How exactly is a SIM Swap Attack carried out, and what does an attacker need for it to succeed?
The most common path: the attacker first gathers the victim's personal information through various channels (birthdate, address, the last few digits of an ID number, details shared publicly on social media), then contacts the victim's carrier's customer service, impersonating the victim, claiming their phone was lost or damaged, and requesting the number be transferred to a new SIM card. If the carrier's identity verification process isn't rigorous enough, that collected personal information alone can be enough to pass. A more direct path is bribing a carrier employee to complete the number transfer directly in the backend system, entirely bypassing any front-facing verification.
Once the transfer succeeds, the victim's original phone instantly loses signal (the screen shows 'No Service' or 'Emergency Calls Only'), while the attacker's device begins receiving every text message and call meant for the victim -- including SMS verification codes from exchanges, wallet services, and bank accounts. This means the attack's real bottleneck isn't technical at all; it's how easily the carrier's identity verification process can be bypassed.
Why are crypto holders particularly attractive targets for SIM swap attacks?
The most direct reason: even if a traditional online service account (banking, social media, e-commerce) gets compromised, the actual damage is usually limited, and there's often some chance of partial recovery afterward through bank freezes, disputed charges, or similar mechanisms. Crypto is different -- once transferred out, the transaction is irreversible by nature, and once an attacker uses an SMS verification code to log into an exchange account and completes a withdrawal, the assets are almost never recoverable. This makes crypto holders an extremely high-payoff target.
Blockchain data's public transparency also makes it easier for attackers to select targets -- if an attacker can link a real name to a wallet address holding substantial assets, whether through on-chain analysis tools or an offhand detail shared on social media, they simultaneously gain both 'is this person worth attacking' and 'who is this person.' In this context, a SIM Swap Attack becomes a high-ROI crime targeting an already-identified, high-value victim, rather than a random shot in the dark.
Are there concrete cases showing the actual scale and legal consequences of this type of attack?
Crypto investor Michael Terpin's lawsuit against carrier AT&T is one of the most closely watched long-running cases of this kind: in January 2018, Terpin suffered a SIM Swap Attack that cost him roughly $24 million in cryptocurrency. The lawsuit has dragged on for years and was scheduled to go to jury trial in March 2026, with the core dispute centering on whether AT&T's failure to properly verify identity constitutes negligence liability under Section 222 of the Federal Communications Act. Another case involves T-Mobile, which paid a $33 million settlement over a SIM swap incident tied to cryptocurrency theft in 2020.
Industry-level data also shows this problem continuing to worsen: some identity protection organizations have reported SIM swap case counts multiplying several times over in recent years, with the overwhelming majority of victims reporting they noticed nothing unusual at all before the attack. In other words, most victims weren't targeted because they made a mistake or clicked a phishing link -- the vulnerability sits within the carrier's own verification process itself, which is also why the U.S. Federal Communications Commission (FCC) has recently begun imposing heavier penalties on carriers for failures to protect customer data.
What can the average crypto holder actually do to defend against this type of attack?
The single most effective step is entirely avoiding SMS as the sole method of two-factor authentication -- switching to a hardware security key (like a YubiKey) or an authenticator app (like Google Authenticator or Authy) instead of a text-message code, since neither method depends on control over the phone number, meaning that even if an attacker seizes the number, they still can't complete verification. Most major exchanges and some wallet services support both of these more advanced verification methods, but the default option is usually still SMS, requiring the user to actively go in and switch it.
Some carriers also offer advanced account protection features like an 'extra PIN' or 'port-out lock,' which require a password only the account holder knows before a number transfer can proceed -- it's worth proactively contacting your carrier to enable this (don't assume it's on by default). The more fundamental principle is moving significant crypto assets into offline storage that doesn't depend on phone-based verification at all, such as a Hardware Wallet -- because even if an attacker successfully completes a SIM swap, if the assets aren't sitting on a platform requiring SMS verification to move, this entire attack path fails from the start.
Crypto investor Michael Terpin suffered a SIM swap attack in January 2018 that cost him roughly $24 million in cryptocurrency, and his lawsuit against carrier AT&T was scheduled to go to jury trial in March 2026. T-Mobile separately paid a $33 million settlement over a SIM swap incident tied to cryptocurrency theft in 2020.
The advantage of SMS verification is a low setup bar and near-universal support across services, offering more protection for everyday accounts than having no verification at all. The drawback is that this protection's strength depends entirely on how rigorous the carrier's identity verification process is -- once a gap opens up in that process, SMS verification not only fails to protect the user, it becomes the single gate an attacker needs to breach. For users holding high-value crypto assets, this risk is disproportionate to the potential scale of loss, making stronger verification methods worth adopting on top.