Most SIM swap victims were doing almost everything right. Strong passwords, 2FA enabled, a hardware wallet for cold storage. But SMS-based 2FA on a single email account was enough to unravel the whole stack. Within two hours of the swap, the attacker had their exchange accounts, their seed phrase backup email, and their identity documents.
This attack is preventable. Not with one setting — with a layered setup that removes every dependency on your phone number as an authentication factor.
How a SIM Swap Actually Happens
SIM swap attacks rely on carrier-side social engineering or insider bribery. An attacker who knows your name, phone number, and last-4 SSN — all of which are available in consumer data breaches — calls your carrier, claims to be you, and requests a "port" or "SIM change." A poorly trained or malicious employee approves it. Your phone loses signal; the attacker's phone gains it.
From there, the playbook is predictable:
- Reset your primary email password using SMS recovery.
- Search your email for "Coinbase," "Binance," "Kraken," "seed phrase," "MetaMask," "Ledger."
- Reset passwords on every exchange account found.
- Bypass SMS 2FA on those accounts because they now receive the SMS.
- Drain.
Start-to-finish, often under two hours. The typical victim first notices when their phone shows "No Service" and assumes it's a carrier issue.
The Defense Is Layered, Not Single-Setting
There is no one toggle that makes you SIM-swap-proof. The goal is to make your phone number not a credential. Any account that can be recovered or authenticated via SMS is a soft target.
Layer 1: Carrier-Side Hardening
Add a port-out PIN or account passcode
Every major US carrier allows a separate PIN for port-out requests. Set one that is:
- Not your phone unlock PIN.
- Not your last-4 SSN, birthday, address, or anything in your consumer records.
- 6–8 digits minimum. Use a random generator.
Enable carrier account-takeover protections
- T-Mobile — enable NumberShield / Account Takeover Protection via the app or by calling.
- AT&T — enable Wireless Account Lock.
- Verizon — enable Number Lock in the app.
- Google Fi / MVNOs — use the strongest 2FA option the carrier offers, ideally TOTP-based sign-in.
These flags make in-store or phone-based port requests fail without additional verification. Attackers generally pivot to softer targets rather than fight this.
Consider eSIM-only setup
eSIMs are harder to physically swap because they require device-level authorization. On iPhone 14 and newer, US models are eSIM-only. This alone doesn't prevent social-engineering attacks, but raises the bar.
Layer 2: Remove SMS From Every Sensitive Account
The entire point of a SIM swap is to receive your SMS 2FA codes. If no sensitive account uses SMS 2FA, the swap has no payoff.
Replace SMS 2FA with:
- Authenticator apps (TOTP) — Google Authenticator, Authy, 1Password, Raivo OTP, or Ente Auth. These generate codes on your device, not via SMS.
- Hardware security keys (FIDO2 / WebAuthn) — YubiKey, Google Titan. Physical keys that phishing cannot replicate.
- Passkeys — increasingly supported on major exchanges and email providers.
Priority accounts to upgrade first
- Primary email account. This is the master key. If SMS can reset your email password, nothing else matters.
- Backup email account. Same treatment.
- Every cryptocurrency exchange. Disable SMS 2FA, enable TOTP or hardware key, and set withdrawal whitelist where offered.
- Password manager. Hardware key is ideal.
- Cloud storage (iCloud, Google Drive). Especially if you've ever photographed a seed phrase. More on that below.
- Bank accounts and brokerages. Where possible, upgrade to app-based auth instead of SMS.
Layer 3: Separate Phone Number for Financial Use
For the small number of accounts that still require a phone number (banks, some brokerages), consider using a dedicated number that is:
- Not on your main carrier.
- Not published anywhere — not on LinkedIn, not in any contact form, not on your business card.
- Routed through a service like Google Voice (tied to a hardware-key-protected Google account) or a separate eSIM-only line from a MVNO.
A number that an attacker doesn't know exists cannot be targeted for a port-out.
Layer 4: Email and Recovery Hygiene
- Audit email forwarding rules. Attackers often set silent forwards so they can watch for password resets. Check Gmail, Outlook, and any alias services monthly.
- Review recovery methods. Remove SMS from the recovery chain. Use hardware keys and printed backup codes stored offline.
- Lock down the Apple ID / Google Account tied to your phone. These often grant access to backups, keychain, contacts, and sometimes synced password managers.
- Do not store seed phrases or private keys in photos, cloud notes, or email. Ever. If you've done this, rotate the wallet. See our recovery guide for next steps if compromise is already suspected.
Layer 5: Behavioral Practices
- Don't publicly discuss crypto holdings. Every podcast interview, tweet, or Twitter Space mention that implies a large balance is a targeting cue. Publicly visible holdings attract attackers.
- Don't reuse handles across public crypto accounts and consumer accounts. Doxx-linking a Twitter persona to your real carrier account is a common pivot.
- Keep PII exposure low. Data broker opt-outs (DeleteMe, Optery, or manual opt-outs) remove the easy info that fuels social engineering against your carrier.
What to Do If You've Been SIM Swapped
If your phone suddenly shows "No Service" or "SIM Not Provisioned" — especially late at night or early morning, favored windows for this attack — treat it as a SIM swap until proven otherwise.
- Call your carrier from another phone and report a fraudulent port. Have them restore the number to your SIM and freeze future changes.
- Change passwords from a different, clean device — starting with primary email, then every exchange, then anything else with financial exposure.
- Withdraw or whitelist-lock exchange balances. If withdrawals are already in progress, some exchanges have a cancellation window if contacted within minutes.
- File a police report and IC3 complaint the same day. SIM swap cases with timely carrier cooperation are genuinely investigated. See our guide on how to report to the FBI.
- Preserve evidence — screenshot the "No Service" state, capture any emails about account changes, save carrier call logs.
- If crypto was stolen, engage forensic tracing in the first 72 hours. Steps detailed in the first 72 hours after a crypto theft.
The Bottom Line
SIM swaps work because most people still have a phone number somewhere in their authentication chain. Eliminate that — at the carrier, at the 2FA method, and at the account-recovery level — and the attack mostly evaporates. It takes about an hour to audit and upgrade the major accounts. It's an hour worth spending.
If you've already been hit, speed and documentation decide outcomes. Legitimate forensic investigators can trace on-chain movements, and SIM swap cases with law enforcement cooperation have led to meaningful recoveries, especially when funds land at centralized exchanges.