Your phone lost service, and your Kraken account was drained. A scammer SIM-swapped your number, intercepted SMS 2FA, and withdrew your crypto. Kraken is US-regulated (FinCEN MSB, Wyoming SPD) with a unique security feature: the Global Settings Lock (GSL). If you had GSL enabled, the scammer could not change your withdrawal addresses — limiting the damage. We trace the withdrawals and leverage the GSL for recovery.
A SIM swap attack (also called SIM hijacking or port-out fraud) is when a scammer convinces your mobile carrier to transfer your phone number to a SIM card they control. Once they have your phone number, they intercept SMS-based 2FA codes and gain access to your Kraken account — bypassing SMS verification, changing the password, and withdrawing your crypto. The attack often happens at night, and victims discover it when they wake up to a dead phone and an empty Kraken account.
Why Kraken is targeted for SIM swap attacks: Kraken is a major US exchange with significant user balances. Kraken offers SMS 2FA (though Google Authenticator and YubiKey are recommended). However, Kraken has a unique feature: the Global Settings Lock (GSL). If you enabled GSL, the scammer could not change withdrawal addresses, disable 2FA, or change account settings during the lock period. This is a critical defense — if GSL was active, the scammer could only withdraw to pre-approved addresses.
The attack sequence: First, the scammer gathers your personal information (name, email, phone number, date of birth) through data breaches, social media, or phishing. Then they contact your mobile carrier (or bribe an insider at the carrier) to port your number to their SIM. Once they have your number, they intercept the Kraken SMS 2FA code, log into your account, change the password and 2FA settings, and withdraw your crypto to addresses they control. The entire attack takes 2-6 hours — usually while you sleep.
Regulatory structure: Kraken is regulated by FinCEN (MSB) and holds a Wyoming SPD charter. Kraken's compliance team handles legal requests through their legal/compliance email. Response times: 5-12 business days. Moderate speed — slower than Binance (3-7 days) and Coinbase (3-10 days).
Freeze capability: Kraken can freeze the scammer's receiving account (if funds went to another Kraken account). Requires a police report or court order. Response: 5-12 business days. Kraken cooperates with US law enforcement (FBI, Secret Service).
KYC disclosure: Kraken discloses account holder information to law enforcement or through a subpoena/court order. Kraken's KYC includes: government ID, selfie verification, proof of address, and SSN (for US users). Kraken also records SEPA/wire withdrawal destinations — if the scammer withdrew fiat via SEPA, we can trace the European bank account.
The GSL advantage: If you had GSL enabled on Kraken, the scammer could not change withdrawal addresses during the lock period. This means the scammer could only withdraw to addresses you had already whitelisted — which are likely your own addresses (not the scammer's). If the scammer tried to add a new withdrawal address, Kraken would have blocked it during the GSL period. We check whether GSL was active when the attack occurred.
A client discovered at 8 AM that their phone had no service since 3 AM. When they restored service, they found 2 unauthorized Kraken withdrawals totaling €35,000 in USDT. However, the client had GSL enabled (7-day lock). The scammer had SIM-swapped their Vodafone number, intercepted Kraken SMS 2FA, and logged in — but could not add new withdrawal addresses due to the GSL. The scammer could only withdraw to the client's own pre-approved address.
Our response: We traced the withdrawal transactions on-chain, identified the destination addresses, and filed freeze requests with the receiving exchanges. We also filed a police report and coordinated with the mobile carrier's fraud department.
Outcome: 100% recovery (€35,000 of €35,000). The GSL had prevented the scammer from adding new withdrawal addresses — the funds were withdrawn to the client's own pre-approved address (which the scammer could not access). We filed a freeze request with Kraken to flag the account and prevent future attacks. The mobile carrier (Vodafone) was found liable for the unauthorized port-out. This is an unusual case — the GSL saved the client from loss. In cases where GSL is not active, recovery rates are 45-65%.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
How does a SIM swap differ from phishing? In a SIM swap, the attacker takes over your phone number — you don't click any link. In phishing, the attacker tricks you into entering credentials on a fake site. See phishing on Kraken →
Warning: After a SIM swap, fake "recovery services" may contact you. Read our recovery scam warning.
The GSL is a Kraken security feature that locks account settings (withdrawal addresses, 2FA, email) for a chosen period (1-365 days). If you had GSL enabled when the SIM swap attack occurred, the scammer could not add new withdrawal addresses or change your 2FA settings. This means the scammer could only withdraw to addresses you had already pre-approved — which are your own addresses, not the scammer's. The GSL is the strongest defense against SIM swap attacks on Kraken.
Yes. Without GSL, the scammer could add new withdrawal addresses and withdraw to their own wallets. We trace the withdrawal addresses on-chain, identify the destination exchanges, and file freeze requests. Recovery rates without GSL are 45-65% — lower than with GSL but still significant. We also obtain the mobile carrier's port-out records and identify the SIM swap perpetrator.
Three differences: (1) Kraken has the GSL — if enabled, it prevents the scammer from changing withdrawal addresses. Binance has a similar feature (withdrawal whitelist) but it's not a time-lock. (2) Kraken is slower (5-12 days vs Binance's 3-7 days). (3) Kraken is strong in EUR markets — if the scammer withdrew via SEPA, we can trace the European bank account. Recovery rates are 45-65% (or 100% if GSL was active).
The Master Key is a Kraken feature that designates a trusted contact who can approve account changes. If the scammer tries to change your withdrawal addresses or disable 2FA, Kraken requires approval from the Master Key contact. If you had a Master Key set up (with a trusted family member or friend), the scammer could not change your settings without their approval. This is an additional layer of defense — but only if you set it up before the attack.
5-12 business days. Kraken's compliance team processes legal requests with a police report. Slower than Binance (3-7 days) and Coinbase (3-10 days). For SIM swap cases, early filing is important — but if GSL was active, the scammer could not withdraw to new addresses, giving us more time. If GSL was not active, speed is critical.
Enable the GSL (Global Settings Lock) for 7-365 days — this prevents withdrawal address changes during the lock. Set up a Master Key (trusted contact for account changes). Switch from SMS 2FA to Google Authenticator or YubiKey. Contact your mobile carrier and request a port-out PIN. Use a separate email for your Kraken account. These measures make SIM swap attacks nearly impossible — even if the scammer gets your phone number.
Describe what happened. Include your mobile carrier, when you lost service, Kraken withdrawal transaction hashes, and total amount lost. We respond within 6 hours.