Skip to main content
Solflare
51k Ratings
Install
SIM Swap Attacks: How They Work and How to Protect Your Crypto

Your phone number is the master key to your email, your exchange account, and everything that resets via SMS — and criminals can steal it without ever touching your phone. Here's how SIM swap attacks work, the warning signs to catch them early, and how to make sure your crypto isn't reachable if it happens to you.

Your phone shows “no service” and you assume it’s the network. Twenty minutes later you’re locked out of your email, and an hour after that your exchange balance is zero. That sequence has a name, and it starts with something you probably still trust: your phone number.

Quick answer: A SIM swap attack transfers your phone number to a criminal’s SIM card, so every SMS code and “recover via phone” flow now goes to them. Exchange accounts protected by SMS 2FA are prime targets. Coins in a self-custody wallet secured by a seed phrase have no phone-number recovery path for the attacker to hijack.

What a SIM swap attack is

A SIM swap attack steals your phone number, not your phone. The device in your hand never leaves your hand. What moves is the number attached to it: a criminal convinces your mobile carrier to activate your number on a SIM card they control, and from that moment every call and text meant for you routes to them. Your phone just goes dead.

The uncomfortable part is that SIM swapping abuses a completely legitimate process. Carriers move numbers between SIMs all the time, when you upgrade to a new phone, replace a lost one, or switch to an eSIM. The attacker isn’t hacking the carrier’s systems. They’re walking through the front door of a routine customer-service flow and pretending to be you. That’s why this is not a malware problem you can antivirus away. It’s an identity problem, and the identity being verified is depressingly shallow: a birthday, an address, the last four digits of a card.

How a SIM swap works

The attack runs in three stages, and you’re only present for the first one, usually without knowing it.

how a sim swap attack works

Stage 1: they gather your information. Phishing emails and fake login pages harvest credentials, data breaches leak the rest, and data brokers sell what’s left. Social media fills the gaps: your birthday from the party photos and your address from the moving-day post. Even your carrier can surface in a complaint tweet. The shopping list is short. Date of birth, home address, last four digits of a payment card, account PINs, security answers.

Stage 2: they impersonate you to the carrier. The attacker calls support, claims a lost or damaged phone, and asks for the number to be moved to a new SIM. Armed with your details, they pass the identity checks. Some skip the acting entirely and bribe a carrier employee to process the swap directly. Either way, your number moves. According to IDCARE, about 90% of SIM swap attacks succeed without any interaction from the victim at all. You don’t click anything. You don’t approve anything. The first sign is your phone dropping to no service.

Stage 3: they intercept everything. With your number live on their SIM, every SMS 2FA code and password-reset link arrives on their screen. They reset your email first, because email resets everything else, then work through your accounts in order of value. The FBI’s IC3 logged 2,026 SIM swap complaints with $72.6 million in losses in 2022 — and SIM swapping remained one of the top five cyber threats reported in the FBI’s 2025 annual report. The numbers fluctuate year to year, but the threat has never left the list.

Why crypto holders are prime targets

Security firm Bitsight lists cryptocurrency holders among the most frequent SIM-swap targets, and the logic is cold arithmetic. A hijacked bank account triggers fraud departments and reversals. A hijacked exchange account triggers a withdrawal to an address the attacker controls, and on-chain transfers are final. There is no chargeback to file and no fraud department to call. The money is simply gone.

Once the number moves, the drain can start within minutes: SMS codes for the exchange login and the password reset both go to the attacker now. Attackers rehearse the sequence in advance. The victims are still restarting their phones.

No one is too prominent to be a target, either. In 2019, attackers SIM swapped Jack Dorsey, then CEO of Twitter, and posted from his own account through his hijacked number. If he can lose his number, the identity checks protecting yours deserve some skepticism.

The specific weak link is SMS 2FA on accounts that hold money. It feels like a second lock, but if your number can reset the password, the attacker doesn’t need your password at all. The second factor and the recovery path just moved to a stranger’s pocket together. Our wallet security 101 guide covers the broader principle: anything recoverable by phone number is only as strong as your carrier’s support script.

Warning signs you’re being SIM swapped

Speed is the whole defense once an attack starts, so know the signals:

  • Your phone suddenly shows no service or SOS only, in a place where you normally have coverage.
  • Texts and calls stop arriving. Friends say your number rings but you never pick up.
  • You get “new login” or “activity elsewhere” alerts from accounts you haven’t touched.
  • You’re abruptly locked out of your email or exchange account.
  • Your carrier notifies you of a SIM change or number transfer you didn’t request.
  • Unauthorized charges appear on cards or accounts tied to your number.

One of these alone can be a glitch. Two together, especially the dead phone plus a login alert, means you should be moving, not troubleshooting your signal.

How to protect yourself

Prevention is mostly a one-afternoon project, and the order below is roughly the order of impact.

  1. Turn on your carrier’s SIM lock. Verizon’s SIM Protection is free, blocks all SIM changes while enabled, and enforces a 15-minute delay after you disable it before any swap can happen. Support reps cannot switch it off for you, which is exactly the point: the feature assumes the person on the phone might not be you. AT&T and T-Mobile offer their own SIM and port-out locks. Enable it today.
  2. Replace SMS 2FA with an authenticator app or hardware security key on everything that touches money. Authenticator codes are generated on your device, not sent to your number, so a stolen number gets the attacker nothing. A hardware key is stronger still.
  3. Remove your phone number as a recovery method from your email and exchange accounts. This one is easy to miss: you can use an authenticator for login and still leave SMS recovery active, which quietly puts the number back in charge.
  4. Set a carrier account PIN so that “knows my birthday” stops being enough to impersonate you to support.
  5. Share less. Your date of birth plus your address plus your carrier is the attack kit; every public scrap makes the stage 2 call easier. Our wallet security best practices apply the same thinking to your wallet setup.

What a SIM swap can and can’t reach

The blast radius of a hijacked number is exactly the set of accounts that trust that number. Map yours:

AccountReachable via SIM swap?Why
Exchange account with SMS 2FAYesCodes and password resets go to the attacker’s SIM
Email with phone-number recoveryYesAnd email then resets nearly everything else
Bank account with SMS one-time codesYesSame interception, though banks can sometimes reverse fraud
Self-custody wallet (Solflare)NoKeys derive from your seed phrase; there is no phone-number recovery to hijack

The last row deserves the explanation. In a self-custody wallet, your private key is derived from your seed phrase, and that’s the entire chain of custody. There is no “recover via phone” flow and no support line that can hand your wallet to a convincing stranger. A hijacked number has nothing to reset. The attack surface a SIM swapper exploits simply doesn’t exist.

Two honest caveats before you relax. First, this cuts both ways: you are the recovery mechanism. Lose the seed phrase and nobody, including Solflare, can restore your wallet, which is why backing it up properly is not optional homework. Second, a SIM swap is not phone theft. A stolen unlocked phone with a wallet app, or a seed phrase in cloud notes your hijacked number can reset access to, are different attacks with different defenses. Self-custody removes the number from the equation only if the seed phrase never depends on it. For holdings you rarely touch, a hardware wallet takes the keys off internet-connected devices entirely; Solflare pairs with hardware wallets natively.

No service right now? The emergency runbook

If your phone just died and a login alert followed, work this list in order. Minutes matter.

  1. Call your carrier’s fraud line from another phone and demand the swap be reversed and the line locked. Verizon: *611 or 1-800-922-0204. AT&T: 1-800-331-0500. T-Mobile: 1-800-937-8997.
  2. From a device you control, change your email password first and remove your phone number from its recovery options. Email is the master key; take it back before anything else.
  3. Lock or freeze your exchange accounts. Most major exchanges have an emergency lock or freeze option in their security or support pages. Expect support to place a temporary withdrawal hold after an emergency freeze while they verify you; that delay protects the funds.
  4. Rotate passwords on every account that used SMS 2FA, switching each one to an authenticator app as you go.
  5. If your exchange funds survived, consider moving long-term holdings to self-custody, where a phone number can’t reach them regardless of what the attacker tries next.
  6. File the reports. Open a fraud case with your carrier and file with the FBI’s Internet Crime Complaint Center. The paper trail matters for recovery and for any dispute that follows.

Keep your long-term holdings out of reach

The cleanest defense against SIM swapping is having less that a phone number can touch. Coins in self-custody sit behind your seed phrase, not behind a carrier’s verification questions — and no support call can hand them to a convincing stranger. Solflare’s security is built around exactly that model: your keys live on your device, and nobody else can reach them regardless of what your carrier does.

The trade is real. The keys are fully yours, which means guarding the seed phrase is fully yours too. For most people who’ve just read this article, that trade is an easy yes.

FAQs

Can you protect yourself from SIM swapping?

Yes, and the two highest-impact moves are free: enable your carrier’s SIM lock (such as Verizon’s SIM Protection) so no swap can be processed, and replace SMS 2FA with an authenticator app on every account that touches money. Removing your phone number as a recovery method from your email closes the biggest remaining door.

How do I know if I've been SIM swapped?

The classic first sign is your phone dropping to no service or SOS only while everyone around you has coverage. Texts and calls stop, then login alerts arrive from accounts you haven’t touched, and you find yourself locked out of email or your exchange. A carrier notice about a SIM change you didn’t request confirms it.

What happens when someone SIM swaps you?

Your phone number activates on the attacker’s SIM, so every SMS code and password-reset link goes to them instead of you. They typically take your email first, then use it and the intercepted codes to reset and drain financial accounts. Your own phone goes dead for the duration.

Does SIM swapping work on eSIM?

Yes. An eSIM is a digital SIM profile rather than a physical card, but the number can still be transferred to an attacker through the same carrier processes; Verizon confirms its SIM swapping guidance covers eSIM profiles. Carrier-level protections like SIM locks apply to eSIMs too.

Is SMS 2FA safe for crypto?

It’s the least secure form of two-factor authentication, because it trusts your phone number and phone numbers can be stolen through your carrier. For low-stakes accounts it’s better than nothing. For anything holding money, use an authenticator app or a hardware security key instead.

Can a SIM swap steal crypto from a self-custody or hardware wallet?

No. Self-custody wallet keys derive from your seed phrase, not your phone number, so there’s no recovery flow for a hijacked number to exploit. The exception is self-inflicted: if your seed phrase sits in cloud storage that your phone number can reset access to, the swap reaches it indirectly.

Your seed phrase can't be SIM swapped.

Self-custody wallet. No phone-number recovery. No carrier’s support script standing between you and your funds.

Share this Crypto 101: