Your phone lost service overnight, and when it came back, your Binance account was empty. A scammer SIM-swapped your phone number, intercepted SMS 2FA, and withdrew your crypto. Binance is the world's largest exchange — a primary target for SIM swap attacks. Binance has the fastest compliance response (3-7 business days) and mandatory KYC on all accounts. We trace the withdrawal addresses, identify the scammer's Binance account, and file emergency freeze requests.
A SIM swap attack (also called SIM hijacking or port-out fraud) is when a scammer convinces your mobile carrier to transfer your phone number to a SIM card they control. Once they have your phone number, they intercept SMS-based 2FA codes and gain access to your Binance account — bypassing SMS verification, changing the password, and withdrawing your crypto. The attack often happens at night, and victims discover it when they wake up to a dead phone and an empty Binance account.
Why Binance is targeted for SIM swap attacks: Binance is the largest crypto exchange — SIM swap attackers know that Binance users often hold significant balances. Binance offers SMS 2FA as an option (though Google Authenticator is recommended). If you had SMS 2FA enabled (instead of GA), the SIM swap attack bypassed it. However, Binance also has withdrawal address whitelisting — if you had this enabled, the scammer had to add a new address (which triggers a 24-hour lockout). We check whether this lockout was active.
The attack sequence: First, the scammer gathers your personal information (name, email, phone number, date of birth) through data breaches, social media, or phishing. Then they contact your mobile carrier (or bribe an insider at the carrier) to port your number to their SIM. Once they have your number, they intercept the Binance SMS 2FA code, log into your account, change the password and 2FA settings, and withdraw your crypto to addresses they control. The entire attack takes 2-6 hours — usually while you sleep.
Regulatory structure: Binance is regulated by FinCEN (MSB), and multiple international regulators. Binance's compliance team processes legal requests through the Binance compliance portal. Response times: 3-7 business days — the fastest among major exchanges. Binance has a dedicated law enforcement portal and published compliance contact.
Freeze capability: Binance can freeze the scammer's receiving account (if the funds were sent to another Binance account) and flag the withdrawal addresses. Requires a police report or court order. Response: 3-7 business days. Binance is the most cooperative major exchange — they have a dedicated team for SIM swap cases.
KYC disclosure: Binance discloses account holder information to law enforcement or through a court order. Binance's KYC includes: government ID, selfie verification, proof of address, and IP address history. The scammer's real identity (if they used Binance to receive funds) is on file.
The withdrawal address whitelist: If you had withdrawal address whitelisting enabled on Binance, the scammer had to add a new withdrawal address — which triggers a 24-hour lockout. During this lockout, the scammer cannot withdraw. We check whether the lockout was active when you discovered the attack. If so, the funds may still be on Binance. If not, we trace the withdrawal addresses immediately.
A client woke up at 7 AM to find their phone had no service since 2 AM. When they restored service, they found 6 unauthorized Binance withdrawals totaling €48,000 in USDT. The scammer had SIM-swapped their phone number at 2 AM, intercepted the Binance SMS 2FA, changed the password, disabled withdrawal whitelist, and drained the account to 3 different external wallets over 4 hours.
Our response: We traced the withdrawal transactions on-chain, identified the destination addresses, and filed freeze requests with the receiving exchanges. We also filed a police report and coordinated with the mobile carrier's fraud department.
Outcome: 62% recovery (€30,000 of €48,000). We traced the 3 withdrawal addresses: 2 were on Binance (the scammer's own Binance accounts — frozen in 4 business days), 1 was on an external Tron wallet (untraced). The scammer's Binance KYC revealed a resident of the UK. €30,000 recovered from the frozen Binance accounts. The €18,000 on the Tron wallet was blacklisted through Tether (the USDT issuer) — frozen on-chain but not yet returned. Criminal proceedings initiated through UK authorities. The mobile carrier (O2) was found liable for the unauthorized port-out.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
How does a SIM swap differ from phishing? In a SIM swap, the attacker takes over your phone number — you don't click any link. In phishing, the attacker tricks you into entering credentials on a fake site. See phishing on Binance →
Warning: After a SIM swap, fake "recovery services" may contact you. Read our recovery scam warning.
The scammer contacts your mobile carrier (or bribes an insider) to port your phone number to their SIM. Once they have your number, they intercept Binance SMS 2FA codes, log in, change the password, disable security features, and withdraw your crypto. The attack usually happens at night — you discover it when you wake up to a dead phone. The entire attack takes 2-6 hours.
SMS 2FA is vulnerable to SIM swap attacks — the scammer intercepts the SMS codes after porting your number. This is why Binance recommends Google Authenticator (or a hardware key) instead of SMS 2FA. Google Authenticator generates codes on your device — the scammer cannot intercept them even with your phone number. If you had SMS 2FA, the SIM swap bypassed it. After recovery, switch to Google Authenticator.
The Binance withdrawal address whitelist requires you to pre-approve withdrawal addresses. If the scammer tries to withdraw to a new address, Binance triggers a 24-hour lockout before the address becomes active. During this lockout, the scammer cannot withdraw. If you had the whitelist enabled, the scammer had to wait 24 hours — giving us time to detect and freeze. If you didn't have it enabled, the scammer could withdraw immediately.
Yes. Mobile carriers have a duty to verify identity before porting a number. If the carrier ported your number without proper verification (or due to insider fraud), they can be held liable for the resulting losses. We coordinate with law enforcement and file civil claims against the carrier. In the EU and UK, carriers are regulated by Ofcom/EU regulations — we leverage these in our claims.
3-7 business days — the fastest among major exchanges. Binance has a dedicated law enforcement portal and compliance team. For SIM swap cases, we file an emergency freeze request — if the funds are still on Binance (e.g., sent to another Binance account), they can be frozen within 3-7 days. If the funds were withdrawn to an external wallet, we trace on-chain and file with the destination exchange.
Switch from SMS 2FA to Google Authenticator or a hardware security key on Binance. Enable the withdrawal address whitelist (24-hour lockout for new addresses). Contact your mobile carrier and request a "port-out PIN" or "number lock" — this requires a PIN to port your number. Use a separate email for your Binance account (not linked to social media). Enable Binance's anti-phishing code. These measures make SIM swap attacks much harder.
Describe what happened. Include your mobile carrier, when you lost service, Binance withdrawal transaction hashes, and total amount lost. We respond within 6 hours.