3 Details Are All It Takes: How SIM Swapping Reaches Your Crypto Account
Fraudsters have a new SIM card activated in your name at the mobile operator and intercept every SMS code with it. How the attack on your crypto account unfolds and which settings make it run into the void.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
In SIM swapping, fraudsters take over your mobile number by having the operator activate a new SIM card in your name. From that moment on, every SMS code lands on their device, including the confirmation code from your crypto exchange. The most effective protection has two steps: two-factor authentication on the exchange account runs through an authenticator app or a hardware key instead of SMS, and a customer password sits with the mobile operator, without which nobody can order a new card over the phone.
This is not a theoretical risk. Anyone holding bitcoin or other coins on an exchange loses them for good in a successful attack: a transfer on the blockchain cannot be recalled, and balances at a crypto exchange carry no deposit protection of the kind a bank has. The attack itself needs no technology. It needs only a member of staff at the customer desk who takes the person on the other end of the line for you.
SIM Swapping Explained: the Fraud at the Mobile Operator's Customer Desk
SIM swapping is the unauthorised move of a mobile number onto a new SIM card controlled by the attacker. The abbreviation SIM stands for subscriber identity module, the module that carries your subscriber identity. The decisive part: the number belongs to the contract, not to the card. Any operator can move a number onto another card or an eSIM profile at any time, because that is exactly what a customer who has lost their phone needs.
That move is the point of attack. The specialist literature also calls the method SIM hijacking or SIM swap fraud. According to the trade magazine PC-WELT, SIM swapping usually runs through the customer portal or the customer hotline of the mobile provider. So no security hole in a chip is exploited, but a process gap in customer service. The attacker calls, poses as you and reports a lost phone.
To you the result looks harmless. Your phone loses the network, nothing more. Control over the number already lies elsewhere at that moment.
Your Crypto Account Hangs on Your Mobile Number: from SIM Swap to Empty Exchange
With most online services the mobile number is the master key. That number serves as the second factor at login, as the route for a password reset and as the channel for confirmations on withdrawals. Whoever controls it holds three levers at once.
The typical sequence on a crypto account: the attacker starts a password reset at the exchange. The confirmation goes to your email address. If they have access there too, because the email account was also secured by SMS, the chain is closed. They reset both passwords, confirm the login with the SMS code that now reaches them, and order a withdrawal to an address of their own. With bitcoin and ethereum, that transfer is final after a few confirmations.
This is why SIM swapping hits crypto investors harder than bank customers. A bank can under certain circumstances recall a transfer within the SEPA area and is liable in a dispute under the rules for unauthorised payments. A blockchain transaction knows no recall. Anyone not holding their balance themselves should at least build the account access so that a foreign SIM card does not open it. Which exchanges offer which methods is shown in our crypto exchange comparison.
Name, Date of Birth and Address: These Three Details Often Suffice for Fraudsters
The groundwork is unspectacular. O2 writes in its guide to the method that in many cases it is enough for the criminals to supply basic personal data such as the full name, the date of birth and the address. For many people all three sit openly on the internet or can be assembled with little effort.
The sources are familiar: profiles on social networks from which birthday and place of residence can be read off; data breaches at online retailers whose records are traded on the dark web; and phishing emails that ask specifically for contract details. An attacker needs not a single figure from your exchange account. They only need enough to sound credible on the phone.
From that follows an uncomfortable rule for social media: every publicly visible detail that could appear in a security question is a building block for the attack. That applies to the birthday as much as to the name of the first pet, which still serves as a security question in many customer systems.

From Customer Portal to New SIM Card: the Attack in Three Phases
O2 describes the sequence in three phases, and they match what investigators report from cases.
Phase one: collecting the data
The attacker gathers what the mobile operator asks for to identify a customer. Phishing emails, counterfeit websites and public profiles are enough for that.
Phase two: taking over the identity
They contact the operator, pose as the contract holder and justify the request for a new card with a loss or a technical problem, such as a different card format.
Phase three: activating the number
The new SIM card or the new eSIM profile is switched on, and your old card loses the network. From then on calls, messages and every SMS code arrive at the attacker.
In the worst case, minutes pass between phase two and phase three. That is why a defence that only takes effect after the attack is almost always too late. What really helps are hurdles that stand beforehand.
971 Cases, $17.4 Million: the FBI Figures on SIM Swapping for 2025
For Germany there is no separate statistic on this form of fraud. The best available survey is run by the US federal police, the FBI, with its annual report of the Internet Crime Complaint Center, and the figures there are clear enough to show the order of magnitude.
For 2025 the FBI counts 971 reported SIM swap cases with damage of $17,366,758. A year earlier there were 982 cases and $25,983,946, and in 2023 still 1,075 cases and $48,798,103. Arithmetically a reported case in 2025 therefore costs around $17,900. The number of reports is barely falling, then, while the reported damage total is falling markedly.
Two caveats belong with this. First, these are reports from the United States, not from Germany. Second, the authority records only what somebody actively reports; the unreported number is unknown. What the figures do show: the damage per case sits in the five-figure range, and that fits an attack that only pays off once a notable balance sits behind the account.
The age distribution in the same survey is telling. Most SIM swap reports in 2025 come from the 40 to 49 age group with 210 cases, followed by the 50 to 59 group with 194 and the 30 to 39 group with 162 cases. Under 20 there are six. This is no youth phenomenon; it hits the age groups with the largest assets.
For a sense of scale: the same survey records 181,565 complaints with a crypto connection for 2025 and damage of a good $11.3 billion. SIM swapping is a small but particularly targeted slice of that.
No Network, Foreign Codes, Unknown Logins: the Warning Signs of a SIM Swap Attack
A SIM swap announces itself, though only for a few minutes and only if you know what points to it. These signs appear consistently in the guides from operators and security firms:
- Suddenly no network. Your phone shows no reception, or only emergency calls, although other devices in the same place work normally. That is the clearest warning sign of all.
- An unexpected confirmation from the operator. An email or a letter announces a new SIM card, a new eSIM profile or a contract change that you did not request.
- SMS codes you did not ask for. While the old card still runs, codes sometimes arrive for logins that nobody in your household triggered.
- A rejected login. You can no longer get into your email account or your exchange account even though the password is right.
- Quiet changes in accounts. New devices, new sessions or changed contact details appear on social networks or in online banking.
The snag with the first point: a dead spot looks exactly the same. Hence the rule of thumb that a sudden loss of network in the middle of an ordinary day, without a change of location and without a restart, deserves a call to the operator from another phone within a few minutes.

Authenticator App Instead of SMS: Switching Two-Factor Authentication on the Exchange Account
Two-factor authentication requires a second, independent piece of evidence alongside the password. Whether that evidence survives a SIM swap depends solely on where it is generated.
The Federal Office for Information Security classifies the methods clearly in its recommendations on account protection. On delivery by SMS the authority writes that what is common above all is delivery by SMS, meaning mTAN or smsTAN. On the alternative it says, in its own words: "Better are TAN generators (hardware) or authenticator apps (software), which generate one-time passwords anew on a time or event basis." And on the strongest tier: "safer, however, is storage in hardware on a chip card (HBCI, signature cards) or a dedicated USB stick or NFC token (FIDO/U2F)."
For your crypto account that means, in ascending order of safety:
- SMS code. Hangs on the mobile number and fails completely in a SIM swap. Only as a stopgap, where a provider can do nothing else.
- Authenticator app (TOTP). The one-time code arises on your device from a secret seed value and the time of day. A foreign SIM card changes nothing about that. You back the seed value up separately from the phone during setup.
- Passkey or hardware key (FIDO2/U2F). The key sits in a separate piece of hardware or in the device's security chip and never leaves it. It is also the only factor that protects against phishing as well, because it checks the internet address of the genuine site.
The important part is the second step, which many forget: after switching, remove the phone number as a recovery option. Otherwise the old route stays open, and the attacker simply takes it. We worked through exactly the same logic in detail in our piece on two-factor authentication at the crypto exchange.
Customer Password at Telekom, Vodafone and O2: the Bolt at the Mobile Operator
The second half of the protection sits with the mobile operator. According to PC-WELT, a dedicated customer password is mandatory on the customer hotline at Telekom, Vodafone and O2. That password is the bolt: without it, no order and no card transfer is supposed to go through on the phone.
From that follow three concrete moves that anybody can complete in a quarter of an hour:
- Set and change the customer password. It has to differ from all your other passwords and must contain nothing that appears in a public profile. Many contracts start out with a weak default password in there.
- Secure access to the customer portal. According to PC-WELT the portal is the second route alongside the hotline. Its own password, and where the operator offers one, a second factor that is not your own number.
- Ask about additional blocks. Telekom has offered identification by voice since the summer of 2018. Other operators work with callbacks or with delivery by post. Which hurdle your contract knows appears on no tariff sheet; you find that out only by asking.
A side effect of the eSIM helps here: because the profile is tied to a particular device and has to be authorised on top of that, moving it to foreign hardware takes more effort than with a plastic card that can be posted somewhere.
Withdrawal Addresses, Withdrawal Lock and Self-Custody: the Second Line of Defence
Even if an attacker gets as far as the account, they still have to get the coins out. That is exactly where the second line of defence starts, and it costs nothing but a few minutes in the settings.
Fixing withdrawal addresses
Most exchanges allow a list of permitted withdrawal addresses, often called an address book or whitelist. If an address is not on it, nothing goes out. What counts is the lock-up period when adding a new address: 24 or 48 hours in which no withdrawal to the new destination is possible. That period is precisely the window in which you notice an attack.
Withdrawal lock after changes
Many providers automatically block withdrawals for a day after somebody changes the password, the email address or the second factor. Where this is configurable, switch it on. Where it is not, it is worth checking whether the provider knows this lock at all.
What does not have to sit on the exchange
The hardest protection remains not leaving the long-term holding with the provider in the first place. Anyone holding their own coins has no account that can be taken over by telephone. In exchange they take on other risks, above all with approvals in their own wallet. What can go wrong there we showed using the example of wallet drainers and their signatures, and how to get rid of old permissions again is covered in our guide to revoking token approvals on Ethereum.
A Replacement SIM for 14.95 Euros: What a Frankfurt Court Ruling Means for Victims
After a SIM swap you need a new card, and operators long charged a flat fee for it. The Federation of German Consumer Organisations sued over this and reports a ruling of the Higher Regional Court of Frankfurt am Main of July 18, 2024 against Drillisch Online GmbH, case number 1 UKl 2/24. At issue was a price list under which a replacement SIM card was to cost 14.95 euros, without any exception.
The court held that flat fee inadmissible, because it also covers cases the customer did not cause. The federation sums up the core by saying the charge may not cover cases in which the replacement of the SIM card was not caused by the customer. According to the federation the decision is final.
For you that means two things. First, the fee for a replacement card after an incident caused by somebody else is open to discussion, and pointing to this ruling in a conversation with the operator does no harm. Second, it changes nothing about the actual damage: the card is the cheapest part of the whole story. Anyone wanting to settle liability questions with a bank or a mobile operator needs legal advice, because the legal position depends on the individual case and cannot be answered in general terms.
The SIM Swap Has Happened: How to Check Your Accounts and Block the Number
Once the suspicion is there, the order counts. These steps appear consistently in the recommendations of operators and security firms:
- Have the number blocked. Call the mobile operator from another phone, report the incident and have the foreign card blocked. That is the only step that cuts off the supply of codes.
- Secure the email account first. The email address is the root; the exchange account comes after it. Change the password, end all foreign sessions, switch the second factor to an app or a hardware key.
- Freeze the exchange account. Most providers have an emergency block for withdrawals or for the whole account. After that, set the password and the second factor anew and sign out every active device.
- Notify the bank and payment services. Online banking and every service that confirms bank transactions through the number belong on the same list.
- File a police report. A police report is the basis for any later claim for reimbursement or liability. Along with it, secure everything that documents the timing: screenshots, emails from the operator, the times of the withdrawals.
- Move the remaining holdings. Whatever is still there belongs at an address whose key the attacker has never seen.
Honesty requires this: once coins have flowed out, recovery on the blockchain is not provided for. What remains is the trail of the transaction, the police report and the route through the exchange where the loot lands.
SIM Swapping: What to Take Away
The method needs no technology, only patience on the telephone, and it aims at the weakest point of your account security: a phone number that a stranger can have transferred. Three steps close the gap.
- Switch the second factor. Move from SMS to an authenticator app or a hardware key at the exchange and the email provider today, and delete the number as a recovery route. Which providers stand under European supervision and which methods they offer is shown in our overview of regulated crypto exchanges.
- Set the bolt at the mobile operator. Assign a customer password, secure the customer portal with its own password and ask about additional hurdles for a card change. In parallel, check what has to sit with the provider at all and what belongs better in your own software wallet.
- Activate the second line of defence. Fix the withdrawal addresses, switch on the withdrawal lock after changes and take the long-term holding into self-custody; the devices for that are in the hardware wallet comparison.
(As of October 2, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about SIM swapping
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
- Beware of New Ethereum Node Scam: USDT Fraud Exposed
- 387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
- SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
- Inactivity Fees at Crypto Exchanges: How to Check Whether Your Dormant Account Loses Money Every Month
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
September 27, 2026 4:20 PM

Bybit's Counterparty List Runs to Over 50 Names: What to Check on Balances, Withdrawals and Custody
Bybit has published a list of more than 50 platforms, services and organisations whose involvement can, under its own rules, lead to an account freeze. What decides the outcome is not your next trade but the payment history you already have.
September 26, 2026 4:21 AM

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls
Six authorities have disconnected 13,888 phone numbers used by investment fraudsters to call their victims in Operation Herakles, 9,304 of them in the past three months alone. What the Federal Network Agency now requires of telecoms providers and which three checks protect you from the scheme.
September 25, 2026 4:13 PM

Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
September 8, 2026 7:33 AM

Withdrawal Whitelist at the Crypto Exchange: How to Lock the Withdrawal Path Against Foreign Addresses
A withdrawal whitelist lets balances leave only to addresses approved in advance, and it works even when password and second factor are compromised. On September 8, 2026 we checked which of thirteen providers document the function publicly.
September 4, 2026 4:39 AM

Source of Funds at a Crypto Exchange: Why a Deposit Can Freeze Your Account for 15 Days
OKX chief Star Xu described on September 2 what an unusual deposit sets off: reviews of 15 days and longer, during which balances and account functions can be restricted. What that means for investors in Germany, and which documents you should keep to hand.
July 1, 2024 8:35 AM

Floki Inu Issues Major Scam Alert: A New Crypto Hack?
Floki Inu issues a major scam alert, urging investors to stay vigilant against fraudulent token schemes and the importance of security in the crypto space. What is it about?
March 3, 2021 7:07 PM

Breaking News – LiteBit exchange was HACKED, here’s what you Need to Know
In an email sent to its users, LiteBit announced that they were hacked. Repercussions were not very harsh, and the company reassured its users.
August 22, 2026 4:16 PM

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
September 22, 2026 1:12 PM

Buying Bitcoin With PayPal in Germany: What Really Works and What It Costs
PayPal runs no crypto service of its own in Germany, but it works as a deposit route at regulated exchanges. What the detour costs, which withdrawal hold follows it and why buyer protection does not apply here.
September 30, 2026 10:24 PM

$766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
CertiK counts around $766.4 million in damage for September 2026, the highest monthly figure of the year. Two incidents carry more than 92 percent of it, and both hit a place where your balance could be sitting too.
September 27, 2026 4:11 PM

Ripple Cannot Freeze 83 Million Dollars in Stolen XRP: What to Check in Custody and Deposits
The attacker from the Bitget incident has moved around 83 million dollars in XRP, and Ripple has no technical means to stop it. What can be frozen, what cannot, and why an account freeze also hits investors with no connection to the case.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 21, 2026 1:26 PM

Crypto Exchange Account Frozen: Why Nobody Tells You Why, and What Actually Helps
If you get no explanation after a freeze, it feels like arbitrary treatment. In fact the German Money Laundering Act forbids the provider from telling you. What happens in that time, which deadlines apply and which documents shorten the process.
August 21, 2026 7:38 AM

Crypto Exchange Insolvency: When Your Coins Can Be Segregated and When They Fall Into the Estate
If a custodian goes under, neither the deposit guarantee nor investor compensation covers crypto-assets. Whether the holdings are still yours is decided by the right of segregation under Section 47 of the German Insolvency Code, and you can read up on the condition for it beforehand.
August 20, 2026 7:18 AM

Crypto Exchange Self-Certification: No Answer by 1 January 2027 and Trading Stops
The German Crypto Asset Tax Transparency Act obliges crypto providers to obtain a tax self-certification from every existing customer by 1 January 2027. Anyone who ignores the request, the reminder and the formal notice is barred from trading after 60 to 90 days.
August 18, 2026 7:14 PM

Two-Factor Authentication on a Crypto Exchange: Why SMS Is the Weakest Option
SMS codes are the most common form of two-factor authentication on crypto exchanges, and the weakest. The problem is not only SIM swapping, which the FBI has recorded falling for three years. It is real-time phishing, and against that neither SMS nor an authenticator app helps.
September 10, 2023 6:19 PM

This Crypto CEO got Jailed for More than 10,000 Years…Here’s Why!
Thodex Crash: Faruk Fatih Ozer, the CEO and founder of the Turkish crypto exchange Thodex, has been sentenced to 11,196 years in prison.
August 3, 2023 6:25 PM

Just In: Binance Possibly Facing Fraud Charges from U.S. DOJ
The U.S. Department of Justice (DOJ) is weighing charges of fraud against the crypto giant. Is Binance in danger?
June 12, 2023 5:29 PM

Binance CEO Addresses FUD Amid Billions in Exchange Outflows
In a surprising move, Binance, the world's largest cryptocurrency exchange by trading volume, experienced a substantial binance outflow of capital.
April 24, 2023 6:54 AM

3 Types of Scammers in the Crypto World
The recent rise of cryptocurrencies brought about a new threat – scammers. Here are 3 types of scammers in the Wild, Wild West of cryptos.
August 22, 2019 9:55 AM

Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
It’s practically similar to stating the sky is blue yet we have another Facebook Data Leak close by influencing a huge number of clients. This time around, it includes the contact data of in excess of 49 million Instagram Accounts […]
October 12, 2018 1:57 AM

Belgium Warns of 19 Probable Fraudulent Cryptocurrency Exchanges
Lately, numerous cryptocurrency exchanging platforms have showed up on the web. They all claim to offer the best (or truly outstanding) exchanging platform(s), empowering the novices and experts to exchange digital currencies in a matter of seconds and with full […]
September 21, 2026 10:12 AM

ZETA Moves to Solana: What Holders in Germany Must Check Now
ZETA holders have voted with 99.4 percent to move the token 1:1 to Solana as an SPL token and to shut down their own blockchain afterwards. There is no date yet, but your exchange decides for itself whether it takes part in the swap.
September 13, 2026 10:12 PM

Chainflip Hack on Tron: How to Check Whether Your USDT Swap Is Still Stuck
An attacker drained 736,442 USDT through Chainflip's Tron rail on September 12, 2026, and trading has been at a standstill ever since. On September 13 we measured for ourselves which functions of the protocol are switched off and which are still running.
More from CryptoTicker


