Sat, 29 August 2026
Security15 July 2026

SIM swapping: how criminals steal crypto via your phone number

One transferred phone number and your SMS codes belong to the attacker. Why SMS 2FA is your weakest link — and the six measures you can take today.

Article image for: SIM swapping: how criminals steal crypto via your phone number

Your phone suddenly loses signal. No outage — at that very moment someone else is logging into your email and your exchange with your number. This is SIM swapping: the attacker convinces (or pays) a telecom employee to transfer your number to his SIM card. Every SMS verification code goes to him from then on.

Why crypto holders are target number one

With a stolen bank account, the bank can reverse transactions. Not with crypto: once sent, coins are gone. SIM swappers do their homework — social media, data leaks, phishing — and strike at people they suspect hold crypto behind the number. So never talk publicly about your holdings with your real name attached.

The attack in four steps

  1. Attacker gathers your name, number and date of birth (data leaks, social engineering).
  2. He calls your provider, impersonates you and requests a ‘replacement SIM’.
  3. Your device loses signal; his device now receives your SMS and calls.
  4. Via ‘forgot password’ plus SMS code he first takes over your email, then your exchange account.

Six measures that make the difference

  1. Scrap SMS as 2FA, everywhere. Use an authenticator app (TOTP) or — better — a hardware security key (FIDO2/passkey) for email and exchanges.
  2. Protect your email like the crown jewels. Whoever has your mailbox resets everything. Unique password + hardware key.
  3. Enable a withdrawal allowlist. At exchanges like Kraken and OKX you can restrict withdrawals to pre-approved addresses with a waiting period — a SIM swapper then still hits a wall.
  4. Request a porting block or extra PIN from your provider. Most providers offer additional verification for SIM changes on request.
  5. Use a separate, secret number for financial accounts — not the number in your email signature.
  6. Large amounts don't belong behind a phone number. Long-term holdings go in self-custody on a hardware wallet — that cannot be SIM-swapped.

Recognise the attack in time

Suddenly ‘no service’ without an outage at your provider? Act immediately: call your provider (from another device) to block the swap, change your email password and freeze withdrawals at your exchange. Speed is everything — most damage happens in the first hour.

More security basics: our seed phrase guide and the complete scam checklist.

Sources: Kraken, OKX. Last checked: 14 July 2026.

#security#sim-swapping#2fa