Skip to content
buybitcoinsmart

Glossary / Privacy & security

SIM swap

Also known as SIM swapping, SIM jacking.

Definition
A SIM swap moves your phone number onto a criminal's SIM card, handing them every SMS code and password reset that your exchange account and email depend on.

Your mobile carrier, not your exchange, is the weak point: a fooled or bribed employee can port a number in minutes. The FBI logged 1,611 SIM swap complaints in 2021 with losses above 68 million dollars, against 320 complaints in the three preceding years combined. If any account that touches your bitcoin can be recovered by text message, your phone company is effectively your custodian.

How it works

A SIM swap is a customer service transaction, executed by someone who is not the customer.

Attackers start with reconnaissance. Breached databases supply the name, address, date of birth, and last four digits of a card. Social media supplies the rest of the knowledge-based answers carriers still ask for. Public boasting about crypto holdings supplies the motive, which is why anyone who posts portfolio screenshots is on a list somewhere.

Then comes the port. There are three routes, and all three are still in use: walking into a retail store with a convincing fake ID, calling the support line and passing the verification questions, or paying an insider. Prosecutions in the United States have repeatedly involved carrier or authorized-retailer employees taking a few hundred dollars per swap, which is why "my carrier would never" is not a security model.

The moment the number moves, your handset drops to no service and the attacker's phone starts receiving. The order of operations that follows is always similar. Email first, because most providers allow a reset by SMS, and email is the master key to everything else. Then the exchange, where a password reset plus an SMS one-time code is often enough. Then the withdrawal, at three in the morning your time.

SMS was never designed for this job, and the standards bodies have said so. NIST's SP 800-63B, published in 2017, classifies one-time codes delivered over the public telephone network as a "restricted" authenticator, meaning implementers must accept and disclose the risk of exactly this attack.

Why this matters when you buy bitcoin

Every large exchange we review offers something better than SMS, and almost nobody turns it on.

Kraken supports FIDO2 security keys and a Global Settings Lock that freezes changes to security and withdrawal settings until you deliberately unlock it. Coinbase supports security keys and passkeys. Binance, Bitstamp, and Bitpanda all support authenticator-app codes at minimum. A hardware security key is the strongest of these because it is bound to the site's domain, which defeats phishing as well as SIM swapping, and it cannot be read out over a phone line.

The step people miss is the second one. Turning on an authenticator app does not help if the account can still be recovered by text, so remove the phone number as a recovery method, not just as a login factor. Check the account recovery page, not the two-factor page.

Ask the carrier for a port-out PIN or number transfer lock. In the United States, FCC rules adopted in 2023 require carriers to authenticate customers before porting a number or changing a SIM, and to notify you when either is requested. That notification is the alarm bell: if your phone loses service for no reason, treat it as an attack in progress and get to a computer.

Then there is the part no exchange setting can fix. A SIM swap can only reach coins that some company holds on your behalf. Bitcoin sitting on a hardware wallet has no phone number, no account recovery flow, and no support agent who can be persuaded. Buy on an exchange, then withdraw. That single habit takes the entire attack class off the table for everything except your trading balance.

Terpin v. Truglia, a 24 million dollar phone call

Michael Terpin's case is the one with a paper trail, and the numbers in it are public court record.

On January 7, 2018, attackers took over Terpin's phone number and drained roughly 24 million dollars in cryptocurrency. In May 2019 a California court entered a 75.8 million dollar judgment against Nicholas Truglia over the theft. Truglia was later prosecuted federally, and in December 2022 he was sentenced to 18 months in prison and ordered to pay about 20.4 million dollars in restitution. Terpin separately sued AT&T for 224 million dollars, arguing the carrier's own employee enabled the swap.

Read the ending carefully, because it is the lesson. Years of litigation produced judgments, not coins. A restitution order is a claim against whatever assets a convicted person still has, and bitcoin that has been moved and mixed is not in that pile. The recovery rate on stolen cryptocurrency is not the recovery rate on a stolen credit card.

SIM swap vs phishing

A SIM swap and a phishing attack both end in someone else logging into your account, and they demand different things from you. Phishing needs a mistake on your part: a link clicked, a code typed into the wrong box, a fake support agent believed. A SIM swap needs nothing from you at all, and it typically happens while you are asleep with your phone face down on a nightstand showing no signal. Awareness training helps with the first and is useless against the second.

SIM swap vs two-factor authentication

Two-factor authentication is the defense; a SIM swap is the attack that beats one weak version of it. The three common implementations are not equivalent. Codes by SMS depend on a phone company employee doing their job, and are the specific target here. Authenticator app codes live on your device and survive a SIM swap, though they can still be relayed to a convincing fake login page. A hardware security key signs the actual domain you are talking to, so it resists both. Choosing "2FA is on" as your answer skips the only question that matters, which is which kind.

Not to be confused with

Frequently asked questions

Is an authenticator app enough to stop a SIM swap?

It stops the code interception, but only if the account cannot also be recovered by SMS. Many exchanges and email providers still allow a phone-based reset that bypasses the app entirely, so remove the number as a recovery option as well as switching the second factor.

My phone just lost service for no reason. What do I do first?

Assume a swap is underway. From another device, change your email password and sign out all sessions, then lock or freeze your exchange accounts and contact the carrier from a different line. Minutes matter, because the attacker's next step is a withdrawal.

Can a SIM swap reach bitcoin in a hardware wallet?

No. A SIM swap works by taking over accounts that a company controls on your behalf. A hardware wallet has no account, no password reset, and no phone number attached, so there is nothing for the attacker to recover.

Read next

Related terms

More in Privacy & security