If your phone has just gone dead with no signal, and you did not change anything: treat it as in progress, not as a network fault. On another device, sign in to your exchange account and your email, sign out of all sessions, and check the withdrawal address list. Then call your mobile operator from any working phone and say the number has been ported without your authorisation. Do the account first. The number can be recovered later; a withdrawal cannot.
If nothing is wrong and you are here to prevent it, there are two changes to make, one with your mobile operator and one in the exchange account, and the words to use on the call are written out further down.
This is a recognised consumer-fraud category rather than a crypto curiosity — the US Federal Trade Commission and the Federal Communications Commission both publish on it, which is worth knowing because it means your mobile operator has heard of it too when you call them.
The sequence is short enough to describe in a paragraph. Someone assembles enough about you to sound like you — name, address, date of birth, the last four digits of something. They contact your mobile operator, report a lost or upgraded handset, and ask for the number to be moved to a new SIM. If the request is granted, your phone drops off the network and theirs starts receiving your calls and messages. Then they begin resetting things.
The window is short — they are working against the moment you notice the phone has gone quiet and start making calls of your own. Anything that slows your response down, such as an evening or a weekend when the operator's shops are shut, works in their favour, so do not wait for a convenient time to react.
What a SIM swapper can unlock with your phone number
Audit this on your own accounts, because the answer is usually "more than I thought".
- Any account using text-message codes as a second factor. The code arrives on their handset.
- Any account whose password reset falls back to a text message, even if the normal second factor is stronger. A fallback is a door.
- Your email account, if it has the same weakness — and this is the serious one, because the email is the recovery path for everything else.
- Voice-based verification, where a service reads a code out to the number.
Notice how little of that involves your exchange directly. The most damaging path does not need the exchange to accept text messages at all: if the number can reset the email, the email can reset the exchange.
Two changes that protect you from a SIM swap
At the exchange, and at your email provider
Enrol a second factor that is not a text message, then go back and check what the account will still accept. An account with an authenticator app configured but text-message verification still enabled as an alternative is protected at the strength of the weaker option. Removing the weak one is usually a separate action from adding the strong one, and it is the half that gets forgotten.
Do this on the email account before the exchange account. It is the higher-value target and the one people forget, because it does not feel like a financial account.
Which strong method to use is a decision with a few honest trade-offs, but for this specific threat any of the three non-text options removes it entirely.
At the mobile operator
Call your operator and ask for a port-out lock, transfer PIN, or account PIN — the name varies by country and provider. What you want is a condition that must be satisfied before the number can move, one that a stranger with your date of birth cannot satisfy.
Ask two follow-up questions while you have someone on the line. Can the lock be removed over the phone, or does it require visiting a shop with identification? And is there a note on the account requiring a callback before any transfer? The strength of this protection varies enormously between providers, and the only way to know what yours offers is to ask.
Do not publicise the connection between your phone number and your holdings. A targeted swap needs a target, and mentioning crypto somewhere public, under a name or handle that can be matched to a real identity, is the easiest way to become one. There is no setting that protects against being visibly worth the effort.
What to ask your mobile operator for: a port-out lock or transfer PIN
"Ask your provider for a port-out lock" is easy to write and oddly hard to do, because the person answering may not use that phrase, and the protections sit under different names in different countries. So here is what to actually say, and what to listen for.
Open with the outcome rather than the jargon: "I want to stop anybody transferring my number to another SIM or another network without my authorisation. What do you have?" That phrasing survives every naming convention, and it puts the burden of finding the right product on the person who knows their own catalogue.
Then ask three follow-ups, because the answers vary enormously and the differences are the whole point:
- Can the protection be removed over the phone? If yes, it is worth much less than it sounds — the same conversation that moves your number can remove the lock first. A protection that requires visiting a shop with identification is a genuinely different product from one that requires a passphrase read out to an agent.
- Is there a note on the account requiring a callback before any transfer? Some providers will add one on request. It costs nothing and it inserts a step that a stranger cannot complete.
- What happens if I have an eSIM? Provisioning an eSIM to a new device is a different flow from swapping a physical card, and on some networks it is faster and needs less. If your number is on an eSIM, ask specifically about that path rather than assuming the lock covers it.
Write down the date, the reference number and the name of whoever you spoke to. Not out of caution about them — out of usefulness later. If the number does get moved, the first question anybody asks is when the protection was applied, and a reference number turns that from a memory into a record.
One thing not to do on that call: do not explain why. "I hold cryptocurrency and I am worried about a SIM swap" tells a stranger on a support line that your number is attached to money. The request does not need a reason, and if you are asked for one, "account security" is enough.
Should you use a second phone number for 2FA?
A recurring suggestion in this area is to keep a separate number that exists only for account verification: a cheap prepaid line, or a number from a service that provides them, never given to anybody and never used for calls.
The logic is sound. An attacker cannot socially engineer a number they do not know exists, and the usual route to discovering someone's number — it being the one they give out — is closed. For people with a genuinely large balance this is a reasonable measure.
Two caveats stop it being a general recommendation. Prepaid numbers can be recycled if the line lapses, which means the number protecting your accounts could later belong to a stranger; this is a real failure mode and it is silent. And numbers from app-based providers are frequently rejected by financial services, so you may find the number is not accepted where you most want it.
For most readers the better version of this idea costs nothing: stop using the number as a verification method at all, keep it purely for alerts, and put a transfer lock on it. You get most of the benefit without maintaining a second line whose main risk is that you forget it exists until the day it stops working.
Signs of a SIM swap in progress, and what to do first
The first sign is almost always the same and almost always dismissed: the phone loses service and does not get it back. Not one bar. No service, in a place where you normally have coverage, and a restart does not fix it.
If that happens and you hold crypto, treat it as an incident rather than a network fault. Two minutes of assuming the worst costs you nothing if you are wrong.
The order, in the first five minutes:
Immediately, from another device
Get to your email account and change its password from a computer or a second phone with a different number. Email first, exchange second — it is the recovery path for everything.
Then the exchange
Sign in, revoke every session, and check whether a withdrawal address or a verification method has been changed. Then work down the first-hour sequence, which assumes exactly this situation.
Then the operator
Contact them by any means other than your own number, report the transfer as fraudulent and ask for it to be reversed. Write down the time you called and who you spoke to.
Afterwards
Once the number is back, do not simply re-enable text-message verification because it is convenient again. That is how the same person gets a second attempt.
One closing thought that applies beyond this attack. A withdrawal allowlist with a long waiting period is the protection that keeps working even when the login has been taken, because it does not depend on who you are — it depends on time. That is an argument made at length elsewhere, and a SIM swap is the scenario where it earns everything it cost you in inconvenience.
The exchange-side advice here follows the two-factor options documented by the platforms themselves, including one exchange's own authenticator guidance, read September 2026. The mobile-operator side varies by country and provider and we have not surveyed them, so the instruction is to ask yours rather than to expect a particular feature. No figures on how often this happens appear above, because the ones in circulation are not from sources we could verify.