Definition
SIM swapping abuses the mobile account’s number-transfer process rather than copying a blockchain key directly. Once a number is reassigned, calls and text messages may reach the attacker instead of the owner. This can put SMS verification and phone-based recovery at risk. Legitimate SIM replacement also exists; the malicious element is an unauthorized reassignment.
How It Works
An attacker may exploit weak carrier verification or compromise account-management processes. The reassigned number can then become a route into services that trust possession of that number. Loss of phone service can be a warning sign, but outages also have ordinary causes. The attack does not automatically reveal codes generated by an unrelated offline authenticator or private keys stored on separate secure hardware.
Key Considerations
Protect the carrier account with available account locks and a strong PIN, and use authentication methods less dependent on SMS where supported. Check recovery options as well as normal login methods. If service unexpectedly disappears alongside account alerts, contact the carrier through a verified channel and secure important accounts from a trusted device. Do not rely solely on the affected number to regain control. Review active sessions and recent changes, and remember that restoring the number alone may not invalidate access already obtained elsewhere.