MrDeFi
Security & Scams2026-04-024 min read

What Is a SIM Swap Attack? How Hackers Hijack Your Phone

How SIM swap attacks bypass SMS-based 2FA to hijack phone numbers and seize control of crypto accounts and email.

A SIM swap attack is a fraud in which an attacker convinces or bribes a mobile carrier into transferring a victim's phone number to a SIM card the attacker controls, allowing them to intercept calls and text messages — including SMS-based two-factor authentication codes — and use that access to take over email, exchange, and other accounts tied to the phone number.

SIM swapping is particularly dangerous for crypto holders because a phone number is often the weakest link in an otherwise reasonably secure setup — someone might use a strong password and even enable 2FA, but if that 2FA relies on SMS, an attacker who controls the phone number controls the second factor too.

How the attack works

The core of a SIM swap attack isn't a technical hack of the phone itself — it's social engineering or insider fraud directed at the mobile carrier. The general sequence:

  1. Information gathering. The attacker collects personal details about the victim — full name, date of birth, address, and sometimes the last four digits of a social security number or account PIN — often sourced from data breaches, phishing, or public social media information.
  2. Contacting the carrier. Posing as the victim, the attacker contacts the mobile carrier's customer support (by phone, chat, or occasionally in person at a retail store) and requests that the phone number be ported to a new SIM card, claiming a lost or damaged phone.
  3. Bypassing verification. Using the gathered personal information — or in some documented cases, a bribed or complicit carrier employee — the attacker passes the carrier's identity verification and the transfer is approved.
  4. Number hijacked. The victim's phone suddenly loses service entirely (a key warning sign), while the attacker's device now receives all calls and texts, including SMS 2FA codes and password-reset links, sent to that number.
  5. Account takeover. The attacker uses "forgot password" flows on email, exchange, and social media accounts, intercepting the SMS or call-based verification to reset credentials and lock the real owner out, then moves to drain any accessible crypto holdings.

Why crypto holders are specifically targeted

Crypto transactions are irreversible, and many exchange accounts and even some wallet recovery flows still rely on phone-number verification as a fallback. Attackers who specifically target crypto holders will often research public information — social media posts about crypto holdings, conference attendance, or NFT ownership — to identify likely high-value targets before attempting a SIM swap, making this a more targeted attack than opportunistic phishing.

Warning signs

Sudden, complete loss of cell service (no calls, texts, or data) with no clear cause is the primary red flag — this is different from a dead zone or an outage, since it typically doesn't resolve on its own. Unexpected password-reset or 2FA emails/texts for accounts you didn't try to access, or notifications of a "new device" logging into an email or exchange account, are also strong indicators an attack is already underway and require an immediate, direct response with your carrier and affected platforms rather than waiting to see if service returns.

SMS 2FA vs. SIM swap risk

Factor SMS-based 2FA App-based or hardware 2FA
Vulnerable to SIM swap Yes — codes route to the hijacked number No — tied to a device or app, not phone number
Carrier dependency High None
Ease of setup Very easy Slightly more setup required
Recommended for crypto accounts Avoid where alternatives exist Preferred

Our fuller comparison of authenticator apps vs. SMS 2FA covers the tradeoffs in more depth, and the glossary has background on how wallets and account recovery generally work.

Prevention

The most effective defense is removing the phone number as a dependency for anything valuable: use an authenticator app or hardware security key for 2FA instead of SMS wherever a platform supports it, and avoid linking a phone number to exchange accounts or email as a recovery method if an alternative exists. Set up a carrier PIN or port-freeze with your mobile provider specifically to block SIM transfers without additional, harder-to-fake verification (see our step-by-step guide on preventing SIM swap attacks). Avoid publicly disclosing crypto holdings or wallet activity, since this kind of visibility is what draws targeted attacks in the first place — general wallet OPSEC practices apply directly here. Use a hardware wallet for significant holdings so that even a full account takeover on an exchange doesn't expose self-custodied assets, and review our broader DeFi wallet security guide for related habits.

Bottom line

A SIM swap attack doesn't require breaking any encryption or hacking your device — it exploits a carrier's identity verification process to hijack the one credential, your phone number, that too many accounts still treat as a trustworthy second factor. Removing SMS dependency from your most valuable accounts, and locking down your carrier account with a port-freeze, closes off this attack regardless of how much personal information an attacker manages to gather about you.

Related articles

This article is for educational purposes only and is not financial advice. DeFi involves significant risk, including total loss of funds. Always do your own research.