SIM swap attack crypto how SMS two factor gets hacked
A SIM swap attack is one of the most effective ways to drain a cryptocurrency exchange account. It does not require hacking the exchange, nor does it require malware on your phone. It exploits a human weakness in the telecom system.
Here is how the attack chain works.
How the attacker sets it up
The attacker first collects personal information about you. Data breaches supply most of this material; social media accounts provide the rest - birth dates, email addresses, sometimes even your mother's maiden name. The attacker does not need much.
They then call your mobile carrier, pretending to be you. They claim to have lost their phone or their SIM card. They provide the stolen personal details to verify their identity. If the carrier agent is convinced, they port your phone number to a new SIM card in the attacker's possession. Your phone goes dead. You lose service. Most people assume it is a network glitch and wait for it to come back.
How the exchange gets drained
The attacker now controls your phone number. Any SMS message sent to your number reaches their device, including two-factor authentication codes from your crypto exchange.
The attacker visits the exchange login page and clicks "forgot password." The exchange sends a password reset link or code to your phone number. The attacker receives it, sets a new password, and logs in. If your account requires SMS 2FA to withdraw funds, the attacker triggers a withdrawal. The exchange sends the confirmation code. The attacker enters it. The funds move to a wallet they control. The entire process can take under ten minutes, and you may not notice your phone is dead until the funds are gone.
Why SMS 2FA is weak
SMS was designed in the 1990s for person-to-person text messaging. It was never built for security. The vulnerability is not in the SMS protocol itself; it is in how carriers handle SIM changes. A determined attacker can socially engineer most carrier support agents. Some carriers offer no verification beyond basic personal details. Others can be tricked even with stronger checks. The human element is the weakest link.
What to use instead
The only reliable fix is to stop using SMS for exchange 2FA entirely.
Authenticator apps generate codes on your device. They do not send anything over the network, so an attacker who controls your phone number cannot intercept these codes. Google Authenticator, Authy, and Microsoft Authenticator all work the same way: you scan a QR code from the exchange once, and the app produces a new six-digit code every thirty seconds.
Hardware security keys are even stronger. A YubiKey or similar device must be physically connected to your computer or phone to authorize a login. No code is displayed. No code can be intercepted. No social engineering can bypass it, because the attacker would need your physical device. Most major exchanges support both options, and some now require them for high-value accounts.
One additional defense: a carrier PIN
Some mobile carriers let you set a PIN or password on your account. The support agent must verify this PIN before making any changes. This makes social engineering harder because the attacker does not know your PIN. It is not a complete solution - PINs can be reset through other channels, and some carriers do not enforce them consistently - but it adds one more barrier. Call your carrier and ask about "port-out protection" or a "SIM change PIN." Set it to something you have not used anywhere else.
What to do if you are attacked
If your phone suddenly loses service and you did not cause it, act immediately. Contact your carrier on another device and ask them to freeze your account. Then contact your exchange. Tell them you are the victim of a SIM swap, and ask them to lock your account and reverse any pending withdrawals. The faster you move, the better your chances. Exchanges have different policies on reversing transactions; some will not reverse them at all. That is why prevention matters more than recovery.
SMS 2FA is convenient. It is also the easiest 2FA method to break. Switch to an authenticator app or a hardware key today. The ten minutes it takes could save everything in your account.
Not financial advice. dgnx.finance publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.