys go further by also resisting phishing.
How do attackers get my personal details? Mostly from large data breaches, phishing messages, and public social media — not from sophisticated hacking. Assume your basic details are already circulating.
SIM swap attacks succeed through weak carrier processes, not clever technology. Harden the human links — your carrier account, your 2FA methods, your public footprint — and you remove the attacker’s leverage. A few hours of prevention today can save you from a devastating loss tomorrow.



