A SIM swap attack does not directly target a crypto wallet or exchange account. It targets the phone number sitting behind them. By convincing a mobile carrier to transfer that number to a SIM card the attacker controls, everything relying on that number for identity or verification becomes reachable, including bank accounts, email, and any exchange account still using SMS based codes as a second factor of authentication.
The FBI's Internet Crime Complaint Center recorded 982 SIM swap complaints in 2024 with reported losses of just under twenty six million dollars, though that figure understates the true scale, since SIM swapping is typically the access step in a larger crime and the resulting financial theft is often booked under separate categories once the funds are moved. In March 2025, T-Mobile was ordered to pay thirty three million dollars in arbitration after a single SIM swap allowed attackers to drain a customer's cryptocurrency wallet, illustrating how catastrophic one successful swap can be for a crypto holder specifically.
How the attack is carried out
Gathering information on the target
Before contacting a carrier, an attacker typically gathers enough personal information to convincingly impersonate the victim, often sourced from prior data breaches, social media activity, or targeted phishing. Public indicators that someone holds significant crypto, discussion in online communities, visible wallet addresses, or a public profile tied to trading, can make that person a specific target for this kind of research.
Social engineering the carrier or an insider
With enough personal detail in hand, the attacker contacts the victim's mobile carrier, claims the original SIM was lost or damaged, and requests the number be transferred to a new SIM card in their possession. Some documented cases have involved a bribed or complicit carrier employee completing the transfer directly, bypassing the need to social engineer a support representative at all, which is part of why regulators have pushed carriers to strengthen their internal verification procedures for this specific request.
Taking over accounts through the stolen number
Once the number is active on the attacker's device, they can intercept SMS verification codes and use them to reset passwords or approve login attempts on email, exchange, and wallet related accounts. Email is often the first target, since a compromised email account frequently allows further password resets across every other service linked to it, creating a cascading takeover that can reach a crypto exchange account within minutes of the initial swap.
SMS based two factor authentication is significantly weaker than app based or hardware based authentication specifically because the phone number itself, not just the device, can be redirected without the victim's knowledge until service unexpectedly stops working.
eSIM swapping: a newer variant of the same attack
The rise of eSIM technology, which stores a carrier profile digitally rather than on a physical removable card, has introduced a faster version of the same underlying attack. Instead of requesting a physical SIM replacement, an attacker convinces a carrier, or in some documented cases directly manipulates a carrier's self service app or web portal, to transfer the eSIM profile to a new device. Because no physical card needs to be shipped or swapped in person, an eSIM based takeover can be completed entirely remotely and often faster than a traditional SIM swap, sometimes within minutes of the attacker gaining sufficient account access. This shift has pushed some carriers to add extra verification specifically for eSIM transfers, though adoption of that additional protection is not universal across every carrier and every plan type.
A realistic scenario: from a data broker leak to a drained exchange account
- An earlier, unrelated data breach at an online retailer exposes a victim's name, home address, date of birth, and the last four digits of a payment card, all of which are later aggregated and sold on a criminal marketplace.
- An attacker purchases this data and combines it with publicly available social media information to build a convincing enough profile to answer a mobile carrier's standard identity verification questions.
- The attacker contacts the carrier through an online chat or phone call, claims the original phone was lost, and successfully requests the number be transferred to a new SIM or eSIM.
- Within minutes, the attacker uses the hijacked number to receive a password reset code for the victim's email account, then uses the compromised email to trigger further password resets on a cryptocurrency exchange account.
- The exchange account's SMS based two factor authentication, tied to the same hijacked number, approves the login, and the attacker withdraws funds to a new wallet before the victim notices their phone has lost service.
Every step in this chain depends on a piece of the victim's identity that had already leaked somewhere else, months or years earlier, through a breach entirely unrelated to their crypto holdings. This is part of why monitoring for personal data exposure matters even for someone who has never directly interacted with a crypto specific scam.
SIM swap attacks compared to phishing based account takeover
Phishing based account takeover generally requires the victim to actively participate in their own compromise, entering a password or a one time code directly into a fake page. A SIM swap requires no action from the victim at all once the carrier has been convinced to transfer the number. This makes SIM swapping considerably harder for an individual to prevent through vigilance alone, since there is no fraudulent email or suspicious link for a cautious person to notice and avoid. The defense instead has to happen at the level of the carrier account and the authentication methods tied to it, rather than at the level of an individual message or click.
Recognizing an attack in progress
- A phone suddenly loses cellular service entirely, showing no bars or an emergency calls only status, with no clear explanation such as a known outage.
- Unexpected password reset emails or login notifications arrive for accounts you did not attempt to access.
- A carrier confirms a SIM change or number transfer request that you did not initiate.
- You are logged out of an email, exchange, or wallet related account without warning.
If a phone unexpectedly loses service, the correct response is to treat it as a likely SIM swap in progress rather than a technical glitch, and to move quickly to secure email and exchange accounts from another device while contacting the carrier directly. Waiting to see if service returns on its own gives the attacker more time to complete an account takeover.
Reducing exposure before an attack happens
- Set a PIN or additional verification requirement directly with your mobile carrier for any SIM change or port request, a step CISA specifically recommends as a baseline defense against SIM swapping.
- Move away from SMS based verification wherever possible, replacing it with an authenticator app or a hardware security key for email, exchange, and wallet related accounts.
- Avoid publicly linking your identity to visible crypto holdings, since that visibility is part of what makes a specific individual worth the effort of a targeted SIM swap.
- Use a dedicated, non guessable email address for exchange accounts that is not reused across other services, limiting the cascading damage if one account is compromised.
It is also worth contacting a mobile carrier proactively, before any incident occurs, to ask specifically about the protections available on the account.
- Whether a port out or SIM change PIN, separate from a standard account password, can be set on the account and whether it applies to both physical SIM and eSIM transfer requests.
- Whether the carrier requires in person identity verification at a retail location for any SIM or number transfer request, and whether that requirement can be enabled as a standing account preference.
- Whether the carrier sends an independent notification, such as an email to an address not tied to the phone number itself, whenever a SIM or number change is requested.
- Whether a temporary freeze can be placed on the account that blocks any SIM or number changes until manually lifted by the account holder in person or through a verified separate channel.
Once an exchange account has actually been compromised following a SIM swap, the response shifts from prevention to containment and evidence gathering, which is covered in detail in our guide on what happens when an exchange account is compromised. The overlap between these two topics is significant, since a SIM swap is frequently the specific mechanism behind an exchange account takeover rather than a separate, unrelated event.
What to do after regaining control of your number
- Contact your mobile carrier to confirm the fraudulent transfer has been fully reversed and ask for a written incident reference number for your records.
- Change the password on every account that uses the phone number for verification or recovery, starting with email, since a compromised email is frequently the pivot point to everything else.
- Review login history and connected devices on your email and exchange accounts for any session that does not match your own activity, and revoke any you do not recognize.
- File a report with your national cybercrime reporting body and, if a crypto exchange account was affected, follow the exchange specific reporting steps covered in our guide on exchange account compromise.
Recovering the phone number itself is only the first step. Every account that relied on it for verification during the window the attacker had control should be treated as potentially exposed, not just the one account that was actually drained.
Frequently asked questions
The underlying goal is the same, hijacking a phone number, but an eSIM transfer can often be completed entirely remotely through a carrier's digital systems, without needing to ship or physically swap a card, which can make it faster and in some cases harder for a carrier's fraud systems to catch in time.
Once a number is successfully transferred, an attacker with prior knowledge of the target's accounts can often complete password resets and drain an exchange account within minutes, which is why fast recognition of lost cellular service matters more than almost any other warning sign.
A carrier PIN significantly raises the difficulty of a successful swap and is recommended by CISA as a baseline protection, but it is not absolute, since insider assisted swaps and sufficiently convincing social engineering have both been documented as bypassing PIN requirements in some cases.
Yes, meaningfully. An authenticator app or hardware key is tied to a specific device rather than a phone number, so it cannot be redirected through a carrier level SIM transfer, removing the specific attack path a SIM swap depends on.
Immediately use a different device or a landline to contact your mobile carrier and report the unauthorized transfer, and simultaneously attempt to secure your email and any exchange accounts from that other device before the attacker can complete further password resets.
Sources and further reading
- Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public · FBI Internet Crime Complaint Center (IC3)
- Mobile Communications Best Practice Guidance · Cybersecurity and Infrastructure Security Agency (CISA)
- SIM Swap Scam Statistics 2025: $26M Lost & Rising Threats · DeepStrike