sim-swapping-why-2fa-is-not-a-fortress.md ~/netts/blog/posts 2,573 words · 13 min read
Insights Jul 14 2026 Netts.io 13 min read 78 views

SIM Swapping: Why 2FA Is Not a Fortress

SIM swapping shows why SMS-based 2FA can fail, how phone-number theft drains crypto accounts, and what safer recovery habits look like.

SIM Swapping: Why 2FA Is Not a Fortress

The first sign that something was terribly wrong for Michael Terpin, crypto investor and businessman, was not the disappearance of millions of dollars in crypto assets - it was his inability to send or receive a text message.

For an ordinary person, the inability of a mobile phone to send or receive SMS would hardly be the harbinger of financial ruin. However, for Terpin, this seemingly inconsequential event was the beginning of the end. The problem was the number itself: a cell phone number that had previously served him for routine business purposes, account recovery, and multi-factor authentication, had, without notice, ceased to belong to him.


More precisely, it belonged to someone else - fraudsters who, with relative ease, managed to detach his number from his SIM card and install it on their own. The fraudsters, having gained full control of the number, blocked any attempts by Terpin to recover the account, changed his recovery e-mail on the carrier’s website to theirs, and, eventually, stole more than 24 million dollars from his crypto wallets. A teenager went to prison for this enormous-scale theft; the main suspect, 15-year-old Ellis Pinsky, was accused of leading a criminal group that extorted money from crypto wallets through SIM swaps. Among the accused was also Nicholas Truglia, one of the first and most significant contributors to the case’s high-profile notoriety.

Court records show that Pinsky and his accomplices bribed an employee of an authorized AT&T retailer, Jahmil Smith, who changed Terpin’s SIM card in favor of fraudsters. Thus, with a fairly simple but effective scam, crypto enthusiasts were deprived of millions of dollars in cash - and, for the first time in history, the cellular carrier found itself in a lawsuit with a customer over a SIM swap. After the initial phase of the trial, Pinsky reached an out-of-court agreement with Terpin, paying him 22 million in damages. The latter also succeeded in the lawsuit against AT&T, which, in an attempt to avoid paying huge sums, argued that Terpin was at fault for trusting a cellular carrier with his crypto assets. Nevertheless, in 2024, the Ninth Circuit Court ruled in favor of Terpin’s appeal against AT&T, which opened the way for a new round of litigation.

Meanwhile, for the average crypto holder, the case of Michael Terpin is an object of study and a lesson in the vulnerabilities of the blockchain’s weakest link - the account on an exchange. Terpin’s account was hacked not because of a vulnerability in the blockchain itself, but because traditional methods of multi-factor authentication proved to be ineffective against fraudsters. On the contrary, the fraudsters used fairly routine methods - social engineering and phone number swapping - to gain access to the exchange, deceive the customer about the “theft” of the number and, eventually, drain the account.

The reason why such scams are so devastating for crypto holders is that they are usually multi-stage: fraudsters not only steal crypto assets but also exploit the customer’s (often poor) account recovery policy to gain unauthorized access to the exchange. In addition, the customer can suffer from phishing, identity theft, or fraud with personal data.

Such a scenario can be avoided if the crypto holder takes at least some measures to increase the level of security and account recovery resilience. The most reasonable step would be to exclude SMS multi-factor authentication (MFA) when possible and switch to other more reliable methods, such as apps. In addition, it is necessary to ensure that the SIM card number cannot be changed at the cellular carrier without complex and verified steps.


Most importantly, it is necessary to exclude SMS from account recovery procedures or, at least, to transfer all account settings and recovery procedures to another, more reliable channel. Finally, it is vital to ensure that personal data or private keys are not stored in vulnerable places, such as a cloud. The reason why SMS MFA fails in the case of SIM swapping is that, technically, the phone number does belong to the fraudster in this case. Thus, SMS messages sent to this number are received by the fraudster, and any codes sent there are for his use and benefit. Therefore, even if the blockchain wallet or exchange account requires SMS-based MFA, this does not make it any more secure - provided that the fraudster can convince the carrier that he is the owner of this number.

And the ability to do this is ensured by a relatively simple process of number swapping in most cellular carriers around the globe. The fact that SMS MFA makes the account more vulnerable is not an undisputable truth - however, it is fair to say that SMS is one of the weakest methods in terms of account security.

This is due both to the relatively low level of protection of the SMS channel itself and to the ability of fraudsters to use social engineering to gain access to the number. Thus, SMS MFA is convenient for the customer but carries a high risk of fraud, which the Terpin case demonstrates.

Who Really Benefited from Number Swapping Fraud?

When analyzing cases of SMS-based account hijacking through SIM swapping, it is important not to overestimate the complexity of such fraud. Although the cellular carrier is indeed a vulnerable point in the security system, fraudsters often exploit other weak spots to pull off a scam.

The most common way to do this is to use phishing to obtain personal information from the victim. Information such as the account recovery e-mail, SMS number, name, date of birth, partial Social Security Number, and other personal information can be obtained either through phishing or, more rarely, through hacking social media accounts.

Thereafter, fraudsters can use this information to contact the cellular carrier and, using social engineering techniques, convince them that they are the new owner of the number. There are several ways to do this: bypassing fraud detection systems by presenting a convincing enough story, bribing an employee of the cellular carrier who handles such requests, or using insider knowledge from the company itself. Once the fraudster has gained control of the number, the next step is to change account recovery settings and gain full control over the account. The account takeover is usually completed within a few hours to a couple of days - depending on how the fraudster’s actions are disguised and how high the level of account security is. Thus, with great skill and resourcefulness, fraudsters can not only steal cryptocurrencies but also personal data and money from bank accounts.

However, despite the apparent simplicity of the scheme, SIM swapping fraud requires a certain amount of preparation and personal skills. Therefore, it is usually not the amateurish fraudster who resorts to it - but rather an organized group of criminals.


One of the most notorious cybercriminal groups operating in this niche is Scattered Spider, also known as 0ktapus, UNC3944, or Muddled Libra. According to various reports, this gang consists of independent but allied social engineers and hackers who speak English. It operates globally; the main targets are large business organizations, which are often hacked through phishing attacks on their employees.

However, the methods used by representatives of this group are not unique in principle. One of them, Noah Michael Urban, also known as King Bob or Sosa, has already been convicted of defrauding several large companies and individuals. As stated in the US legal documents, he used SIM swapping and phishing to gain unauthorized access to victims’ exchange accounts and steal their cryptocurrencies. Among other things, Urban’s criminal activities include intercepting victims’ e-mails and SMS, transferring money from wallets to accounts controlled by fraudsters, and using stolen identities to transfer large sums of money. As a result, he was sentenced to ten years in prison and was obliged to pay more than 13 million dollars in damages. However, it is not his sentence, nor his fraud that seems to be significant, but his open testimony about the specifics of the work of SIM swapping fraudsters.


According to Urban, in order to gain control of a victim’s number, fraudsters usually contact the cellular carrier. In most cases, fraudsters do not use any complex methods to convince the carrier of their identity - they just tell their story and claim to be a victim of identity theft. According to him, it took him about ten days from the moment he called the carrier to the moment he gained full control of the number and withdrew several hundred thousand dollars.

Another well-known hacker associated with the group and accused of massive fraud is Tyler Robert Buchanan. This young man from Scotland was arrested in Spain on charges of wire fraud conspiracy and aggravated identity theft. According to the prosecution, he was part of a criminal group that used text-message phishing to target businesses and SIM swapping to target individual victims. This tactic allowed them to steal at least eight million dollars in virtual currency from their victims. In addition, evidence was found of unauthorized access to the e-mail of a company executive.

The arrest of Buchanan demonstrates that law enforcement agencies are paying increasing attention to SIM swapping fraud. The authorities are not only monitoring the activities of such scammers but also bringing them to justice: Buchanan was sentenced to five years in prison for his role in the fraud scheme.

However, despite such cases, one should not be misled by the successes of the police in combating fraud. The fact that some fraudsters were caught does not mean that the cellular carrier or exchange platforms are not vulnerable. On the contrary, the existence of such vulnerabilities is confirmed by the fact that fraudsters continue to exploit them. In addition, it should be borne in mind that every fraudster has different opportunities and skills. While some may resort to phishing and a careful study of the victim’s data, others may have the resources and skills to bypass multi-factor authentication or intercept SMS traffic. Consequently, for every victim, there is always a fraudster who knows exactly how to take advantage of a particular weakness in the security system.

What Can Be Done?

One should understand that in terms of consumer-level account protection, there is no such thing as an infallible, unbreakable system or method of protection. Thus, when selecting tools for account protection, it is necessary to rely not on subjective feelings and opinions but on objective assessments and analysis.


There is no doubt that the transition from SMS-based MFA to app-based MFA will make the account significantly more secure. However, such an assessment is conditional: it all depends on what fraudster tactics we are talking about. Consequently, in each case, one should carefully consider what security measures to use, what recovery steps to take, and what account management strategies to use.

Below are some recommendations to consider before continuing to use SMS as MFA and SIM card number as account recovery factor:

Reduce the risks associated with SMS by using more reliable authentication methods for your accounts, whenever possible. It is advisable to use authenticator applications or hardware security keys where available.

Use number portability lock, number lock, or some other high-level setting on your carrier account to prevent number theft.

Take measures to secure your e-mail, as it is often the key to your accounts. Use strong and unique passwords to access your e-mail and your accounts; use hardware-based security keys or apps whenever possible. Pay special attention to the security of the account recovery procedure if it is based on SMS. It is undesirable to have a forgotten password recovery e-mail as a secondary account or one that has been used for many years. In addition, it is important to reduce the availability of personal information (such as the ability to request a recovery key via SMS).

Ensure that the private keys to your blockchain wallet are in safe storage. It is advisable to use a safe and reliable wallet for storing significant sums of money and only use non-custodial exchange wallets for the minimum necessary for trading.

Use only trusted custodians for large-scale trading. Set up withdrawal allowlists, delayed transfers, and multi-signature withdrawals where possible. A 24- or 48-hour withdrawal delay can be very convenient in case of account theft.

Reduce your visibility as a victim. Avoid posting information about your wallet balances or holdings on social networks or other platforms where this information may be visible to fraudsters. Do not publicly discuss your methods of securing accounts or the details of transactions, such as which exchange or wallet services you use.

Plan your actions in advance so that you know what to do in case of account hijacking. This includes withdrawing funds from your accounts to safe wallets and funds, changing account recovery settings, informing your carrier about account security threats, contacting banks about account security threats, and notifying trusted people.

None of these steps will make you unbreakable, but they will reduce the likelihood of becoming a victim of fraud and the damage that fraud can cause. In addition, these steps will be much more comfortable and reliable for everyday use of technology in general.

Weakness in the Wall: Summary

Although SMS MFA is generally considered to be a fairly reliable method of protecting an account, SIM swapping fraud shows that this security measure is far from being foolproof. The relatively simple scheme of deceiving the cellular carrier and thereby gaining unrestricted access to the victim’s number highlights the importance of not only protecting the account but also thinking about the ways of its recovery.

The ability to recover an account is as important as the ability to protect it, and both aspects must be considered when choosing a security strategy. The account recovery and fraudster interception strategies must be designed in such a way that they do not have any weaknesses that the fraudster can use.

As mentioned above, some account protection measures are standard procedures in the industry. For example, most companies offering such services now have policies that allow them to respond to fraud and account hijacking in a timely manner. This may include number portability lock, number lock, SIM card change delay, account recovery through keys or hardware security keys, and so on. In addition, both carriers and crypto exchanges are taking steps to improve fraud detection and response mechanisms, including stricter SIM card change verification procedures and enhanced account security settings.

Moreover, regulators are taking steps to reduce the risks associated with number portability fraud. The FCC has adopted new regulations aimed at preventing number portability fraud and strengthening consumer protection. These rules require cellular carriers to implement procedures for SIM change fraud detection, notify consumers of SIM change or number portability attempts, establish account lock procedures, and streamline fraud response processes.

Meanwhile, Know Your Customer (KYC) and Anti-Money Laundering (AML) protocols are also being strengthened - for both telecom carriers and crypto exchanges. Thus, telecom operators are now more careful about number portability fraud, and crypto exchanges are applying stricter identity verification policies for account opening and account closure. In addition, companies are using more advanced technologies to protect their accounts, such as analyzing behavioral patterns of users, considering account characteristics, and evaluating blockchain transactions during account closure.



And remember - on Netts Energy Market you can check prices of any providers right now to choose the cheapest one for renting TRON Energy.