Skip to main content

Shepley Capital

RISKS & SCAMS
Risks and Scams - Cryptopedia by Shepley Capital

SIM Swap and Account Takeover Attacks on Crypto Accounts

SIM swap fraud is one of the most effective and damaging attacks against cryptocurrency holders. The attack transfers your mobile phone number to a SIM card controlled by the attacker, instantly capturing all SMS messages sent to your number, including two-factor authentication codes for exchange accounts, email accounts, and any service using SMS verification. With control of your phone number, attackers can reset passwords, bypass 2FA, and drain accounts within minutes, often before the victim realises anything has happened.

The attack exploits the trust that Australian telcos (Telstra, Optus, Vodafone) place in customer service representatives to authorise number transfers. Attackers use personal information obtained through data breaches, phishing attacks, or social media research to impersonate victims convincingly. The information required is often surprisingly minimal: full name, address, date of birth, and an account number or recent bill amount are frequently sufficient for a number port.

 

How SIM Swap Attacks Work

The mechanics of a SIM swap are straightforward. The attacker contacts your mobile carrier (often by phone, though in-store visits also occur) claiming to be you. They provide the personal information needed to pass identity verification and claim that their SIM card has been lost or damaged and they need a replacement. If the carrier’s representative accepts the identity verification, the phone number is transferred to a new SIM card the attacker has prepared. Once the transfer completes, your physical SIM stops receiving calls and messages, and the attacker’s SIM receives everything sent to your number.

The attack is then executed in a specific sequence. First, the attacker uses your phone number to trigger an SMS 2FA code for your email account, allowing them to reset the password and gain access to your email. With access to your email, they can then trigger password resets for any service linked to that email, including crypto exchanges. The combination of email control and SMS 2FA control allows complete account takeover within a timeframe of minutes to hours.

Account takeover attacks more broadly include SIM swapping but also encompass phishing attacks that capture credentials directly, malware that intercepts authentication codes, and SS7 network-level attacks (a telecom protocol vulnerability that allows SMS interception without a SIM swap). For crypto holders, all of these threats share the common weakness: SMS-based two-factor authentication is not a secure second factor against determined attackers.

 

Why Crypto Accounts Are Targeted

Cryptocurrency accounts are disproportionately targeted for SIM swap attacks because the combination of high-value assets, irreversible transactions, and typically no fraud recovery mechanism makes them uniquely lucrative for attackers. When a bank account is fraudulently accessed, the bank can often reverse transactions and reimburse the victim. When a crypto exchange account is drained, the funds are typically gone permanently. The victim bears the full loss.

Crypto holders who are publicly visible (discussing holdings on social media, participating in crypto forums, or appearing in news articles) are higher risk targets because they have confirmed both that they hold crypto and indicated potential scale of holdings. Even seemingly innocuous posts (discussing a particular exchange, mentioning significant gains, or describing using hardware wallets) can identify you as a high-value target and trigger background research into your identity.

The protecting your crypto from hacking guide covers the broader landscape of account security. Within that landscape, SIM swap protection is specifically about hardening the phone number layer of your security stack.

 

Protecting Against SIM Swap Attacks

The most effective protection against SIM swaps is removing SMS from your authentication chain entirely. Replace SMS 2FA with an authenticator app (Google Authenticator, Authy, or hardware-based TOTP) on every account that supports it. Authenticator app codes are generated locally on your device and are not vulnerable to SIM swap attacks: an attacker who has swapped your SIM cannot receive authenticator app codes. For the highest-value accounts, hardware security keys (YubiKey or similar) provide the strongest 2FA protection.

Contact your Australian mobile carrier and enable any available SIM swap protection or number porting protection. Most major Australian carriers (Telstra, Optus, Vodafone) offer some form of enhanced account security, including port-out PINs or in-person-only porting requirements. The effectiveness of these protections varies and depends on staff compliance, but they add friction to an attack. Additionally, placing a verbal password or PIN on your carrier account means customer service representatives must verify this code before making any account changes.

Reduce your public digital footprint: avoid posting information that identifies you as a crypto holder with significant assets. Review your social media profiles for posts that could assist an attacker in constructing a convincing impersonation. The information required for a successful SIM swap (name, address, date of birth, account numbers) is often assembled from multiple sources, including data broker sites, social media, and previous data breaches.

 

Signs You Have Been SIM Swapped

The first sign of a SIM swap is typically a sudden loss of mobile service: calls and messages stop working, and the phone shows “No Service” or “Emergency Calls Only.” This occurs because your number has been transferred to the attacker’s SIM and your SIM is no longer registered on the network. If this happens unexpectedly, treat it as a potential security incident immediately, not as a network outage.

Other indicators include: receiving unexpected SMS messages about account changes you did not initiate, notification emails from exchanges or other services about password resets you did not request, or unusual activity on any account that uses SMS 2FA. If you notice these signs while you still have mobile service, the attack may be in progress: act immediately.

If you suspect a SIM swap: call your mobile carrier immediately from a different phone and report the suspected fraud. While on hold or after reporting, attempt to access and secure your highest-priority accounts (email, then crypto exchanges) from a device on a different network (wifi, not mobile data). Change passwords and update 2FA methods on all critical accounts.

 

What to Do After a SIM Swap Attack

If an attack has already succeeded and accounts have been accessed or funds taken, immediate action on the remaining accessible accounts is the priority. Recover access to your mobile number through your carrier’s fraud team. Change all passwords for all accounts that used that phone number for 2FA, starting with email. Replace all SMS 2FA with authenticator app 2FA on every account.

Report the incident to your carrier’s fraud department, to the Australian Cyber Security Centre (ACSC) via ReportCyber, and to any exchange that was accessed. While crypto losses are typically irrecoverable, exchanges may freeze accounts if notified quickly enough to prevent fund withdrawal, and reporting contributes to pattern detection that helps protect other victims.

Document everything: timestamps of when service was lost, when you were notified, what accounts were accessed, and what was taken. This documentation is required for any insurance claims and for law enforcement if you choose to report to the AFP or state police.

Frequently Asked Questions

What are SIM swap and account takeover attacks?

SIM swap fraud is one of the most effective and damaging attacks against cryptocurrency holders. The attack transfers your mobile phone number to a SIM card controlled by the attacker, instantly capturing all SMS messages sent to your number, including two-factor authentication codes for exchange accounts, email accounts, and any service using SMS verification. With control of your phone number, attackers can reset passwords, bypass 2FA, and drain accounts within minutes, often before the victim realises anything has happened.

How SIM Swap Attacks Work?

The mechanics of a SIM swap are straightforward. The attacker contacts your mobile carrier (often by phone, though in-store visits also occur) claiming to be you. They provide the personal information needed to pass identity verification and claim that their SIM card has been lost or damaged and they need a replacement.

Why Crypto Accounts Are Targeted?

Cryptocurrency accounts are disproportionately targeted for SIM swap attacks because the combination of high-value assets, irreversible transactions, and typically no fraud recovery mechanism makes them uniquely lucrative for attackers. When a bank account is fraudulently accessed, the bank can often reverse transactions and reimburse the victim. When a crypto exchange account is drained, the funds are typically gone permanently.

How do you protect yourself against a SIM swap?

The most effective protection against SIM swaps is removing SMS from your authentication chain entirely. Replace SMS 2FA with an authenticator app (Google Authenticator, Authy, or hardware-based TOTP) on every account that supports it. Authenticator app codes are generated locally on your device and are not vulnerable to SIM swap attacks: an attacker who has swapped your SIM cannot receive authenticator app codes.

What are the signs you have been SIM swapped?

The first sign of a SIM swap is typically a sudden loss of mobile service: calls and messages stop working, and the phone shows "No Service" or "Emergency Calls Only." This occurs because your number has been transferred to the attacker's SIM and your SIM is no longer registered on the network. If this happens unexpectedly, treat it as a potential security incident immediately, not as a network outage.

What to Do After a SIM Swap Attack?

If an attack has already succeeded and accounts have been accessed or funds taken, immediate action on the remaining accessible accounts is the priority. Recover access to your mobile number through your carrier's fraud team. Change all passwords for all accounts that used that phone number for 2FA, starting with email.

What are the risks associated with SIM Swap and Account Takeover Attacks on Crypto Accounts?

SIM swaps are among the most damaging attacks on crypto holders because they defeat SMS two-factor authentication and give an attacker access to password resets across email and exchange accounts at once. The attack usually succeeds through social engineering of the mobile carrier rather than any failure on the victim's part, and the window between losing service and losing funds is often measured in minutes. Crypto transfers cannot be reversed, so recovery through the platform is rarely possible.

How does SIM Swap and Account Takeover Attacks on Crypto Accounts affect Australian crypto investors?

Australian holders should remove SMS from the authentication chain entirely, replacing it with an authenticator app or a hardware security key, and add a carrier-level port-out PIN or account lock. Long-term holdings belong in self-custody rather than on an exchange, so an account compromise cannot reach them. If service drops unexpectedly, treat it as an attack in progress: contact the carrier from another line and lock exchange accounts immediately. Any loss should also be reported to the platform, the carrier and Australian authorities.

WRITTEN & REVIEWED BY Chris Shepley

UPDATED: AUGUST 2026

Choose your next topic from our Cryptopedia​

Grow your crypto portfolio with the latest insights, straight to your inbox!

Join 10,150+ CEOs, Business Owners, Parents, Students, & more receiving actionable crypto insights to grow their portfolios.