The $24 Million SIM Swap That Targeted a Cryptocurrency Investor
Not every attack in this series requires malware or a stolen password. Some require nothing more than a phone call to the right person or the wrong one. This is the case that shows what happens when a phone number alone stands between an attacker and a fortune.
What Happened
January 2018. An AT&T retail employee processed a SIM swap request for a phone number belonging to Michael Terpin, a cryptocurrency investor and entrepreneur, without asking for identification and despite a six-digit security PIN meant to prevent exactly this. Attackers walked away controlling his phone number entirely.
Once in control, they used it to reset passwords across his email and cryptocurrency exchange accounts, both of which relied on the phone number for identity verification. It was the second such attack against him within seven months. The first, a smaller incident five months earlier, should have been a warning sign.
The Damage Caused
Terpin lost close to $24 million in cryptocurrency in the January attack. He sued AT&T for $224 million, arguing the carrier's negligence, an employee bypassing its own stated security protocol, directly enabled the theft. The case has moved through the Ninth Circuit Court of Appeals for years since, a reminder that even a clear-cut loss does not mean a quick resolution.
What Caused the Breach
A SIM swap does not require any flaw in a victim's own security practices. It requires convincing, tricking or bribing someone at a mobile carrier into transferring a phone number to a SIM card the attacker controls. Terpin had done the things a reasonably careful person would do. He had a PIN on file with AT&T specifically meant to block unauthorised swaps.
The PIN did not matter, because the employee did not check it. The deeper failure was structural. A phone number, tied to nothing more than a name and a request at a retail counter, had become the master key to a fortune, because two-factor authentication and password recovery on his most important accounts routed through SMS.
What Could Have Been Done to Avoid the Issue
For anyone holding meaningful cryptocurrency or other high-value digital assets, the practical answer is to remove SMS from the picture entirely. Cold storage, hardware wallets kept offline and disconnected from any phone number or internet-facing account, protects the asset itself regardless of what happens to a carrier account. For accounts that must stay online, authenticator apps or hardware security keys replace a vulnerable phone number with a factor no carrier can be tricked into handing over.
None of this makes an account swap-proof. A determined attacker with the right social engineering approach or the right bribe can still find a way through a carrier's process. It does mean that when they do, there is nothing of value sitting behind the phone number for them to reach.
Every security measure involves a trade-off between protection and convenience. Where that balance should sit depends on the resources a realistic attacker would bring to bear against you specifically. For most people, a handful of consistent habits closes the majority of that gap. For those whose assets or profile make a determined, well-funded attacker plausible, a more considered approach becomes worth the investment.
At Executive Privacy Advisors, we build that approach around your specific threat profile rather than a generic checklist. We extend the same thinking to your whole household, not just one set of accounts.
Ready to Understand your families risks?
Request an AuditPublished by Executive Privacy Advisors.
This article is for general informational purposes only and does not constitute security, legal or risk advice. Services described are subject to assessment, licensing and availability in your area. Your circumstances may differ and you should seek a professional assessment before making decisions.