SIM swap attacks transfer a victim's phone number to an attacker-controlled SIM, intercepting SMS-based 2FA codes and enabling exchange account takeover.

Replace SMS 2FA with hardware security keys or authenticator apps on all exchange and email accounts linked to crypto holdings. Add carrier-level port protection where available.

Minimize public exposure of phone numbers and personal data that attackers use for social engineering carrier support staff.

Post-SIM-swap recovery depends on exchange support responsiveness; prevention is significantly more effective than remediation.