A crypto SIM-swap attack begins when a criminal transfers a victim’s mobile number to a SIM or eSIM under the criminal’s control. Calls and text messages can then arrive on the attacker’s device, creating an opportunity to intercept SMS verification codes, reset passwords and take over cryptocurrency exchange accounts. Protecting funds requires securing the mobile account, email, authentication methods and withdrawal controls—not relying on one security product.

Last reviewed: September 7, 2026. Carrier procedures, exchange controls and ExpressVPN features vary by country, plan and device. Confirm current settings with the relevant provider. This independent educational guide does not guarantee protection or recovery and is not financial advice.

What is a crypto SIM-swap attack?

A subscriber identity module connects a mobile subscription and telephone number to a device. With a physical SIM, the chip is moved between devices; with an eSIM, the profile can be transferred digitally. A legitimate transfer is useful when replacing a phone. A fraudulent transfer, often called SIM swapping, SIM jacking or number porting fraud, redirects the number without the subscriber’s informed permission.

The attacker may impersonate the subscriber when speaking to a carrier, abuse a compromised carrier account, use stolen identity information or persuade an insider to approve a transfer. Once the original phone loses service, the attacker may receive calls and SMS messages intended for the victim.

A SIM swap does not reveal a non-custodial wallet’s private key by itself. The danger arises when the phone number is trusted by an email provider, exchange, cloud backup, bank or recovery workflow. One compromised recovery channel can become a bridge to several connected accounts.

How a phone number can lead to a crypto account takeover

Stage Attacker action Potential consequence
1. Reconnaissance Collects a name, phone number, email address and exchange clues. More convincing carrier and account impersonation.
2. Number transfer Moves the number to another SIM or eSIM. The victim’s handset unexpectedly loses cellular service.
3. Email recovery Requests a password reset and intercepts an SMS code. Email access exposes alerts and connected accounts.
4. Exchange recovery Resets credentials or satisfies weak SMS verification. Account access, changed security settings or API keys.
5. Asset movement Attempts withdrawals, trades, purchases or address changes. Financial loss and a more difficult recovery process.

Actual attacks do not always follow this exact order. A criminal may compromise email first, socially engineer support or combine a SIM swap with phishing and previously leaked passwords. This is why replacing SMS alone is important but not a complete defense.

Warning signs that require immediate action

  • Cellular service suddenly disappears even though other nearby phones have coverage.
  • The device shows “SOS only,” “No service” or an unexpected inactive-SIM message.
  • The carrier sends notice of a SIM activation, eSIM download or number-port request you did not make.
  • Password-reset, login or one-time-code messages arrive without your request.
  • Email alerts report a new device, password change, API key or withdrawal address.
  • Friends receive unusual calls or messages that appear to come from your number.
  • You are unexpectedly signed out of an exchange or primary email account.

A network outage or damaged SIM can produce similar symptoms. Do not spend time guessing. Contact the carrier through a separately verified channel and inspect critical accounts from a trusted connection.

Why SMS 2FA is a weak choice for valuable crypto accounts

SMS two-factor authentication is better than using only a password, but the code depends on control of a transferable phone number and the carrier’s account-recovery process. That creates risks outside the exchange’s direct control. Text messages can also be exposed through malicious apps, phishing, notification previews or synchronized devices.

Prefer a phishing-resistant security key or passkey when the exchange supports it. An authenticator application that generates codes locally is generally less exposed to a number transfer, though malware, cloud backup compromise and fake login pages remain risks. Store recovery codes offline and never photograph or email them to yourself.

Method SIM-swap exposure Important limitation
SMS code High when the number is transferred. Depends on carrier and recovery controls.
Authenticator app Not delivered through the phone number. A fake site can still capture a valid code.
Passkey Not based on SMS. Recovery and device synchronization must be secured.
Hardware security key Not based on SMS and resistant to ordinary phishing. Requires a protected spare and recovery plan.

Harden the mobile carrier account

  1. Create a unique carrier password. Do not reuse an email, exchange or shopping password.
  2. Set an account PIN. Avoid birthdays, address numbers and predictable sequences.
  3. Request a port-out or number-transfer lock. Terminology and availability differ by carrier.
  4. Ask about high-security verification. Some carriers support in-person identification or additional approval before SIM changes.
  5. Secure the carrier email address. Protect it with strong authentication that does not depend only on the same phone number.
  6. Review authorized users. Remove former employees, family members or devices that no longer require access.
  7. Reduce public exposure. Avoid publishing the number used for financial recovery on social profiles or business directories.

Carrier controls reduce risk but cannot eliminate malicious insiders, procedural mistakes or identity fraud. Treat the telephone number as one component of identity rather than proof that a person is the account owner.

Secure email before securing the exchange

The primary email account is often the master recovery channel. Give it a unique password and use a security key, passkey or authenticator instead of SMS where possible. Review active sessions, forwarding rules, filters, recovery addresses, app passwords and connected applications. An attacker may add a forwarding rule so that exchange alerts disappear from the inbox while still reaching the attacker.

Consider using a private email address solely for financial accounts and never publishing it. Do not place the exchange name in the address. Protect the email provider’s recovery process with the same care as the exchange login itself.

Configure stronger exchange protections

  • Replace SMS authentication with the strongest supported alternative.
  • Enable a withdrawal-address allowlist and a delay for new addresses.
  • Turn on anti-phishing codes so genuine exchange emails contain a recognizable value.
  • Require authentication for withdrawals, API creation and security-setting changes.
  • Review login sessions, trusted devices and active API keys regularly.
  • Use separate API keys for each application and disable withdrawal permission unless essential.
  • Activate transaction alerts through more than one protected channel where available.
  • Keep only the amount needed for near-term activity on a custodial exchange.

Feature names vary across Coinbase, Kraken, Binance, Bybit and other platforms. Navigate from a bookmark or the genuine mobile application instead of following links in an unsolicited message.

Protect wallet recovery paths

A self-custody wallet is not normally recovered with a telephone number, but related services might be. Cloud backups, password managers, browser profiles and email accounts can expose wallet data or provide context for convincing social engineering. Never give a seed phrase or private key to a carrier, exchange, wallet developer or person claiming to investigate a SIM swap.

Store recovery material offline in a location protected from theft, fire and accidental disposal. Test the recovery procedure using a safe method before relying on it. Do not type a seed phrase into a website reached through search advertising, email, SMS or social media.

What ExpressVPN can and cannot do

ExpressVPN encrypts supported internet traffic between a device and the VPN server. This can reduce exposure to a malicious or curious local network operator, especially on hotel, airport or café Wi-Fi. Websites generally see the VPN server’s public IP address rather than the connection’s assigned public IP.

A VPN cannot prevent a carrier from transferring a telephone number. It cannot secure weak carrier verification, replace exchange authentication, stop a user from disclosing a one-time code or protect a seed phrase entered into a fraudulent website. Carrier locks and phishing-resistant authentication address those risks more directly.

Use ExpressVPN as one network-security layer while accessing exchange and email accounts on untrusted networks. Enable automatic connection and Network Lock where appropriate, keep the application updated and verify that the VPN is connected before signing in. HTTPS, a clean device and careful domain verification remain necessary.

Emergency response: the first 30 minutes

  1. Call the carrier from another device. Use a number from the carrier’s official website or account paperwork. Report an unauthorized SIM change and request an immediate freeze.
  2. Protect the primary email account. Change its password from a trusted device, revoke unknown sessions and remove unfamiliar recovery methods or forwarding rules.
  3. Contact exchanges through official channels. Ask them to lock withdrawals and document the incident. Do not use phone numbers sent by text.
  4. Revoke compromised sessions and API keys. Inspect security history before assuming that a password change removed every access method.
  5. Secure financial accounts. Contact card issuers or banks if purchases, transfers or identity fraud are possible.
  6. Preserve evidence. Save carrier notifications, timestamps, email headers, transaction IDs and support case numbers.
  7. Notify relevant authorities. Reporting options depend on jurisdiction and the nature of any loss.

If a non-custodial recovery phrase was exposed, changing an exchange password is insufficient. From a clean device, create a new wallet with a new phrase and transfer remaining assets after carefully verifying the destination. Never reuse the compromised phrase.

Recovery checklist after service is restored

  • Confirm that the carrier removed every unauthorized SIM or eSIM.
  • Set a new carrier PIN and restore the number-transfer lock.
  • Change passwords for email, exchanges and the carrier in that priority order.
  • Replace SMS authentication and regenerate backup codes.
  • Review exchange balances, trades, withdrawal addresses and API activity.
  • Check email trash, forwarding, filters and delegated access.
  • Inspect devices for malicious applications and install security updates.
  • Monitor financial and identity records for follow-on fraud.
  • Record what failed and update the recovery plan while details are fresh.

Common mistakes to avoid

Do not assume cellular service returning means the incident is finished. The attacker may retain an email session, exchange API key or approved withdrawal address. Do not negotiate with a person who contacts you claiming to recover stolen crypto for an advance payment. Do not move assets to a “safe wallet” supplied by unsolicited support. Do not disable security controls merely because an attacker creates urgency.

A second phone number can separate public communication from sensitive recovery, but it still requires carrier protection. An authenticator on the same phone remains useful against SIM swapping because its codes are not delivered through the telephone network; however, device theft and malware must still be considered.

Frequently asked questions

Can ExpressVPN stop a SIM swap?

No. A VPN protects supported network traffic. Preventing unauthorized number transfers requires strong carrier-account controls, while protecting crypto accounts requires stronger authentication and recovery settings.

Does a SIM swap expose a seed phrase?

Not directly. It may expose accounts or cloud services connected to the number, and attackers can use control of the number to deliver convincing phishing attempts. A seed phrase must remain offline and private.

Is an authenticator app safer than SMS?

For SIM-swap risk, yes, because authenticator codes are generated locally rather than delivered to the transferred number. Security keys and passkeys can provide stronger phishing resistance where supported.

Should I remove my phone number from every account?

Remove it as an authentication or recovery method where a stronger supported option exists. Some services require a number for operational reasons, so secure the carrier account and minimize the number’s authority.

Why did my phone lose service?

A SIM swap is one possibility, but outages, account problems and hardware failures can look similar. Contact the carrier immediately through an independently verified channel.

Can a criminal withdraw funds immediately?

That depends on the exchange’s security delays, allowlists, identity checks and the access obtained. Rapid reporting can improve the chance of stopping pending activity but cannot guarantee recovery.

Final takeaway

SIM-swap defense is an account architecture problem, not a single-toggle solution. Lock the mobile account, move critical logins away from SMS, protect email as the master recovery channel, enable exchange withdrawal controls and keep self-custody recovery material offline. ExpressVPN can strengthen the network layer when connecting to these services, but it must be combined with carrier and account protections.

For additional context, consult ExpressVPN’s official guide to SIM swapping and account protection. Verify carrier and exchange procedures through their official applications or directly entered domains.

Visit ExpressVPN ↗Official website