A SIM swap attack is an identity fraud technique where an attacker convinces a mobile carrier to reassign a victim's phone number to an unauthorized subscriber identity module card.
How to Secure Accounts Against SIM Swapping
Prioritize removing Short Message Service (SMS) verification from all sensitive cryptocurrency exchanges, email inboxes, and financial profiles. Because cellular network routing relies on carrier customer service verification rather than cryptographic proof, SMS-based two-factor authentication remains vulnerable to social engineering.
Protect your crypto assets by systematically applying defensive measures across your communication and trading accounts:
- Replace SMS verification with time-based one-time password authenticator applications or hardware security keys like FIDO2 devices.
- Establish a secondary verbal PIN, port-freeze passcode, or transfer lock directly with your telecommunications carrier.
- Remove publicly exposed mobile numbers from account recovery options on primary email addresses and trading accounts.
- Transition custodial login credentials to alias email addresses not linked to public social media accounts.
Attack Mechanics and Distinct Threat Types
The attack mechanism begins when a malicious actor gathers personal identifiable information through data breaches, phishing schemes, or open-source intelligence. Armed with these details, the attacker impersonates the subscriber and contacts the telecom operator, claiming a lost or damaged device to request an immediate number transfer.
Once the carrier activates the new card, incoming text messages and voice calls route directly to the attacker. The perpetrator uses password reset workflows on target platforms, receives the one-time confirmation codes over the redirected cellular connection, and locks out the legitimate account owner to drain custodial crypto funds.
It is important to distinguish a SIM swap from phone number spoofing. Spoofing alters outbound caller identification metadata to disguise an attacker's identity during an outbound call, but it cannot intercept incoming SMS verification tokens or hijack carrier routing.