What a SIM swap actually reaches
Anything where the phone number can reset a password or satisfy a second factor. That typically means your email, which then unlocks almost everything else, including centralised exchange accounts.
It does not reach a self-custodied wallet. A private key is not protected by a phone number, which is one of the genuine advantages of self-custody.
Why SMS keeps being accepted
It has near-universal reach and no app requirement, so it remains the default recovery mechanism at many providers. The weakness is not the message — it is that the number can be reassigned by a human decision at a call centre.
Removing SMS where possible, and adding a carrier-level port-out PIN where it is not, closes most of the gap.
Factors that are meaningfully stronger
A hardware security key is the strongest widely available option and resists phishing by design, because it verifies the domain. An authenticator application is a large improvement over SMS. Both should have recovery codes stored offline.
Email-based recovery is only as strong as the email account, so that account deserves the strongest factor you have.
Reducing the blast radius
Use a dedicated email address for financial accounts that is not published anywhere. Remove SMS recovery wherever an alternative exists. Keep self-custodied funds in wallets whose keys have no relationship to any online account.
FBT Swap requires no account, no email and no phone number for the on-chain swap interface, so there is no FBT login for a SIM swap to take over.