Your phone lost service overnight, and your Bybit account was drained. A scammer SIM-swapped your phone number, intercepted SMS 2FA, and withdrew your crypto from Bybit. Bybit is Dubai-headquartered (VARA-regulated) with mandatory KYC since 2023. Bybit's derivatives focus creates an additional risk: the scammer may trade your funds on perpetual futures before withdrawing — reducing the recoverable amount. We trace the withdrawals and file with Bybit's Dubai compliance team.
A SIM swap attack (also called SIM hijacking or port-out fraud) is when a scammer convinces your mobile carrier to transfer your phone number to a SIM card they control. Once they have your phone number, they intercept SMS-based 2FA codes and gain access to your Bybit account — bypassing SMS verification, changing the password, and withdrawing your crypto. The attack often happens at night, and victims discover it when they wake up to a dead phone and an empty Bybit account.
Why Bybit is targeted for SIM swap attacks: Bybit is a major derivatives exchange — users often hold significant balances for margin trading. Bybit offers SMS 2FA (though Google Authenticator is recommended). Bybit's derivatives markets create a unique SIM swap risk: the scammer can trade your funds on perpetual futures, generating trading losses before withdrawing. The remaining balance is what we can recover.
The attack sequence: First, the scammer gathers your personal information through data breaches, social media, or phishing. Then they contact your mobile carrier (or bribe an insider) to port your number to their SIM. Once they have your number, they intercept the Bybit SMS 2FA code, log into your account, change the password and 2FA settings, and withdraw your crypto to addresses they control. The entire attack takes 2-6 hours — usually while you sleep.
Regulatory structure: Bybit's compliance team operates from Dubai under VARA regulation. Response times: 5-14 business days. Bybit is slower than Binance (3-7 days) and Coinbase (3-10 days) but faster than MEXC (10-30 days). Bybit processes legal requests through their compliance email.
Freeze capability: Bybit can freeze the scammer's receiving account (if funds went to another Bybit account). Requires a police report or court order. Response: 5-14 business days. Bybit cooperates with UAE law enforcement and international requests through MLAT.
KYC disclosure: Bybit discloses account holder information to law enforcement or through a court order. Bybit's KYC (mandatory since 2023) includes: government ID, selfie verification, and proof of address. The scammer's real identity is on file if they used Bybit to receive funds.
The derivatives trading risk: If the scammer traded your funds on Bybit's perpetual futures before withdrawing, trading losses are generally unrecoverable — the funds went to market counterparties. However, any remaining margin, realized profits, or unrealized positions at the time of the freeze are recoverable. We check Bybit's internal trading records to determine the actual remaining balance.
A client woke up at 6 AM to find their phone had no service since 1 AM. When they restored service, they found their Bybit account had been accessed — the scammer had SIM-swapped their Etisalat number, intercepted Bybit SMS 2FA, and logged in. The scammer found €55,000 in the account and traded €30,000 on ETH perpetual futures (losing €12,000 to the market), then withdrew the remaining €43,000 (original balance minus trading losses) to 2 external wallets.
Our response: We traced the withdrawal transactions on-chain, identified the destination addresses, and filed freeze requests with the receiving exchanges. We also filed a police report and coordinated with the mobile carrier's fraud department.
Outcome: 42% recovery (€23,000 of €55,000). We traced the 2 withdrawal addresses: 1 was on another Bybit account (frozen in 7 business days — €23,000 in USDT), 1 was on an external Tron wallet (untraced). The €12,000 derivatives trading loss was unrecoverable (went to market counterparties). The scammer's Bybit KYC revealed a resident of the UAE. Recovery: €23,000 from the frozen Bybit account. The €20,000 on the external wallet was not recovered. The mobile carrier (Etisalat) was found liable for the unauthorized port-out.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
How does a SIM swap differ from phishing? In a SIM swap, the attacker takes over your phone number — you don't click any link. In phishing, the attacker tricks you into entering credentials on a fake site. See phishing on Bybit →
Warning: After a SIM swap, fake "recovery services" may contact you. Read our recovery scam warning.
Three differences: (1) Bybit is slower (5-14 days vs Binance's 3-7 days) — the scammer has more time to withdraw. (2) Bybit's derivatives focus means the scammer may trade your funds on perpetual futures, reducing the recoverable balance. (3) Bybit is VARA-regulated (Dubai) — we can file a VARA complaint for regulatory pressure. Recovery rates are 40-60%, lower than Binance.
No — trading losses on Bybit derivatives are generally unrecoverable. The funds went to market counterparties (other traders on the opposite side of the position). However, any remaining margin, realized profits, or unrealized positions at the time of the freeze are recoverable. We check Bybit's internal trading records to determine the actual remaining balance — not the original account balance.
When the scammer gains access to your Bybit account, they may trade your funds on perpetual futures before withdrawing. If they make profitable trades, the balance may increase (and we can recover more). If they make losing trades, the balance decreases (and we recover less). Scammers often use derivatives to "gamble" with stolen funds — if they lose, they withdraw the remainder. We trace the actual remaining balance, not the original.
Yes. Bybit DMCC (Dubai) is VARA-regulated. If Bybit's compliance team is slow, we file a parallel complaint with VARA. This creates regulatory pressure on Bybit to respond. The VARA complaint is a regulatory lever unique to Bybit cases — similar to CFPB for Coinbase. It typically accelerates response by 3-5 business days.
5-14 business days. Bybit's Dubai compliance team processes legal requests. Slower than Binance (3-7 days) and Coinbase (3-10 days). For SIM swap cases, early filing is critical — especially if the scammer is trading on derivatives (which reduces the balance over time). We file through Bybit's compliance email and escalate through VARA if needed.
Switch from SMS 2FA to Google Authenticator. Enable withdrawal address whitelisting (if Bybit offers it). Contact your mobile carrier and request a port-out PIN. Use a separate email for your Bybit account. Avoid keeping large balances on Bybit derivatives — move excess funds to a hardware wallet. These measures make SIM swap attacks much harder — even if the scammer gets your phone number, they cannot access your funds without the Authenticator code.
Describe what happened. Include your mobile carrier, when you lost service, Bybit withdrawal transaction hashes, and total amount lost. We respond within 6 hours.