SIM Swap
A SIM swap is a social engineering attack in which an attacker convinces a mobile carrier to transfer your phone number to a SIM card they control. They then receive all your SMS messages — including 2FA codes — and can take over exchange accounts and wallets within minutes. SIM swap attacks caused hundreds of millions of dollars in crypto losses in 2023–2024.
How a SIM swap attack works
SIM swapping is a social engineering attack: the attacker calls your carrier, impersonates you, and requests a SIM card transfer claiming they lost their phone. With enough personal data in hand, they convince a support agent to port your number. From that moment, every call and SMS — including 2FA codes — goes to the attacker.
The attack unfolds in three phases. First, the attacker collects personal data: full name, date of birth, address, last digits of an ID document. This data is bought on darknet markets after data breaches, obtained via phishing, or scraped from social media. Then they call the carrier. After the transfer is approved, the victim loses signal — and the attacker has full control of the number.
How attackers obtain your personal data
Data breaches are the largest source. Major leaks of 2022–2024 exposed billions of records: names, phone numbers, dates of birth, email addresses. Darknet databases sell for $50–200, enabling mass targeting.
OSINT from public profiles: Instagram, LinkedIn, Facebook. A birthday in a profile, an employer mention, a caption tagging your carrier — all of it helps pass carrier verification. A large public Telegram or Twitter following often marks someone as a valuable target.
Targeted vishing: the attacker calls the victim posing as bank or exchange security, eliciting personal details under the guise of "account verification."
Why SMS 2FA is vulnerable to SIM swap
SMS codes travel through the carrier's network, not through an encrypted app. After a SIM swap, the attacker receives every verification code and can reset your exchange password, confirm a withdrawal, or change the account email — all through standard account recovery flows.
The SS7 protocol underpinning SMS was designed in 1975 and has well-known vulnerabilities. SMS interception is possible not only via SIM swap but through direct attacks on carrier infrastructure — a method used by state actors and professional APT groups.
High-profile cases
In 2024, a hacker used SIM swap to access an AT&T account and compromised data on 110 million subscribers. Scattered Spider used SIM swap in a series of attacks resulting in hundreds of millions in crypto losses. In 2023, Ethereum co-founder Vitalik Buterin's Twitter/X account was compromised via SIM swap.
First 30 minutes: what to do after an attack
If your phone suddenly loses signal, act immediately. From another device, call your carrier and report an unauthorised SIM transfer. Log into all exchanges via email and manually freeze withdrawals or contact exchange support. Change passwords on any account you can still access.
Contact each exchange through their official support form, explain you have been SIM-swapped, and request an emergency withdrawal freeze. Most major exchanges (Binance, Bybit, Coinbase) have emergency procedures — but they only work if you reach out within the first hours.
How to protect yourself
Replace SMS 2FA with an authenticator app (Google Authenticator, Authy) or a hardware key (YubiKey) — neither depends on your carrier. Set a SIM lock PIN at your carrier: most operators allow a requirement for in-person ID verification before any SIM transfer.
Use a separate phone number exclusively for financial accounts and never publish it anywhere. Move important accounts to an email address not linked to your main phone number. Never share personal data with callers claiming to be "bank security."
SIM swap and crypto
Exchanges are the primary target of SIM swap attacks. Attackers know that a single SMS code is enough to reset a password and approve a withdrawal. After gaining control of the number, the entire attack takes 5–10 minutes: password reset, withdrawal confirmed, email changed to lock out the real owner.
KarCrypto investigates crypto losses from SIM swap attacks. In some cases it is possible to freeze funds at the exchange if the attacker has not yet completed the withdrawal. The key factor is reaching out within the first hours of the incident.
Why this matters for your security
SIM swap is dangerous precisely because it attacks the carrier's infrastructure, not your device. Antivirus, firewall, and a strong password offer no protection here. Victims typically discover the attack only when their phone stops receiving calls.
If your phone suddenly loses signal, check all financial accounts immediately from another device. Every minute of delay reduces the chances of stopping the theft.
Frequently asked questions
How do I know if I have been SIM-swapped?
The primary sign is your phone suddenly losing network signal despite being in coverage. You cannot receive calls or texts. Simultaneously, you may receive email notifications about password changes or withdrawal requests. Call your carrier immediately from another device.
Can I recover funds after a SIM swap attack?
In some cases, yes. If the funds are still on the exchange or linked to a centralised platform, a legal freeze request is possible. KarCrypto provides this service. The probability of success drops sharply with each hour of delay.
Is the carrier liable for a SIM swap?
In some jurisdictions, yes. In the US, AT&T and T-Mobile have paid multi-million dollar settlements to SIM swap victims. In other countries, a formal complaint to the regulator and a civil claim against the carrier are viable options.
Why is an authenticator app better than SMS against SIM swap?
An authenticator app (Google Authenticator, Authy) generates codes locally on your device using the TOTP algorithm. It does not use the carrier network at all. Even after a SIM swap, the attacker cannot get these codes — they are tied to the device, not the phone number.
How do I set up a SIM lock with my carrier?
Most major carriers allow you to add a PIN or passcode that must be provided before any SIM transfer is processed. Contact your carrier's customer support or visit a store in person to enable this. Some carriers require an in-person visit with ID to change the number.