Most crypto security advice focuses on your recovery phrase, since that is the one secret that directly controls a self-custody wallet. But a lot of accounts around your crypto activity, your email, your exchange account, sometimes even your wallet app's cloud backup, are still protected by nothing more than your phone number. SIM swap attacks target exactly that weak point, and understanding what they can and cannot reach helps you close the actual gap instead of the wrong one.
What a SIM swap actually is
A SIM swap happens when an attacker convinces your mobile carrier to move your phone number onto a SIM card they control. They do not need your phone, and they usually do not need to hack anything technical. Instead they rely on social engineering: calling support, presenting some stolen personal details (often bought from a data breach or gathered from social media), and asking for the number to be ported or a replacement SIM to be issued.
Once the swap goes through, your phone stops receiving calls and texts, and the attacker's device starts receiving them instead. From that point on, they can receive any SMS based verification code sent to your number, including password resets and two-factor authentication codes for accounts that rely on text messages.
The first sign is often mundane: your phone suddenly shows no signal, or you get a message from your carrier confirming a SIM change you did not request. If that happens along with unexpected login or password reset emails, treat it as an active attack, not a coincidence.
Why your self-custody wallet is not the main target
Here is the part that matters most for a Base wallet user: a SIM swap on its own cannot move funds out of a properly set up self-custody wallet. Your wallet is controlled entirely by your recovery phrase, which lives on your device or hardware wallet, not by your phone number. An attacker who controls your SIM has no way to sign a transaction or reconstruct your phrase just from receiving your text messages.
That is a meaningful difference from a custodial exchange account, where a phone number is often one of the few things standing between an attacker and your funds. If your exchange account uses SMS for login or withdrawal confirmation, a successful SIM swap can be enough on its own to drain it, because the exchange controls the private keys and the phone number is treated as proof it is really you.
So a SIM swap is dangerous mainly in two ways: it targets exchange and custodial accounts directly, and it can be a stepping stone toward compromising accounts that then get used to trick you further, such as email or a cloud backup service.
Where the real risk hides: email and cloud backups
Your email account is usually the master key to everything else. If an attacker gets into your email through a SIM swap enabled password reset, they can then reset passwords on your exchange account, your domain registrar, or any service that emails a recovery link. From there, they work outward toward anything with financial value, crypto included.
Cloud backups are the other place this gets serious. Some mobile wallet apps offer an option to back up an encrypted copy of your recovery phrase to a cloud account like iCloud or Google Drive, protected by your account password. If that account's recovery also runs through SMS, and your phone number gets swapped, an attacker chasing the backup file has a real path to your phrase, not just to your email inbox. If you use this kind of backup feature, make sure the underlying cloud account has strong, non SMS protection.
Reducing your exposure
A few concrete changes cut most of the real risk here:
Move off SMS for two-factor authentication wherever you can. An authenticator app, such as one that generates time-based codes locally on your device, is not tied to your phone number and is not affected by a SIM swap at all. A hardware security key is stronger still. Reserve SMS codes for services that genuinely do not offer anything better.
Ask your carrier about a port-out PIN or account lock. Most major carriers let you set a separate PIN or passcode that must be provided before any SIM change or number port, on top of normal account login. This is one of the few defenses that directly targets the SIM swap itself rather than what it enables.
Keep your phone number out of your public crypto footprint. Attackers who target SIM swaps usually start with some form of reconnaissance, figuring out who has meaningful crypto holdings and finding a phone number to attach to that person. Avoid posting your number publicly, and be cautious about which apps and forms you give it to, especially ones connected to your crypto or financial identity.
Separate your financial email from your everyday one. A dedicated email address used only for exchange accounts and financial services, with strong non SMS two-factor authentication, is harder for an attacker to reach through unrelated data breaches or social engineering aimed at a more public inbox.
Keep exchange balances you are not actively trading in cold storage. If your exchange account holds less at any given time, a successful account takeover through a SIM swap has less to take. See hot wallets and cold wallets, explained for how to think about that split.
If you think it has already happened
Contact your mobile carrier immediately to reverse the SIM change and lock the account. Then work outward: change your email password from a device you trust, check your email account's recovery settings for anything unfamiliar, and review login activity on any account tied to that email or phone number, especially exchanges. If you have any reason to think your recovery phrase itself was exposed, for example through a cloud backup, treat the wallet as compromised and follow the steps in your wallet was compromised, here is what to do right now.
SIM swapping is a reminder that crypto security is not only about the wallet itself. The accounts and services around it, especially anything still leaning on a phone number as proof of identity, deserve the same level of attention.