What a SIM swap attack is, how criminals hijack phone numbers to drain crypto accounts, real cases, the FCC rules and the steps that protect you.

A SIM swap attack is when a criminal convinces your mobile carrier to move your phone number onto a SIM card they control. From that moment your calls and texts, including password-reset links and SMS login codes, go to the attacker, who uses them to break into your email, exchange and bank accounts.
Crypto holders are a favourite target because stolen coins move fast and are hard to claw back. This guide explains how SIM swaps work, how common they are, two court cases that show the pattern, what the US Federal Communications Commission (FCC) has done about them, and the steps that actually protect you.
The FCC defines SIM swapping as a bad actor convincing "a victim's wireless carrier to transfer the victim's service from the victim's cell phone to a cell phone in the bad actor's possession". A close cousin is port-out fraud: the attacker opens an account with a different carrier in the victim's name and has the number transferred, or "ported out", to it (FCC news release, 15 November 2023).
Either way, the attacker never needs to touch your phone. They only need your carrier to believe they are you, or a carrier employee willing to help.
The FBI describes three routes into the carrier (FBI IC3, February 2022):
Once the number is moved, the attack is a race. The criminal sends "Forgot password" requests to every account tied to the number, receives the reset links and one-time codes by text, and locks the owner out. The FCC describes the attacker trying to reset "as many of the victim's financial and social media accounts as possible before the victim realizes they have lost service".
The FBI also warns about two lighter-touch variants: call forwarding and simultaneous ring, where the criminal gets the carrier to forward calls or ring a second phone, which can also defeat phone-based verification (FBI IC3, April 2024).
The most detailed public figures come from FBI complaint data. From January 2018 to December 2020, IC3 received 320 SIM swap complaints with adjusted losses of about $12 million. In 2021 alone, it received 1,611 complaints with adjusted losses of more than $68 million. The FBI's warning at the time was specifically about criminals using SIM swaps to steal from "fiat and virtual currency accounts".
Complaint data only captures what victims report, so treat these as a floor rather than a full count.
Two recent US prosecutions show how the attack is used in practice:
The SEC case is a useful reminder that being a large, well-resourced organisation does not help if a phone number is the weak link.
On 15 November 2023 the FCC adopted rules aimed at SIM swap and port-out fraud. They require wireless providers to use secure methods to authenticate customers before moving a number to a new device or carrier, to notify customers immediately when a SIM change or port-out request is made, and to take further steps against this fraud.
The legal status is more nuanced than many articles suggest. The rules were published in the Federal Register on 8 December 2023, but the provisions that involve information collection, including the customer notification requirements, were delayed until the FCC announced an effective date (Federal Register). As of 7 October 2026, the SIM-change section of the rules, 47 CFR 64.2010(h), still lists the notification paragraphs as "reserved" and states that compliance "will not be required until this paragraph is removed or contains a compliance date" (eCFR). That text also bars carriers from authenticating SIM changes with readily available biographical or account information.
In practice, carriers already offer account PINs and SIM or port-out locks. Do not wait for regulation to switch them on.
You cannot stop criminals from targeting you, but you can make a hijacked phone number useless to them:
Holding long-term crypto in a non-custodial wallet also helps, because a self-custody wallet is controlled by a private key rather than a phone number. That shifts the risk to protecting your seed phrase, which should never be stored in your phone's notes, photos or cloud backup.
The FCC says the first sign is usually your phone going dark or only allowing emergency calls. Other clues are texts about a SIM change you did not request, or login alerts arriving while your phone has no signal.
If you suspect a SIM swap, the FBI and FCC advise:
A SIM swap is usually the first step in a wider account takeover, so check every account that used your phone number, not just the one where you noticed the problem.
It is a scam in which a criminal persuades your mobile carrier to move your phone number to a SIM card they control. They then receive your calls and texts, including SMS login codes and password-reset links, and use them to take over your accounts.
The most common sign is your phone suddenly losing service or only allowing emergency calls. You may also get a notice about a SIM change you did not request, or login and password-reset alerts you did not trigger.
Not directly. A hardware or other self-custody wallet is controlled by a private key, not a phone number. The risk is to exchange accounts and email that use SMS codes, and to any seed phrase you stored on your phone or in cloud backups.
Yes, against the SIM swap itself, because app codes are not sent over the phone network. Passkeys and hardware security keys go further, because they also resist phishing.
The FCC adopted rules in November 2023 requiring secure authentication before SIM changes and immediate customer notifications. As of 7 October 2026, the federal regulation text says compliance with the SIM-change section is not yet required until a compliance date is set, so check what protections your carrier offers.
This article is educational and is not legal, security or financial advice. Complaint figures are from FBI IC3 announcement I-020822-PSA (February 2022); case details are from US Department of Justice releases dated 16 May 2025 and 21 August 2025; the status of 47 CFR 64.2010(h) was checked against the eCFR text current on 7 October 2026. Sources checked on 9 October 2026.