Can someone steal my crypto through my phone number (SIM swap)?
Also asked as: “Can someone steal my crypto through my phone number?” · “How do SIM-swap attacks steal crypto from exchange accounts?”
Confirmed Published 5 min read
Short answer
Yes. A SIM swap moves your phone number to a criminal’s device, so texted login codes and password resets go to them. The FBI’s IC3 counted 971 SIM-swap complaints in 2025, across all targets, with $17.4 million in reported losses. CISA’s guidance for organizations ranks text codes the weakest login check. It calls FIDO/WebAuthn the only widely available phishing-resistant method.
The full answer
Yes. In a SIM swap, a criminal gets your mobile carrier to move your phone number onto a SIM card or device they control. The FBI describes what follows: “Once the SIM is swapped, the victim’s calls, texts, and other data are diverted to the criminal’s device,” which lets the criminal send “‘Forgot Password’ or ‘Account Recovery’ requests” to accounts linked to that number.[1] Any account that texts login codes or reset links is then exposed.
How does a SIM swap work?
The FBI says criminals mainly use social engineering, pay off carrier employees, or phish carrier staff into downloading malware, to move the number.[1] The IC3 defines the crime as “the use of unsophisticated social engineering techniques against mobile service providers to transfer a victim’s phone service to a mobile device in the criminal’s possession.”[2] Victims are chosen on purpose. The FBI’s Phoenix office wrote in 2022 that criminals “first identify a victim who is likely to own large amounts of digital currency and obtain their phone number and mobile carrier,” and that they “can defeat any SMS-based or mobile two-factor authentication on any accounts with control of the victim’s phone number, and then steal the currency.”[4] Once in control, they reset the passwords on email, cloud storage and social media accounts.[4]
Canada’s Cyber Centre lists signs that a swap may be under way or done, including an abnormal drop in messages, verification codes that stop arriving, and changes to account information you did not make. A successful swap cuts cellular service and Wi-Fi calling, but a Wi-Fi connection can keep data working, so someone whose phone switches often between cellular and Wi-Fi “may not immediately recognize” the swap.[9]
How common is it?
The FBI’s Internet Crime Complaint Center reports SIM-swap complaints as a single row, and the 2025 report does not break that row out by payment type. The FBI’s IC3 received 320 SIM-swap complaints with adjusted losses of approximately $12 million from January 2018 to December 2020, and 1,611 complaints with adjusted losses of more than $68 million in 2021.[1] Its later tables show 2,026 complaints in 2022, 1,075 in 2023, 982 in 2024 and 971 in 2025.[2][3] Reported losses fell from $72.7 million in 2022 to $17.4 million in 2025.[2][3] The 2024 and 2025 reports, read on September 29, 2026, do not say why the count fell. In the 2025 IC3 report’s crime-type table, SIM Swap is listed at 971 complaints for 2025, 982 for 2024 and 1,075 for 2023.[3] IC3 figures cover only the complaints people filed.
Do self-custody wallets face SIM-swap risk at all?
Less directly, going by the public sources. XRPL.org says “whoever has the secret key corresponding to the account’s address has full control over the account and all XRP it contains.”[12] Our analysis: a carrier can move a phone number, but nothing in that statement gives a phone number any role in controlling a ledger account, so a swap alone does not hand over the key.
The exposure comes back through storage. If a recovery phrase or key sits in a cloud note, an email draft or a photo backup, those are the accounts the FBI says criminals reset after a swap.[4] The FBI’s 2024 advice is: “Do not store information about cryptocurrency wallets — logins, passwords, wallet IDs, seed phrases, private keys, etc. — on Internet-connected devices.”[11] Where to keep a phrase instead is covered on keeping XRP keys safe.
Which login methods resist a SIM swap?
The agencies agree on the order. CISA’s 2022 fact sheet, written for organizations, ranks MFA forms “from strongest to weakest” and puts SMS or voice codes last, calling them “vulnerable to phishing, SS7, and SIM swap attacks” and a “last resort” option.[5] It adds: “The only widely available phishing-resistant authentication is FIDO/WebAuthn authentication.”[5] The FTC says an authenticator app’s passcode “isn’t susceptible to a SIM card swap attack,” and that “security keys are the strongest method of two-factor authentication.”[6] Canada’s Cyber Centre says to “only consider short message service (SMS) codes as an authentication factor for low-risk logins.”[7]
Stronger methods bring their own risk. The Cyber Centre notes that “if a user misplaces a token, they lose account access,” which is why it recommends spares.[10] How to set these up on a trading platform, with withdrawal allowlists and alerts, is on securing a crypto platform account.
How do I set up a SIM and port-out lock with my carrier?
Canada’s Cyber Centre advises “requesting your mobile provider to enable port protection or a SIM lock on your accounts, if available,” using any extra verification your provider offers, and “enabling MFA that includes methods other than those that rely on your phone number.”[9] The FBI suggests placing “a note on your account that changes must be done in person,” and verifying any call about your account by phoning the carrier’s own customer service line.[4] Carrier help pages were not read for this page as of September 29, 2026; a Rogers page on port fraud has been requested for fetching.
Is Canada’s carrier protection the same as the US requirement?
Not on the public evidence. In the US, the FCC adopted rules on November 15, 2023 that “require wireless providers to adopt secure methods of authenticating a customer before redirecting a customer’s phone number to a new device or provider” and “to immediately notify customers whenever a SIM change or port-out request is made.”[8] The FCC also noted that data breaches can make these scams easier by exposing customer details.[8] For Canada, the Cyber Centre’s advice is to ask for a lock “if available.”[9] No equivalent Canadian regulator rule was found in the Cyber Centre pages cited here as of September 29, 2026; the CRTC’s 2020 letter on SIM swapping has been requested for fetching.
What should I do if my number is taken?
For anyone who suspects a SIM swap, the FBI’s 2022 notice says to contact the mobile carrier “immediately to regain control of your phone number,” then change account passwords, ask financial institutions to place an alert on your accounts, and “report the activity to the FBI’s Internet Crime Complaint Center.”[1] Reporting routes in Canada and the US are on how to report an XRP scam.
What are the limits of this evidence?
The strongest counterpoint is scale. SIM-swap complaints have fallen each year since 2022, and the 971 in 2025 compare with 72,984 investment-fraud complaints in the same IC3 table.[2][3] The agencies also do not say text codes are useless: CISA says “any form of MFA is better than no MFA,”[5] and the FTC calls a texted code “better than nothing” when it is the only option.[6] The FBI’s Phoenix office says criminals pick victims likely to hold large amounts of digital currency,[4] and the FBI tells holders not to advertise their assets online.[1] Losing XRP through your own mistakes, with no attacker involved, is covered on losing XRP without being hacked.
What we know
- February 8, 2022: the FBI said a swapped SIM diverts the victim’s calls and texts to the criminal, who uses ‘Forgot Password’ and account-recovery requests to take over accounts.
- IC3 SIM-swap complaints (all targets, not only crypto): 1,611 in 2021, 2,026 in 2022, 1,075 in 2023, 982 in 2024 and 971 in 2025. Reported losses fell from $72.7 million in 2022 to $17.4 million in 2025.
- September 27, 2022: the FBI’s Phoenix office said criminals first pick a victim likely to hold large amounts of digital currency, and that control of the phone number can defeat any SMS-based two-factor login.
- October 2022: in a fact sheet for organizations, CISA ranked SMS and voice codes last in its strongest-to-weakest table, vulnerable to phishing, SS7 and SIM-swap attacks, and called FIDO/WebAuthn the only widely available phishing-resistant method.
- November 15, 2023: the FCC adopted rules requiring US wireless providers to authenticate customers securely before moving a number, and to notify them immediately of SIM change or port-out requests.
- February 2026: Canada’s Cyber Centre advised asking your mobile provider for port protection or a SIM lock ‘if available’.
What we reason Analysis
- A SIM swap reaches exchange accounts and email far more easily than a self-custody wallet, because an XRP Ledger account moves only with its secret key, which a phone carrier cannot reset. This follows XRPL.org’s statement that whoever holds the secret key has full control, set against the FBI’s description of password resets by text.
- Self-custody holders are still exposed if a recovery phrase sits in cloud notes, email or a photo, because those accounts can be reset by text. This follows the FBI Phoenix list of accounts criminals reset (email, cloud storage, social media) and the FBI’s 2024 advice to keep seed phrases off internet-connected devices.
- The falling complaint count since 2022 does not show why it fell; carrier rules, stronger logins and under-reporting are all possible. The IC3 tables give counts but no explanation.
- The people most at risk are those known to hold crypto. This follows the FBI Phoenix statement that criminals first pick a victim likely to own large amounts of digital currency, and the FBI’s advice not to advertise crypto holdings online.
What's still open
- The text of the FCC’s SIM-swap order (FCC 23-95) and its later compliance notice: the Federal Register page returned a bot check to the evidence fetcher on September 29, 2026. In its rule text dated December 8, 2023, thefederalregister.org reported that wireless providers are required to offer all customers, at no cost, the option to lock or freeze their account to stop SIM changes.
- No Canadian (CRTC) rule matching the US one turned up in the public sources read as of September 29, 2026. The CRTC’s 2020 letter on SIM swapping has been requested for fetching.
- How many IC3 SIM-swap complaints involved crypto: the 2025 report does not split the SIM-swap row by payment type (checked September 29, 2026).
- Court records for US SIM-swap cases (a $20 million SDNY case and a Michigan group case): the justice.gov press releases came back to the evidence fetcher as empty pages on September 29, 2026, so they are not cited; re-fetch requested.
In plain English
A criminal can talk your phone company into moving your number to their own phone. After that, the texts meant for you go to them, including the codes many websites send to check it is really you. With those codes they can reset your passwords and empty accounts such as a crypto exchange account. Government security agencies say a physical security key or an authenticator app is safer than text-message codes, and a Canadian agency advises asking your phone company for a lock on your number where one is offered.
Key terms
Sources
- Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public (I-020822-PSA) — FBI Internet Crime Complaint Center, February 8, 2022 Primary
- 2025 IC3 Annual Report — FBI Internet Crime Complaint Center, 2026 Primary
- 2024 IC3 Annual Report — FBI Internet Crime Complaint Center, 2025 Primary
- FBI Tech Tuesday: SIM Swapping — FBI Phoenix Field Office, September 27, 2022 Primary
- Implementing Phishing-Resistant MFA (fact sheet) — Cybersecurity and Infrastructure Security Agency (CISA), October 2022 Primary
- Use Two-Factor Authentication To Protect Your Accounts — Federal Trade Commission, September 2022 (checked September 29, 2026) Primary
- Steps for effectively deploying multi-factor authentication (MFA) (ITSAP.00.105) — Canadian Centre for Cyber Security, May 2023 Primary
- FCC Adopts Rules to Protect Consumers' Cell Phone Accounts — Federal Communications Commission, November 15, 2023 Primary
- Security considerations for SIMs (ITSAP.10.021) — Canadian Centre for Cyber Security, February 2026 Primary
- Secure your accounts and devices with multi-factor authentication (ITSAP.30.030) — Canadian Centre for Cyber Security, February 2024 Primary
- North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks (I-090324-PSA) — FBI Internet Crime Complaint Center, September 3, 2024 Primary
- Accounts — XRPL.org, undated (checked September 29, 2026) Primary
- Protecting Consumers from SIM Swap and Port-Out Fraud, Report and Order and Further Notice of Proposed Rulemaking (FCC 23-95) — Federal Communications Commission, Released November 16, 2023 Primary
- Protecting Consumers from SIM-Swap and Port-Out Fraud — Federal Register (Federal Communications Commission), Friday, December 8, 2023 Primary
- FCC Revises CPNI and LNP Rules to Combat SIM Swap and Port-Out Fraud — Davis Wright Tremaine LLP, 12.01.23 Secondary
- 2025 Alabama IC3 Annual Report — Internet Crime Complaint Center (IC3), read 2026-10-02 Primary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
