On January 9, 2024, the official X account of the U.S. Securities and Exchange Commission announced that spot bitcoin ETFs had been approved. Bitcoin jumped on the headline, then fell when the SEC said the post was fake. The agency later confirmed how it happened: nobody breached X, and nobody breached the SEC’s networks. An attacker had taken control of the phone number attached to the account through a SIM swap — a manipulation of an ordinary carrier support process — and used it to reset the account’s password. The real ETF approval arrived a day later. The lesson arrived immediately.
Every SIM swap crypto attack rests on the same quiet assumption, which is worth stating plainly so it can be rejected: that your phone number is you. It is not. A phone number is a routing label leased from a carrier, and the carrier can reassign it to any SIM card in minutes — that is a feature, built for the day you lose your phone. Every SMS code, every “we’ll text you a reset link”, every account that lists your number as a recovery method inherits that feature. If your crypto sits anywhere downstream of it, a support-desk conversation you will never hear is part of your security model.
What a SIM swap actually is
A SIM swap is an attack in which someone convinces or bribes a mobile carrier into moving a victim’s phone number onto a SIM card the attacker controls. Nothing on the victim’s phone is hacked; the device is never touched. The attacker first gathers personal details from data breaches, social media, or phishing, then calls carrier support impersonating the victim with a story about a lost or broken phone. In other documented cases, the attacker simply pays a retail employee to run the transfer from the inside, or ports the number to a different carrier altogether.
From the moment the swap completes, the victim’s handset shows “No service” while the attacker’s device receives every call and text sent to the number. The playbook that follows is fast and standardized: request a password reset on the victim’s email, approve it with the SMS code that now arrives on the attacker’s phone, then work outward through everything that email controls — exchange accounts first. SIM-swap thefts are routinely executed overnight, finished before the victim understands why their phone has gone quiet.
A $24 million theft, a federal agency, and years of warnings
None of this is theoretical, and none of it is new. In 2018, crypto investor Michael Terpin lost roughly $24 million in tokens after his number was swapped — with inside help at a carrier store, according to his account — and his lawsuit against AT&T became one of the most widely reported SIM-swap cases of its era. A court later awarded him roughly $75 million in damages against one of the men behind the theft.
The SEC incident in January 2024 showed the other end of the spectrum: a target with no funds to steal, attacked for its voice. The number attached to the agency’s X account was moved to a new SIM, and by the SEC’s own account, extra multi-factor protection on the account had been switched off months earlier — so control of the number alone was enough to reset the password and post. Federal prosecutors charged a man for the swap later that year. If a support-desk maneuver can briefly move the bitcoin market by hijacking a regulator, an exchange account protected by SMS is not a hard target.
The FBI’s Internet Crime Complaint Center has warned about the pattern for years, logging more than $68 million in reported SIM-swap losses in 2021 alone — several times the combined total of the three years before it. Regulators have since pushed carriers toward stricter identity checks before a number moves, and that helps at the margin. But the structural fact stands: a number that can be reassigned through a support workflow can be reassigned through a manipulated one.
Why crypto is the prime target
SIM swapping predates crypto — it has been used against bank accounts and social media for years — but crypto changed the economics of the attack. A fraudulent bank transfer can be flagged, frozen, and often reversed. A crypto withdrawal clears in minutes and is final; by the time the victim regains their number, the funds have crossed chains or entered a mixer. For an attacker holding a stolen number for a few hours, an exchange account guarded by SMS is the most valuable door that number opens.
Fairness requires a caveat: SMS two-factor authentication is still better than a password alone, and it defeats the bulk of remote credential-stuffing attacks. Exchanges have improved, too — app-based authenticator codes, hardware security keys, withdrawal address allowlists, and time-delayed withdrawals are widely available on major platforms, and all of them are worth enabling today. The problem is not that SMS 2FA does nothing. The problem is that it fails against precisely the attacker who has taken your number — and that is precisely the attacker crypto attracts.
Any account that can be recovered with a phone number is ultimately controlled by whoever your carrier believes is you.
Hardening the accounts that still depend on your number
Some services will insist on keeping a phone number attached. The goal is to shrink what that number can do:
- Remove your number from recovery flows, starting with your primary email account — it is the hub every other reset routes through. If an account can be recovered by SMS, an attacker with your number does not need your password.
- Replace SMS 2FA with an authenticator app or a hardware key. Codes generated on-device never travel through the carrier network, and a FIDO2 hardware key resists phishing outright.
- Lock your number at the carrier. Most major carriers offer a port-out PIN, a number lock, or both. Neither is unbeatable, but they raise the cost of the support-desk con considerably.
- Use a dedicated email address for exchange accounts — one that is published nowhere and has no phone number attached to it.
- Treat sudden loss of signal as an incident. If your phone drops to “No service” while phones around you work, call your carrier from another line and freeze your exchange accounts first, not last.
These steps shrink the attack surface; they cannot eliminate it. The root issue is architectural — a recovery chain that terminates at a support desk you do not control.
The structural fix: keys you hold, not a number you rent
Self-custody changes the shape of the problem rather than shaving its edges. A self-custody wallet has no account to recover: control of the funds is possession of the private keys, and no support desk anywhere can reassign a private key. Ownbit is built on exactly that premise — keys are generated and stored on your device, there is no phone-number-based recovery path at all, and the wallet’s security model assumes Ownbit’s own servers should never be able to touch funds: they coordinate signing but never hold keys.
Honesty requires the next sentence too: self-custody trades carrier risk for key-management risk. A single seed phrase guarding everything is its own single point of failure — one photographed backup or one phished phrase, and the outcome looks like a SIM swap with extra steps. The answer is not returning to SMS; it is splitting control. In a multisig wallet, moving funds requires signatures from multiple independent keys — commonly two of three, a threshold we have argued is the sweet spot for personal custody. An attacker who compromises any single channel — one phished phrase, one stolen phone, or, for that matter, one swapped SIM used to social-engineer a signer — still cannot meet the threshold alone.
SIM swap crypto attacks end where key possession begins. Every key in an Ownbit multisig is a standard BIP39 seed phrase, so the arrangement remains recoverable without Ownbit’s servers. The contrast between the two models is the entire argument of this article: one concentrates control in a credential a third party can reassign in minutes; the other distributes control across keys that only you and the people you choose have ever possessed.
Frequently asked questions
What is a SIM swap attack in crypto?
A SIM swap is an attack in which a criminal convinces or bribes a mobile carrier into transferring your phone number to a SIM card they control. From that moment they receive your SMS two-factor codes and password-reset messages, which is often enough to take over email and exchange accounts and withdraw crypto. Because crypto transfers are final, the losses are rarely recoverable.
How do I know if I have been SIM swapped?
The clearest sign is your phone suddenly showing “No service” or “SOS only” while phones around you work normally, often followed by password-reset emails you did not request. If that happens, act in minutes: call your carrier from another line, lock or freeze your exchange accounts, and change your email password from a device you trust.
Does a hardware security key stop SIM swap attacks?
For the accounts it protects, yes. A FIDO2 or U2F hardware key never sends codes over the carrier network, so moving your number gains the attacker nothing there. But audit every recovery path: a hardware key on the front door is worthless if the same account still allows a password reset by SMS through the back.
Can a SIM swap steal crypto from a self-custody wallet?
Not directly. A self-custody wallet such as Ownbit has no phone-number-based recovery: funds move only with signatures from private keys held on your devices, and no carrier can reassign a private key. A stolen number can still power follow-on phishing against you, which is one reason a multisig threshold — where no single approval can move funds — is a stronger default than a single key.
If some of your crypto currently sits behind an SMS code, moving it behind keys you hold is the biggest single upgrade available — and it costs an afternoon, not a fortune. Ownbit keeps keys on your device with no phone-number recovery to attack, and Ownbit MultiSig lets you split control across two or three devices so that no single compromised channel — SIM, phone, or seed phrase — can move funds alone. Every new user gets a 7-day free trial, and your keys remain yours regardless.