Home › Knowledge Hub › SIM-swap attacks
SIM-swap attacks and cryptocurrency theft
A SIM-swap attack transfers your phone number to a device the attacker controls, usually by deceiving your mobile carrier's support staff. Once they hold the number, any account secured by SMS codes becomes reachable, email first, then exchanges. The defining warning sign is your phone losing service for no reason, and the window to act is roughly an hour.
If your phone just lost service
Act now and read the rest afterwards. If this is a SIM swap, you have minutes rather than hours.
- Call your carrier from another phone. Use the number on their official website, not one from a search advert. Say the words "SIM swap", support staff are trained on it.
- From a different device, change your email password and remove SMS as a recovery method.
- Log into your exchange accounts and lock them, freeze withdrawals, or change the password.
- Do not wait to be certain. A sudden loss of service with no explanation is enough to act on. Being wrong costs you a phone call.
What happens
Your phone number is a credential, whether or not you think of it that way. It resets passwords, receives verification codes, and confirms your identity to banks and exchanges.
An attacker who controls it works through your accounts in order. Email first, because email controls everything else. Then exchanges, then anything financial.
They obtain it in one of three ways: convincing carrier support they are you, using stolen personal details to pass verification, or bribing or compromising an employee with account access. The carrier's own process is the vulnerability, which is why this is largely outside your control.
Warning signs
- Sudden, unexplained loss of mobile service: no bars, no calls, no data, while others nearby are fine
- A carrier notification about a SIM change, port request or new device you did not initiate
- Password reset emails you did not request
- Login alerts from accounts you were not accessing
- Being locked out of email or an exchange
- Contacts saying your number is unreachable or behaving oddly
The first one is the reliable signal. Phones lose service for ordinary reasons, but a sudden loss with no network outage, in a place where service normally works, deserves a call to your carrier.
Why SMS two-factor authentication is the weak link
SMS codes were a significant improvement over passwords alone, and they remain better than nothing. But they depend on something you do not control: your carrier's willingness to keep your number attached to your SIM.
Better options, roughly in order:
- Hardware security key: a physical device you plug in or tap. The strongest widely-available option, and immune to SIM swaps entirely.
- Authenticator app: Google Authenticator, Authy, or similar. Codes are generated on your device with no network involvement. Free and a substantial upgrade.
- Passkeys, where offered.
Where to change it first: email, then exchanges, then banking. Email is the priority because it is the reset path for everything else.
Some services still insist on SMS. Where you cannot remove it, at least remove it as a recovery method even if it stays as a second factor.
Set a carrier PIN
Most carriers offer an account PIN or port-out protection, a code required before your number can be moved. It is free, takes a few minutes, and is the single most effective thing you can do.
Call your carrier or check your online account. Ask specifically for port-out protection or a transfer PIN, and choose something unrelated to your other passwords.
What to preserve
- The exact time your service dropped
- Any carrier notifications about SIM or port changes
- Password reset emails and login alerts, with headers where possible
- Your account access logs from the exchange, most provide login history
- Every transaction hash for funds that left, plus the destination addresses
- A written timeline from service loss to discovery
Your carrier may be liable
This distinguishes SIM-swap cases from most crypto fraud, and it is worth pursuing.
The theft was made possible by your carrier transferring your number to someone who was not you. Where their verification process failed (an agent bypassing procedure, insufficient identity checks, or an employee acting improperly), there may be a claim.
Ask the carrier in writing for the full account activity log covering the change: what was requested, which channel it came through, what verification was performed, and which employee handled it. Ask promptly, because retention periods vary.
For substantial losses this is worth a lawyer's opinion. Carrier liability is contested and outcomes vary by jurisdiction, but unlike an anonymous scammer overseas, your carrier is an identifiable defendant with assets. That changes the calculation compared with most cases we describe on this site.
Is recovery realistic?
The crypto itself follows the same rules as any theft, it depends on speed, destination and records. Our guide on what is recoverable covers that.
What is different here is the second route. Because a company was involved, there may be a claim that does not depend on identifying the thief. That is unusual in this field and it is the reason to document the carrier's failure carefully and early.
Report to police as well. SIM-swap operations typically run against many victims through the same carrier weaknesses, and grouped reports are what expose an insider or a systemic process failure.
Expect a recovery approach
Losses reported publicly attract offers of help within weeks. Read how to spot a recovery scam first, and note that anyone contacting you about a SIM swap by phone or SMS deserves particular suspicion.
Frequently asked questions
How did they get my phone number transferred?
Usually by contacting your carrier's support and passing verification using personal details gathered from data breaches or social media. Sometimes through a compromised or bribed employee. The failure is in the carrier's process, which is why an account PIN or port-out protection is the most effective defence.
Is an authenticator app more secure than SMS?
Yes, substantially. Authenticator codes are generated on your device and never travel through the phone network, so taking over your number gains the attacker nothing. A hardware security key is stronger still.
Can I sue my mobile carrier?
Sometimes. Where their verification process failed, there may be a claim, and unlike most crypto fraud there is an identifiable defendant with assets. Outcomes vary by jurisdiction and it is contested. Request the full account activity log in writing straight away, and take legal advice for a substantial loss.
How long does a SIM swap take to notice?
Often minutes, because you lose service immediately. The difficulty is that people assume a network problem and wait. If your phone loses service unexpectedly and others nearby have signal, call your carrier from another phone straight away.
What if I still have service but suspect a swap?
Then it may be something else, credential theft or a compromised device rather than a carrier issue. Secure your email, change passwords from a different device, review login history on your exchanges, and check for token approvals if a wallet was involved.
Will a carrier PIN definitely stop this?
It stops the common version, where an attacker calls support and talks their way through. It does not protect against a compromised employee. It is still the single most effective step available to you, and it is free.