SIM Swap Attacks on Crypto Accounts: Prevention Checklist
SMS-based security is fundamentally broken. Learn how attackers hijack phone numbers to drain exchange accounts, and how to stop them.

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.
Never use SMS for two-factor authentication (2FA) on your crypto exchange accounts. Always use an authenticator app (like Authy or Google Authenticator) or a hardware security key (like YubiKey).
How a SIM Swap Attack Works
A SIM swap doesn't involve hacking your phone. Instead, it involves hacking the human at your mobile carrier.
- Reconnaissance: The attacker finds out your phone number, email, and the crypto exchange you use (often via data breaches).
- Social Engineering: They call your mobile carrier (AT&T, Verizon, T-Mobile, etc.) pretending to be you. They claim their phone was lost or destroyed and request that the number be transferred to a new SIM card they control.
- The Swap: If the customer service rep is tricked (or bribed), they authorize the transfer. Your phone immediately loses service.
- Account Takeover: The attacker initiates a password reset on your crypto exchange and email accounts. The verification codes are texted to your phone number—which the attacker now receives on their device.
- The Drain: They log in, reset passwords, and withdraw your crypto.
The Prevention Checklist
Take these steps immediately to immunize your crypto accounts against SIM swap attacks.
- 1. Remove SMS 2FA from Everywhere: Go to the security settings of your crypto exchanges, email provider (Gmail/Proton), and password manager. Disable SMS 2FA.
- 2. Switch to an Authenticator App or Security Key: Replace SMS with an app like Authy, Google Authenticator, or preferably, a hardware security key like a YubiKey. These cannot be bypassed by a telecom employee.
- 3. Add a PIN/Passcode with Your Carrier: Contact your mobile provider and add a strict security PIN to your account. Instruct them that no changes can be made without this PIN.
- 4. Avoid Linking Your Primary Number: Do not use your primary public phone number for sensitive financial accounts. Consider using a VoIP number (like Google Voice) for account registrations, as they cannot be SIM swapped in the traditional way.
- 5. Secure Your Email First: Your email address is the master key to your digital life. If an attacker gets into your email, they can reset exchange passwords. Secure your email with a hardware key.
How do I know if I've been SIM swapped?
Your phone will suddenly lose cellular service and display 'No Service' or 'Emergency Calls Only' because your number has been activated on the attacker's SIM card.
Will a SIM swap let attackers access my hardware wallet?
No. A SIM swap only gives attackers access to accounts secured by SMS, such as centralized exchanges (Coinbase, Binance) or webmail. Hardware wallets require physical possession of the device and the PIN.
Can my telecom provider prevent a SIM swap?
Most providers offer a 'SIM PIN' or 'Port Freeze' feature, but these can sometimes be bypassed by skilled social engineers. Removing SMS 2FA entirely is the only guaranteed protection.
