[{"data":1,"prerenderedAt":22},["ShallowReactive",2],{"blog-content-en-sim-swap-attacks-and-crypto":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9},"sim-swap-attacks-and-crypto","SIM-Swap Attacks and Crypto: Why SMS 2FA Fails","Your phone shows no service — minutes later your exchange account is empty. How SIM-swap attacks work, why SMS codes are crypto's weakest lock, and why a fully non-custodial wallet like WATS has no phone-number path to your funds at all.","SIM-swap attacks explained: how criminals hijack your phone number, why SMS 2FA fails, what they can and cannot steal from a self-custody wallet, the carrier PINs and hardware keys that stop it, and why WATS is non-custodial with no SMS or phone-number recovery path.","\u003Cblockquote>\u003Cp>A SIM-swap attack steals crypto by hijacking your phone number at the carrier — a support agent moves your number onto the attacker's SIM — rather than by breaking any wallet. SMS two-factor authentication fails because \"possession of a phone number\" is really a database entry that a support agent can edit, while an authenticator app, a hardware security key or a passkey all prove possession of something the carrier does not control. What a hijacked number reaches is everything custodial around the wallet: exchange accounts secured by SMS, email password resets, and a seed phrase sitting in a cloud account that a phone-recoverable mailbox can open. A fully non-custodial wallet such as WATS has no phone-number path at all — you hold the keys, WATS never holds one, and no SMS code, recovery number or support agent sits between a hijacked number and your funds.\u003C\u002Fp>\u003C\u002Fblockquote>\n\n\u003Ch2>The weakest lock in crypto is your phone number\u003C\u002Fh2>\n\u003Cp>A \u003Cstrong>SIM-swap attack\u003C\u002Fstrong> is when a criminal convinces your mobile carrier to move your phone number onto a SIM card they control — no malware, no hacking of your device. Once they own the number, every SMS one-time code and phone-based password reset lands on their handset, which means SMS two-factor authentication is only as strong as a carrier support agent's judgment.\u003C\u002Fp>\n\u003Cp>That makes it one of the strangest threats in crypto: the attack never touches your wallet, your seed phrase or your computer. It targets a customer-service workflow at a phone company — and documented cases have shown exchange accounts emptied within the hour.\u003C\u002Fp>\n\n\u003Ch2>How does a SIM swap actually work?\u003C\u002Fh2>\n\u003Cp>The attacker starts with your personal details — name, address, date of birth, the last digits of an account — assembled from data breaches, phishing or your own social media. Then they contact your carrier: a call to support, a visit to a retail store, or an online eSIM transfer request. The story is always some version of \u003Cem>I lost my phone — please move my number to this new SIM\u003C\u002Fem>. If the agent accepts it, or an insider has been paid to accept it, the port goes through.\u003C\u002Fp>\n\u003Cp>Your phone drops to \u003Cem>no service\u003C\u002Fem>. Theirs lights up as you. From the network's point of view nothing was hacked — a routine number transfer was processed for a customer who answered the security questions.\u003C\u002Fp>\n\n\u003Ch2>What does owning your number unlock?\u003C\u002Fh2>\n\u003Cp>A phone number is a skeleton key because so many systems quietly treat it as proof of identity:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Exchange logins\u003C\u002Fstrong> — SMS 2FA codes now arrive on the attacker's device, so a leaked or reused password becomes a full account takeover.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Your email\u003C\u002Fstrong> — if phone-based recovery is enabled, a forgot-password flow hands the mailbox over, and the mailbox can reset nearly everything else.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custodial balances\u003C\u002Fstrong> — anything a service holds for you behind SMS or email authentication is now reachable.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The order matters. Skilled attackers go for email first, because owning the mailbox turns one hijacked number into every account you have. The whole cascade often runs in less time than it takes you to reach a carrier support line.\u003C\u002Fp>\n\n\u003Ch2>Can a SIM swap drain a self-custody wallet?\u003C\u002Fh2>\n\u003Cp>Not directly — and this is the nuance most coverage misses. In a self-custody wallet your private keys are derived from your seed phrase and live on your device or hardware wallet. There is no recover-with-phone-number path to them, so an attacker who owns your number still cannot sign a single transaction. A seed phrase restores a wallet on any device — the same property covered in \u003Ca href=\"\u002Fblog\u002Fwhat-happens-if-you-lose-phone-crypto-wallet\">what happens if you lose your phone\u003C\u002Fa> — and that restore path never runs through your carrier.\u003C\u002Fp>\n\u003Cp>WATS is a concrete example of the shape that matters here. Keys are generated on your device and stay there, WATS never holds a key, and there is no WATS-side account, SMS challenge or support-initiated reset that a hijacked number could drive. The same is true of any genuine non-custodial wallet, and it is the practical meaning of \u003Ca href=\"\u002Fblog\u002Fcustodial-vs-non-custodial-wallet\">custodial versus non-custodial\u003C\u002Fa>: a custodian is an intermediary that a social engineer can talk to, and self-custody removes that conversation from existence.\u003C\u002Fp>\n\u003Cp>The exposure is everything \u003Cem>around\u003C\u002Fem> the wallet: exchange accounts holding custodial funds, and — the self-inflicted version — a seed phrase photographed or typed into cloud storage that a phone-recoverable email can open. Self-custody removes your number from the drain path only if you have not quietly wired it back in.\u003C\u002Fp>\n\n\u003Ch2>Why does SMS 2FA fail when app-based 2FA doesn't?\u003C\u002Fh2>\n\u003Cp>Every second factor proves possession of something. The question is what — and who can reassign it.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\u003Cth>Second factor\u003C\u002Fth>\u003Cth>What possession really means\u003C\u002Fth>\u003Cth>Survives a SIM swap?\u003C\u002Fth>\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\u003Ctd>SMS code\u003C\u002Ftd>\u003Ctd>Control of a phone number at the carrier\u003C\u002Ftd>\u003Ctd>No\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Authenticator app (TOTP)\u003C\u002Ftd>\u003Ctd>A secret stored on your device\u003C\u002Ftd>\u003Ctd>Yes\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Hardware security key\u003C\u002Ftd>\u003Ctd>A physical key, bound to the real site's domain\u003C\u002Ftd>\u003Ctd>Yes\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Passkey\u003C\u002Ftd>\u003Ctd>A cryptographic credential bound to the real site, stored on or synced between your devices\u003C\u002Ftd>\u003Ctd>Yes\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>NFC tap card\u003C\u002Ftd>\u003Ctd>A physical card in your hand, paired to one device\u003C\u002Ftd>\u003Ctd>Yes\u003C\u002Ftd>\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Cp>SMS is the only factor on that list whose possession is really a database entry a support agent can edit. Everything else forces an attacker to obtain a physical object, compromise your device, or break into a sync account that is itself not recoverable by phone — which is why the backup settings on your authenticator app and passkeys matter as much as the factor you chose. Security guidance has discouraged SMS one-time codes for years, and as of 2026 they survive mostly as a legacy default that nobody switched off. The case for physical keys — including how origin binding defeats phishing outright — is laid out in \u003Ca href=\"\u002Fblog\u002Fhardware-2fa-crypto-wallet\">hardware 2FA for crypto\u003C\u002Fa>.\u003C\u002Fp>\n\n\u003Ch2>How do you protect yourself before it happens?\u003C\u002Fh2>\n\u003Cp>Prevention is mostly a settings audit, and none of it costs money:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Lock your number.\u003C\u002Fstrong> As of 2026, major carriers offer a port-freeze or number-lock plus an account PIN — enable both, so a transfer requires more than a good story.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Replace SMS 2FA\u003C\u002Fstrong> with an authenticator app or a hardware key on every account that touches money or email.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Adopt passkeys\u003C\u002Fstrong> where supported — there is no code to intercept at all.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove your phone number\u003C\u002Fstrong> from exchange and email recovery options entirely; a number that cannot reset anything is a number not worth stealing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Use a separate, unpublished email\u003C\u002Fstrong> for crypto accounts, and keep your holdings off social media.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Move what you are not actively trading into self-custody\u003C\u002Fstrong>, so the balance that matters most is not sitting behind a login your number can open.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These steps sit alongside the broader checklist in \u003Ca href=\"\u002Fblog\u002Fcrypto-wallet-security-best-practices\">crypto wallet security best practices\u003C\u002Fa> — SIM protection is one layer, not the whole defense.\u003C\u002Fp>\n\n\u003Ch2>What should you do the moment it happens?\u003C\u002Fh2>\n\u003Cp>The tell is sudden: your phone shows \u003Cem>no service\u003C\u002Fem> somewhere with normal coverage, or activation and password-reset emails you never requested start arriving. Move in this order — from another device, call your carrier and reclaim the number; secure your email first, since it is the master key; then lock your exchange accounts and freeze withdrawals; finally rotate passwords and revoke active sessions. The attacker is working the same list from the other side, so minutes genuinely matter.\u003C\u002Fp>\n\n\u003Ch2>Where WATS fits\u003C\u002Fh2>\n\u003Cp>WATS is fully non-custodial across all four of its products — the \u003Ca href=\"\u002Fchrome-extension\">Chrome extension\u003C\u002Fa>, the mobile app, the Hot Wallet and the NFC Metal Card. You hold the keys and WATS never holds one, so there is no WATS account for a carrier agent to reassign, no SMS code that unlocks funds and no phone-number recovery path to socially engineer. That is what takes your mobile number out of the drain path entirely, rather than merely making it harder to abuse.\u003C\u002Fp>\n\u003Cp>Two specifics are worth stating plainly. First, the WATS \u003Ca href=\"\u002Fnfc-card\">NFC Metal Card\u003C\u002Fa> is a factor you physically carry: you tap it to authenticate, it stores no private keys, and each card has a unique ID that pairs to exactly one device. Possession of that card cannot be transferred by a phone call to a support line — which is precisely the property SMS lacks. Second, because one WATS wallet covers Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON from a single recovery phrase, the things you are protecting are that phrase and your device, not a spread of logins tied to your number.\u003C\u002Fp>\n\u003Cp>So the practical version of this article is a short sequence. Put a PIN and a port freeze on your carrier account, replace SMS 2FA with an authenticator app or hardware key on your email and every exchange, strip your phone number out of account recovery, and then move the balance you are not actively trading somewhere a phone number cannot reach: install WATS from the \u003Ca href=\"\u002Fdownload\">download page\u003C\u002Fa>, write the recovery phrase down offline before you fund anything, and pair an NFC Metal Card if you want a physical tap-to-authenticate factor on top.\u003C\u002Fp>",[10,13,16,19],{"q":11,"a":12},"Can a SIM swap steal crypto from a self-custody wallet?","Not directly. Self-custody keys are derived from your seed phrase and stored on your device or hardware wallet — there is no phone-number recovery path, so owning your number does not let an attacker sign transactions. In WATS specifically, keys are generated on your device and WATS never holds one, so there is no account to reset and no support channel to socially engineer. The real exposure is around the wallet: exchange accounts secured by SMS, email-based password resets, and seed phrases backed up in cloud storage that a hijacked email can open. Protect those, and the wallet itself stays out of reach.",{"q":14,"a":15},"What kind of wallet is immune to a SIM swap?","A fully non-custodial one, and WATS is an example: keys are generated on your device, WATS never holds a key, and there is no phone number, SMS code or support-side reset anywhere in the path to your funds — so a hijacked number has nothing to unlock. WATS covers Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON from a single recovery phrase, which means what you defend is that phrase and your device rather than a set of logins tied to your mobile number. The WATS NFC Metal Card can add a physical tap-to-authenticate factor on top; it stores no private keys, pairs to exactly one device, and possession of it cannot be reassigned by a phone call.",{"q":17,"a":18},"How do I know if I have been SIM swapped?","The clearest sign is your phone suddenly showing no service in an area with normal coverage, often alongside emails about a SIM activation or password resets you never requested. If that happens, act immediately: call your carrier from another device to reclaim the number, secure your email account first, then lock exchange accounts and freeze withdrawals. Speed matters — SIM-swap attacks are often completed within the first hour.",{"q":20,"a":21},"Is SMS 2FA better than nothing?","Against untargeted attacks — leaked passwords tried in bulk — yes, SMS 2FA still blocks most automated logins. Against a targeted attacker it fails, because the code is delivered to whoever controls the number, and carriers can be talked into reassigning it. Treat SMS as a temporary floor, not a defense: switch to an authenticator app, hardware key or passkey, and remove your phone number from account recovery so it cannot reset anything.",1786059328208]