SIM Swap Attacks

SIM swap attacks let criminals hijack your phone number — and with it, bypass the SMS-based security protecting your crypto accounts. Understanding how they work, and how to protect yourself before an attack happens, is critical.

SIM Swap Attacks

What Is a SIM Swap Attack?

A SIM swap attack — also called SIM hijacking or SIM porting fraud — is a form of identity theft in which an attacker convinces your mobile carrier to transfer your phone number to a SIM card they control. Once they have your number, any SMS-based two-factor authentication (2FA) codes sent to that number go directly to the attacker instead of you.

For crypto accounts, this is particularly dangerous. Many platforms — and many users — rely on SMS 2FA as a security layer. Once an attacker has your phone number, they can request a password reset on your email, intercept the 2FA code, access your inbox, then do the same on your crypto exchange account. The entire chain can collapse in minutes, and by the time you realise something is wrong, your funds may already be gone.

SIM swap fraud is one of the fastest-growing forms of financial cybercrime in Canada, and cryptocurrency accounts are a primary target because of the speed and irreversibility of crypto transactions.

How a SIM Swap Attack Unfolds

Stage 1 — Reconnaissance. The attacker gathers information about you — your full name, phone number, carrier, email address, and answers to common security questions. This information is often obtained through data breaches, phishing, social media, or social engineering.

Stage 2 — Impersonation. The attacker contacts your mobile carrier — by phone, online, or in a physical store — posing as you. They claim they've lost their phone, damaged their SIM, or need to upgrade their device, and request that your number be transferred to their SIM card.

Stage 3 — The Transfer. If the carrier accepts the impersonation, your number is ported to the attacker's SIM. Your phone loses signal — calls and texts now go to the attacker.

Stage 4 — Account Takeover. The attacker uses your phone number to trigger password resets on your email and crypto accounts, intercepts the SMS 2FA codes, and gains full access.

Stage 5 — Funds Drained. Crypto is transferred out of your accounts immediately. Because blockchain transactions are irreversible, recovery is extremely difficult once funds leave.

Types of SIM Swap Attacks

Carrier Social Engineering — The attacker calls your mobile carrier and persuades a representative to transfer your number by providing personal details obtained through prior research or data breaches.

In-Store Impersonation — The attacker visits a physical carrier store with fake or fraudulent identity documents to request a SIM swap in person.

Insider Threats — In some cases, a corrupt employee at a mobile carrier performs the SIM swap in exchange for payment from the attacker.

Number Porting Fraud — The attacker initiates a fraudulent port of your number to a different carrier entirely, using forged authorisation details.

SIM Swap as Part of a Larger Attack — SIM swapping is often one step in a broader campaign that began with phishing or social engineering to collect the personal information needed to pass carrier security checks.

Warning Signs

  • Your phone suddenly loses signal or shows "No Service" or "SOS Only" in an area where you normally have coverage
  • You stop receiving calls and text messages unexpectedly
  • You receive a text from your carrier about a SIM change or number transfer you didn't request
  • You're unexpectedly logged out of your email, exchange accounts, or other platforms
  • You receive password reset notifications or 2FA codes you didn't request
  • Your mobile carrier account shows a new SIM or device you don't recognise
  • You receive an alert that your account was accessed from an unfamiliar device or location

Example: You wake up to find your phone has no signal. Within minutes, you receive email notifications of password reset requests on your email and your Ndax account — but the 2FA codes go to the attacker who now controls your number. By the time you contact your carrier and confirm the SIM swap, your account has been accessed and funds transferred out.

What Ndax Will Never Do

Ndax will never ask you to verify your account by SMS only, encourage you to rely solely on SMS 2FA for account security, contact you by phone or SMS to ask you to confirm a SIM change, or transfer your funds at your request through an unsolicited call or message. If you receive any such communication claiming to be from Ndax, do not act on it — contact us directly at ndax.io.

How to Protect Yourself

  • Switch from SMS 2FA to an authenticator app — Google Authenticator, Authy, or a hardware key like a YubiKey are significantly more secure than SMS codes, because they aren't tied to your phone number
  • Set a SIM lock or port freeze with your mobile carrier — most Canadian carriers allow you to add a PIN or security phrase required before any SIM changes are processed; call your carrier and ask specifically about SIM lock or number porting protection
  • Use a strong, unique PIN for your carrier account — avoid easily guessable combinations like birthdates
  • Use a dedicated email address for your crypto accounts that is not publicly associated with your identity
  • Enable all available security features on your Ndax account, including non-SMS 2FA and withdrawal address whitelisting where available
  • Limit the personal information you share publicly on social media — attackers use this for reconnaissance before contacting your carrier
  • Use a password manager and never reuse passwords across accounts
  • Be cautious of phishing attempts designed to collect the details an attacker would need to impersonate you to your carrier

Think Your SIM Has Been Swapped?

Act immediately — every minute matters.

Call your mobile carrier right away and tell them you believe you are the victim of a SIM swap. Ask them to reverse the swap and lock your account against further changes.

If you cannot call (because your phone has no service), use Wi-Fi calling, a different phone, or contact your carrier through their online chat or website.

Change your Ndax password immediately from a trusted device. Confirm that your 2FA method is still active and has not been changed. Review your recent account activity for any transactions or withdrawals you did not initiate.

Change the passwords on your email and any other accounts that use SMS 2FA, starting with the email address linked to your Ndax account.
If you transferred crypto from your Ndax account, contact [email protected] right away. Cryptocurrency transfers are generally irreversible, but the information you provide may help us review the activity and protect other users.

If fiat funds, bank transfers, credit cards, debit cards, or payment services were involved, notify the financial institution where the funds originated.

Document everything — timeline of events, screenshots, account activity logs, carrier correspondence, and any communications you received.

How to Report

  • Report to Ndax at [email protected] if your Ndax account was involved or crypto was transferred from your Ndax account
  • Report to the CAFC at antifraudcentre.ca
  • Report to the RCMP at reportcyberandfraud.canada.ca
  • Report to your mobile carrier's fraud team — ask them to flag your account and investigate how the swap was authorised
  • If personal information was exposed, place a fraud alert with Equifax Canada and TransUnion Canada, and monitor your bank, crypto, and email accounts closely for unusual activity
  • Notify the financial institution where the funds originated, such as your bank, card provider, or payment service provider

Don't forget to follow us on social media for more updates and join the conversation on our forums.

Disclaimer: This article is not intended to provide investment, legal, accounting, tax or any other advice and should not be relied on in that or any other regard. The information contained herein is for information purposes only and is not to be construed as an offer or solicitation for the sale or purchase of cryptocurrencies or otherwise.