Crypto is usually considered as one of the safest invest as it is decentralized and cannot be hijacked easily. The investors assume their coins are safe because they have switched on the 2FA or two-factor authentication. but a here is a worrying trend, SIM swapping and other 2FA bypass techniques has shown that not all second factors are equal. This important guide explains how the attackers take over your accounts and why crypto holdings are a prime target. Also, what UK users and services should do to harden defences and eliminate the risks of sim swap and 2FA bypass.
Here is a quick summary
- SIM swap- the attacker convinces the mobile operator to move your phone number to a SIM that they can control, in such case, SMS-based 2FA becomes useless.
- 2FA bypass- The techniques ranges from stealing the SMS codes to phishing the one-time passcodes and abusing the account recovery flows.
- Crypto risk- once the attacker can reset your exchange or email passwords and bypass 2FA, then they can request for withdrawals and transfer funds.
- Best defences- make sure to replace the SMS with authenticator app or better a hardware security key like FIDO2, and lock down mobile accounts, or use cold storage for big holdings.

What is SIM swapping
SIM swap or SIM jacking or port-out fraud happens when the fraudster convivences a mobile network operator to port victim’s phone number to SIM card the attacker can control. Once the ported number rings their device any SMS or voice-based codes sent to such number go to the attacker. It includes bank and crypto exchange verification texts. The SIM swapping technique is a classic account takeover vector.
In the context of UK this is not theoretical, regulators and auditors have examined how the mobile providers detect and report such SIM swap incidents. In such case actions have been taken to improve detection and logging of the complaints. The Information Commissioner Office has published work on the SIM swap detection and the reporting in such response to growing concern. CIFAS data and reporting have shown the scale of the problem rise significantly in years with thousands of suspected incidents, crypto holders have been especially targeted in such case because of vulnerable security shields.
How attackers use SIM swapping to steal your crypto
- Reconnaissance- the attacker collects the personal details from the data breaches, and social media, or different bought lists.
- Social engineering carrier- the attacker connects with the mobile operator claiming the SIM was lost or stolen and convinces staff to port the number, often using victim details.
- Intercepting codes- the fraudsters with the SMS and calls diverted triggers password resets and receives verification codes.
- Takeover- the attackers reset passwords with email or exchange, change recovery options, and withdraw crypto. These are often to addresses that are hard to trace.
In such case, the high-profile criminal groups have used this SIM swapping tactic repeatedly to steal a large sum of crypto showing how lucrative the attack can be.
The 2FA bypass, Itis not just about sim swaps
The two-factor can mean different things and in such case attackers bypass 2FA using methods including the following
- SMS interception- the attackers use the SIM swap or SS7/SS8 network attacks.
- Phishing for codes- the attackers trick the user into entering one-time code on a fake site in the real time. It leads to real-time phishing and MFA prompt attack.
- Malware on device- the attackers are advancing with stealing the authenticator tokens or the session cookies.
- Account recovery abuse- a focus will be made on exploiting the weak or poorly protected helpdesks and automated recovery flows.
The UK cyber authority has recommended avoiding SMS for the high-value accounts wherever possible and using the stronger methods instead.

Which 2FA methods are best
- SMS- It is a convenient but weakest option and vulnerable to SIM swap and some of the network-level attacks.
- Authenticator apps like TOTP –there are significantly better apps available in the market like the Google Authenticator, Authy generate time-based one-time passwords (TOTP) or the Microsoft Authenticator on-device and are not sent over the mobile network. Still in case if your phone and cloud backup is compromised than tokens can be at risk.
- Hardware security keys like FIDO2 / WebAuthn- these are the gold standard where these use a public-key cryptography and are resilient against phishing. There can be a physical key such as YubiKey that must be present to complete the login so that an attacker with only your password and phone number is blocked.
If you are serious about cryptocurrency than a hardware key for your exchange and email accounts is one of the best single investments, you can make.
What to do if you are hit by SIM swap or account takeover
- Contact mobile operator and tell them that you have been SIM swapped and ask them to freeze or port number back and block any further port attempts in real time.
- Change the passwords on the email and financial platforms from secure device and not the possibly compromised phone. In such case use a hardware key if you have one to re-secure accounts.
- Contact the crypto exchanges and request for an emergency freeze or withdrawal halts. make sure to provide proof of identity and any timelines, as many exchanges have dedicated incident channels.
- Report to the UK authorities and report fraud to Action Fraud and to your bank. Also inform the exchange and the ICO in case personal data was breached. The ICO has always worked with providers for the improved detection and reporting of SIM-swap incidents.
Nothing is perfect
It’s a digital age and even strongest protections can be bypassed based on given enough resources. The same can be done with sophisticated social engineering, and insider threats. However, this can be prevented by combining hardware security key with careful account hygiene and diverse operational procedures like cold storage and withdrawal limits reducing risk to manageable levels. It has been noticed that criminals have stolen hundreds of millions using SIM swaps in many coordinated campaigns, the attack is effective as many people and systems still rely on SMS.
Final Thoughts
Cryptocurrency promise of self-custody is powerful, but self-custody also demands self-protection. make sure to replace the SMS where you can and adopt stronger authenticators and treat your phone number like a key and make sure to keep it locked down. The UK cyber and regulatory bodies have issued guidance and are make efforts towards the pushing providers to do much better, but the first and fastest defence is what you do today.
FAQ
1. Is SMS 2FA entirely useless?
No, better than nothing, but it is far weaker than other app and hardware-based methods. make sure, for high value crypto accounts avoid the SMS where you can.
2. Are authenticator applications safe from sim swaps?
Yes, the TOTP applications generate codes locally and they do not use mobile network, so a SIM swap alone will not capture such codes. However, the device compromise and malicious backup sync can still be at risk.
3. What is a hardware security key, and why to use one?
It is a small USB or NFC form device that uses a public-key crypto to authenticate your identity. It will prevent phishing and many remote attacks as the attacker would need the physical key.
4. Should I report my bank about crypto losses?
Make sure to report to your bank and action fraud. If any fraud occurred due to systemic weaknesses than authorities may be able to assist and investigate the matter.
5. Do UK mobile operators offer port-out protection?
Many of the operators offer additional account protections such as PIN and port freezes. Ask your provider and insist them on strong verification for your account changes.

