Live · Tue, Aug 4, 2026 · 14:03 UTC Block 843,917 Fees 14 sat/vB Fear & Greed 72 · Greed
Newsletter Pro Terminal Sign in
McLeod Pacific Investments.
Subscribe →
Live · 14:03 UTC Block 843,917 F&G 72
Bitcoin Security Bitcoin Security desk

How to protect your Bitcoin from SIM swap fraud

SIM swap fraud lets criminals take over your phone number without touching your device, bypassing SMS-based security and gaining access to Bitcoin accounts. Here's what the attack looks like and how to stop it.

Close-up of a smartphone with a SIM card and memory card, showcasing modern technology.

Photo by Silvie Lindemann on Pexels

SIM swap fraud is one of the more unsettling attacks targeting Bitcoin holders because it requires no malware, no phishing link, and no access to your device. The attacker calls your mobile carrier, impersonates you with a few scraped personal details, and convinces staff to transfer your phone number to a SIM they control. From that moment, every SMS verification code sent to your number lands in their hands instead of yours. For anyone relying on SMS-based two-factor authentication on a Bitcoin exchange or wallet service, that's a direct path to a drained account.

How SIM swap fraud actually works

Most mobile carriers let customers transfer their number to a new SIM card when they lose a phone or upgrade a device. The verification process typically asks for an account PIN, the last four digits of an ID, or answers to security questions. Attackers gather this information from social media profiles, data breaches, and phishing calls made to the victim directly. With enough detail, a convincing call to your carrier's support line is all it takes.

Once the number ports over, the attacker triggers a password reset on a target account, receives the SMS code, and resets the login credentials. The entire process can take under an hour. The victim usually notices something is wrong only when their phone loses signal, because their number has been moved to a different carrier or SIM.

Telstra, Optus, and Vodafone all maintain some form of SIM swap protection, but the strength of those processes varies. Frontline customer service staff face pressure to resolve calls quickly, and social engineering exploits exactly that tension.

Why Bitcoin holders are a specific target

SIM swap attacks follow the money. Bitcoin accounts are attractive because transactions are irreversible. A bank transfer can be frozen or recalled. A Bitcoin withdrawal cannot. Attackers know that if they can get into an exchange account and initiate a withdrawal, the funds are gone before any support team can respond.

Crypto exchanges in Australia, including registered Digital Currency Exchange Providers like McLeod Pacific Investments, require identity verification and implement security controls, but the weakest link is often the phone number tied to a customer's account. If that number is compromised, an attacker can reset passwords and bypass SMS authentication in one move.

High-value accounts attract targeted attacks. But even smaller holdings are worth pursuing at scale. Automated tools let criminals attempt hundreds of SIM swaps per day, harvesting accounts where SMS-based security is the only barrier.

How to protect yourself from SIM swap attacks

The most effective protection is removing SMS-based authentication entirely from your Bitcoin-related accounts. Here's how to work through that systematically.

  • Switch to an authenticator app. Google Authenticator, Authy, and similar apps generate time-based codes on your device, not via SMS. An attacker who controls your phone number gets nothing from these. McLeod Pacific Investments recommends enabling app-based authentication on every account that supports it.
  • Use a hardware security key. Devices like a YubiKey provide the strongest form of two-factor authentication. They require physical possession of the key to log in, making remote attacks essentially impossible.
  • Lock your mobile account with a carrier PIN. Contact your carrier directly and add a dedicated SIM lock PIN, separate from your account password. Some carriers in Australia also allow you to add a verbal passphrase that must be given before any account changes are made in-store or over the phone.
  • Enable a number porting freeze. Ask your carrier to block outbound number porting without in-person verification at a store with photo ID. This adds significant friction for any attacker attempting a remote swap.

Beyond authentication, reduce how much personal information is publicly visible. An attacker building a social engineering profile draws on your social media, LinkedIn, and any data exposed in past breaches. Limiting that surface area directly reduces the quality of information they can use in a carrier call.

What to do if you suspect a SIM swap has happened

A sudden loss of mobile signal is the most common first sign. Your phone shows "No service" or "SOS only" even in an area with normal coverage. Don't assume it's a network outage. Call your carrier immediately from a different device or landline and ask whether your number has been ported or a SIM replacement has been requested.

If a swap has occurred, act in this order. First, tell the carrier to reverse the port and flag the account for additional verification requirements. Second, change the passwords on your Bitcoin exchange accounts and email from a device on a trusted network. Third, check withdrawal history and open support tickets with your exchanges immediately. Most platforms have a process to freeze withdrawals pending investigation.

If funds have already moved, report the incident to the Australian Cyber Security Centre (ACSC) and your local police. Recovery of Bitcoin is not guaranteed, but a formal record helps investigators if the attacker targets others.

The link between SIM swaps and broader Bitcoin security

SIM swap fraud doesn't exist in isolation. Attackers who target crypto holders combine it with credential stuffing, phishing, and account takeover techniques. Bitcoin social engineering scams frequently precede a SIM swap: a victim receives a convincing message that nudges them into revealing partial personal details, which the attacker then uses to pass a carrier's identity check.

Strong authentication also needs to sit alongside good wallet hygiene. Keeping significant Bitcoin holdings off exchanges and in self-custody reduces the exposure from any single account compromise. Understanding cold wallet vs hot wallet storage is directly relevant here: funds held in a hardware wallet are not accessible to an attacker who only controls an exchange login.

The pattern is consistent across attacks: the more an attacker can chain together, the larger the payout. Breaking that chain at any point, whether by removing SMS authentication, using a hardware wallet, or locking down your carrier account, forces the attacker to work harder for a smaller reward. Most move on.

→ The Confirmations · Daily newsletter

One email at 06:00 UTC. Six minutes. The only digest written for desks, not for retail.