Protect yourself: attackers easily steal cryptocurrency via user phone numbers

In what will certainly be a wake up call to most people, "cybersecurity and industry experts say investors should guard their cellphone numbers with the same paranoia with which they guard their social security numbers." In an increasingly common form of cryptocurrency theft, attackers are "SIM swapping," or porting a person's phone number from their owned device to a new device. Once they have done so, they are able to take control of online accounts that use a text or phone call for 2-factor authentication (2FA):

"After a criminal hacks into the person’s email or cryptocurrency account from their own devices, what’s known as “two-factor identification” will send a text code to the phone number as a form of security, and to prevent any sort of unauthorized log in. But because the hacker now controls that phone number, there’s no way of the rightful owner regaining control or stopping the hack."

There have been many such incidences of theft, including Cody Brown's well-documented theft via a port of his Verizon account to a new device followed by attackers taking control of his Coinbase account. Additionally, AT&T is being sued for $224M by a man who had $24M in cryptocurrency stolen from him in a SIM swapping attack.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

There are a few very straightforward ways that people can immediately improve their security:

  • Put a PIN on your mobile carrier account
  • Use stronger 2FA, such as Google Authenticator or Authy rather than a text or phone call
  • Use a separate phone number, or remove a phone number *entirely* from key accounts

Stay safe out there by vigilantly monitoring your mobile account and taking the steps above, at a minimum.

(Source: CNBC)

About Author

Mike Dudas is one of the founders of The Block and was the CEO until April 2020 and a board member until April 2021. Prior to starting The Block, Mike was co-founder and CRO of Button, the leading global, mobile performance marketing platform. Mike is a builder of mobile commerce businesses, having worked at Google, Braintree/Venmo and PayPal. Early in his career, Mike worked in corporate M&A and strategy for Disney. Mike earned a BA from Stanford and an MBA from Kellogg.