WalletDNA

Guide

What is a SIM swap and why does it matter

2 min read · August 2026

How attackers hijack a phone number to bypass SMS-based two-factor authentication on exchange and email accounts.

A SIM swap happens when someone convinces a mobile carrier to move your phone number onto a SIM card they control. Once they have your number, they can request password resets on any account that uses SMS as a recovery or verification method, including exchange accounts, email, and sometimes wallet services tied to a phone number.

Why this matters for crypto accounts

SIM swapping is not a blockchain exploit. It targets the identity layer that sits above the chain: your carrier account, your email, and any exchange that treats a text message as proof of who you are. That makes it dangerous precisely because it bypasses cryptographic security entirely and goes after the weakest human process in the chain.

For a compliance analyst or investigator, this matters because a compromised phone number can unlock a cascade of account takeovers in minutes. Two-factor authentication built on SMS gives a false sense of security if the underlying carrier account can be socially engineered.

Where the real weakness sits

The published WalletDNA glossary entry puts it plainly: assume your carrier's account-recovery process is the weakest link in your stack. Carriers are built to help customers regain access to lost phones, not to resist targeted social engineering, and that mismatch is what makes SIM swaps effective.

  • SMS 2FA relies on the carrier, not on the account holder, to gatekeep access.
  • Carrier account recovery often uses lower-friction verification than the accounts it protects.
  • Any account, exchange, email, or wallet, that treats a phone number as an identity anchor inherits this risk.

What to actually do about it

The structural fix, as the glossary states, is to move two-factor authentication off SMS entirely. A hardware security key or an authenticator app removes the phone number from the trust chain, so a carrier-side compromise no longer translates into account access.

  • Replace SMS 2FA with a hardware key or authenticator app on every exchange and email account you rely on.
  • Check whether your mobile carrier offers a PIN, passphrase, or port-out lock on your account, and enable it.
  • Treat any account still tied to SMS recovery as your highest-priority migration, not a low-priority cleanup task.

SIM swapping does not break cryptography. It breaks the assumption that a phone number proves identity, which is why the fix is procedural, not technical.

For analysts working incidents where a SIM swap is suspected, the WalletDNA glossary entry linked below gives the concise definition; this explainer is the longer version for anyone building or reviewing account-security policy.

WalletDNA's wallet analysis tools can help trace what happened to funds after an account was compromised, but they are not designed to investigate the SIM swap itself, that sits with the carrier and the affected platform.

Check a wallet yourself

Risk analysis and entity attribution across 18 chains, free to start.

Analyze a wallet
What is a SIM swap and why does it matter | WalletDNA