Security
Oct 9, 2026

SIM Swap Attack: How It Works and How to Protect Your Crypto

What a SIM swap attack is, how criminals hijack phone numbers to drain crypto accounts, real cases, the FCC rules and the steps that protect you.

SIM Swap Attack: How It Works and How to Protect Your Crypto

A SIM swap attack is when a criminal convinces your mobile carrier to move your phone number onto a SIM card they control. From that moment your calls and texts, including password-reset links and SMS login codes, go to the attacker, who uses them to break into your email, exchange and bank accounts.

Crypto holders are a favourite target because stolen coins move fast and are hard to claw back. This guide explains how SIM swaps work, how common they are, two court cases that show the pattern, what the US Federal Communications Commission (FCC) has done about them, and the steps that actually protect you.

What a SIM swap is

The FCC defines SIM swapping as a bad actor convincing "a victim's wireless carrier to transfer the victim's service from the victim's cell phone to a cell phone in the bad actor's possession". A close cousin is port-out fraud: the attacker opens an account with a different carrier in the victim's name and has the number transferred, or "ported out", to it (FCC news release, 15 November 2023).

Either way, the attacker never needs to touch your phone. They only need your carrier to believe they are you, or a carrier employee willing to help.

How a SIM swap attack works

The FBI describes three routes into the carrier (FBI IC3, February 2022):

  • Social engineering. The criminal impersonates the victim and talks the carrier into switching the number to a new SIM. The FCC notes scammers gather the needed details from social media, or buy them from hackers: address, date of birth, account PINs or passwords, and the last four digits of a Social Security number.
  • Insider help. The criminal pays a carrier employee to make the switch.
  • Phishing carrier staff. Employees are tricked into installing malware that lets the attacker perform swaps directly.

Once the number is moved, the attack is a race. The criminal sends "Forgot password" requests to every account tied to the number, receives the reset links and one-time codes by text, and locks the owner out. The FCC describes the attacker trying to reset "as many of the victim's financial and social media accounts as possible before the victim realizes they have lost service".

The FBI also warns about two lighter-touch variants: call forwarding and simultaneous ring, where the criminal gets the carrier to forward calls or ring a second phone, which can also defeat phone-based verification (FBI IC3, April 2024).

How common SIM swap attacks are

The most detailed public figures come from FBI complaint data. From January 2018 to December 2020, IC3 received 320 SIM swap complaints with adjusted losses of about $12 million. In 2021 alone, it received 1,611 complaints with adjusted losses of more than $68 million. The FBI's warning at the time was specifically about criminals using SIM swaps to steal from "fiat and virtual currency accounts".

Complaint data only captures what victims report, so treat these as a floor rather than a full count.

Notable SIM swap cases

Two recent US prosecutions show how the attack is used in practice:

  • The SEC's X account (January 2024). Attackers took control of the US Securities and Exchange Commission's account on X and falsely announced that Bitcoin exchange-traded funds had been approved. According to the Justice Department, Eric Council Jr. carried out the SIM swap by printing a fake ID card with the victim's personal details and using it to take over the victim's phone number. Bitcoin rose by more than $1,000 after the false post, then fell by more than $2,000 after the correction. Council was sentenced on 16 May 2025 to 14 months in prison (US Department of Justice).
  • Crypto thefts linked to Scattered Spider. Noah Michael Urban of Palm Coast, Florida, was sentenced on 21 August 2025 to 10 years in federal prison. Prosecutors said that from August 2022 to March 2023 he stole cryptocurrency from at least 59 victims using SIM swaps, with total losses above $13 million. He was ordered to pay $13 million in restitution (US Attorney's Office, Middle District of Florida).

The SEC case is a useful reminder that being a large, well-resourced organisation does not help if a phone number is the weak link.

What the FCC rules require

On 15 November 2023 the FCC adopted rules aimed at SIM swap and port-out fraud. They require wireless providers to use secure methods to authenticate customers before moving a number to a new device or carrier, to notify customers immediately when a SIM change or port-out request is made, and to take further steps against this fraud.

The legal status is more nuanced than many articles suggest. The rules were published in the Federal Register on 8 December 2023, but the provisions that involve information collection, including the customer notification requirements, were delayed until the FCC announced an effective date (Federal Register). As of 7 October 2026, the SIM-change section of the rules, 47 CFR 64.2010(h), still lists the notification paragraphs as "reserved" and states that compliance "will not be required until this paragraph is removed or contains a compliance date" (eCFR). That text also bars carriers from authenticating SIM changes with readily available biographical or account information.

In practice, carriers already offer account PINs and SIM or port-out locks. Do not wait for regulation to switch them on.

How to protect yourself from a SIM swap

You cannot stop criminals from targeting you, but you can make a hijacked phone number useless to them:

  1. Lock your mobile account. Set a carrier account PIN or passcode, and ask your carrier to block SIM changes and number transfers unless you lift the lock yourself. The FBI also recommends asking the carrier to disable call forwarding and simultaneous ring.
  2. Remove SMS as a login or recovery method on exchanges, email and password managers. US government guidance from NIST classes SMS and voice codes as a "restricted" authenticator (NIST SP 800-63B-4).
  3. Use passkeys or a hardware security key. CISA notes that SIM swap attacks are not applicable to FIDO/WebAuthn authentication, which it calls the gold standard (CISA). An authenticator app is the next best option.
  4. Secure your email first. Your email account resets everything else, so give it your strongest protection.
  5. Keep your holdings private. The FBI's first tip is not to advertise crypto ownership on social media or forums. Attackers pick targets who look worth the effort.
  6. Set a unique voicemail password and limit the personal details you post publicly.

Holding long-term crypto in a non-custodial wallet also helps, because a self-custody wallet is controlled by a private key rather than a phone number. That shifts the risk to protecting your seed phrase, which should never be stored in your phone's notes, photos or cloud backup.

Warning signs and what to do

The FCC says the first sign is usually your phone going dark or only allowing emergency calls. Other clues are texts about a SIM change you did not request, or login alerts arriving while your phone has no signal.

If you suspect a SIM swap, the FBI and FCC advise:

  1. Contact your carrier immediately from another phone to regain control of the number.
  2. Change passwords on your email and financial accounts, starting with email.
  3. Contact your exchanges and banks and ask them to freeze withdrawals and flag suspicious logins.
  4. Report it to local police and, in the US, to the FBI at ic3.gov. You can also file a complaint with the FCC, and the FCC suggests placing a fraud alert on your credit reports.

A SIM swap is usually the first step in a wider account takeover, so check every account that used your phone number, not just the one where you noticed the problem.

Frequently asked questions

What is a SIM swap attack?

It is a scam in which a criminal persuades your mobile carrier to move your phone number to a SIM card they control. They then receive your calls and texts, including SMS login codes and password-reset links, and use them to take over your accounts.

How do I know if I have been SIM swapped?

The most common sign is your phone suddenly losing service or only allowing emergency calls. You may also get a notice about a SIM change you did not request, or login and password-reset alerts you did not trigger.

Can a SIM swap steal crypto from a hardware wallet?

Not directly. A hardware or other self-custody wallet is controlled by a private key, not a phone number. The risk is to exchange accounts and email that use SMS codes, and to any seed phrase you stored on your phone or in cloud backups.

Does an authenticator app protect against SIM swaps?

Yes, against the SIM swap itself, because app codes are not sent over the phone network. Passkeys and hardware security keys go further, because they also resist phishing.

Are carriers required by law to stop SIM swaps?

The FCC adopted rules in November 2023 requiring secure authentication before SIM changes and immediate customer notifications. As of 7 October 2026, the federal regulation text says compliance with the SIM-change section is not yet required until a compliance date is set, so check what protections your carrier offers.

Keep reading

This article is educational and is not legal, security or financial advice. Complaint figures are from FBI IC3 announcement I-020822-PSA (February 2022); case details are from US Department of Justice releases dated 16 May 2025 and 21 August 2025; the status of 47 CFR 64.2010(h) was checked against the eCFR text current on 7 October 2026. Sources checked on 9 October 2026.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.