Transparent, non-custodial, yours

Your phone number is not an authentication factor

A phone number can be transferred to an attacker with social engineering. What that breaks, what it does not, and which factors to use instead.

What it is Reassignment of your phone number to an attacker
Reaches SMS codes and any account recoverable by phone number
Does not reach A self-custodied private key

FBT Swap

What you should know

A SIM swap is a carrier-level account takeover: the attacker persuades or bribes a provider to move your number to their device. Every code sent to that number then reaches them.

It matters for crypto because so many accounts adjacent to crypto — exchanges, email, cloud storage — still accept SMS as a recovery path.

What a SIM swap actually reaches

Anything where the phone number can reset a password or satisfy a second factor. That typically means your email, which then unlocks almost everything else, including centralised exchange accounts.

It does not reach a self-custodied wallet. A private key is not protected by a phone number, which is one of the genuine advantages of self-custody.

Why SMS keeps being accepted

It has near-universal reach and no app requirement, so it remains the default recovery mechanism at many providers. The weakness is not the message — it is that the number can be reassigned by a human decision at a call centre.

Removing SMS where possible, and adding a carrier-level port-out PIN where it is not, closes most of the gap.

Factors that are meaningfully stronger

A hardware security key is the strongest widely available option and resists phishing by design, because it verifies the domain. An authenticator application is a large improvement over SMS. Both should have recovery codes stored offline.

Email-based recovery is only as strong as the email account, so that account deserves the strongest factor you have.

Reducing the blast radius

Use a dedicated email address for financial accounts that is not published anywhere. Remove SMS recovery wherever an alternative exists. Keep self-custodied funds in wallets whose keys have no relationship to any online account.

FBT Swap requires no account, no email and no phone number for the on-chain swap interface, so there is no FBT login for a SIM swap to take over.

At a glance

At a glance

What it is

Reassignment of your phone number to an attacker

Reaches

SMS codes and any account recoverable by phone number

Does not reach

A self-custodied private key

Best factor

A hardware security key; an authenticator app as a minimum

FAQ

Frequently asked questions

Clear answers before you decide.

Can a SIM swap steal my wallet?

Not directly. A private key has no connection to a phone number. The risk is indirect: your email and exchange accounts, and anything where you stored key material online.

Is an authenticator app enough?

It is far better than SMS and still phishable, because you can be tricked into entering a code on a fake site. A hardware key removes that because it checks the domain itself.

Does FBT Swap need my phone number?

No. There is no account, no email and no phone number for the on-chain swap interface. Notifications are optional and device-based.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.