Zhenku
Guard · The Watchful Eye 2FA

Why SMS Codes Are the Weakest 2FA: What a SIM Swap Really Is

Zhenku Editorial · Cheng Mo Updated 2026-07 About 11 min
Cover for SMS 2FA and SIM swaps

"But I had SMS codes turned on — how did I still get hacked?" That's the line you hear most in groups of people who've been hit. The trouble is the first half of it: an SMS code looks like a lock, but it's the easiest of these second factors to get around. Whether it's weak isn't down to you — it's down to the phone network that carries the code to your handset. This piece makes clear where it's weak, how a SIM swap steals your number, and the one thing you most need to do: don't let SMS be your only second key.

First, what 2FA actually protects

Two-factor auth (2FA) works on the idea that "knowing the password isn't enough — you also have to prove you're holding a second thing". That second thing might be an SMS code texted to your phone, a rotating code that changes every 30 seconds in an authenticator app, or a security key plugged into your computer. What it protects is the scenario where your password has already leaked: even if someone credential-stuffs or phishes your password, without this second key they still can't log in.

The crux is this: the strength of the whole 2FA setup is decided by how secure that "second key" itself is. And that's exactly SMS's problem — its key is delivered to your phone number, and a phone number is easier to take from you than you'd think.

What a SIM swap really is

A SIM swap (also called a port-out or SIM re-issue attack) comes down to one line: someone moves your phone number onto a SIM of their own. The whole thing needs no hacking of your phone — it attacks the carrier's human process. The usual script goes like this:

What makes it frightening: your phone and your password may not have been touched at all — they've simply plugged the "pipe" that delivers your codes into their own end. By the time you notice your phone has inexplicably lost signal, the account is often already gone.

Watch for this signYour phone suddenly loses signal, or shows "No SIM" or "Not registered on network", while other people's phones on the same carrier nearby are fine — especially when you haven't touched the SIM or missed a bill. That's the classic early sign of a SIM swap. Don't write it off as a glitch; contact your carrier by another means to check right away.

Where SMS is weak: not just SIM swaps

SIM swaps are the most famous, but the fragility of the SMS channel doesn't stop there:

Compare it with the other two and the gap is obvious:

So the takeaway is blunt: SMS isn't unusable, it just shouldn't be used alone. It's fine as a fallback, wrong as your only second key. To compare all three side by side, go straight to the 2FA method comparison table — the SIM-swap-resistance column sorts them out at a glance.

How to demote SMS to a backup

There's no need to agonise over "should I turn SMS off." The right move is to bind a stronger primary verification to the account and push SMS down into the backup slot:

  1. Bind an authenticator app first. In Binance's security settings, enable the authenticator (such as Google Authenticator), scan the code to bind it as prompted, and set it as your primary 2FA method. For the full steps and how to move it to a new phone, see the complete 2FA guide.
  2. Write down the backup recovery codes. When you bind the authenticator you'll be given a backup key / a set of recovery codes — copy them out offline and keep them safe. With those in hand, changing or losing your phone won't lock you out, so you won't have to fall back on SMS to bail you out.
  3. Add a security key too if you can. For anyone holding a fair amount, a security key / Passkey is worth setting up — it takes care of phishing resistance in one stroke.
  4. Keep SMS as a backup. Once your primary verification is standing, SMS goes from being your "only channel" to a "last-resort fallback," and its fragility is no longer a fatal single point of failure.
While you're at itWhen you upgrade your 2FA, turn on the withdrawal address whitelist as well. If SMS really does get hijacked and the attacker logs in, the whitelist means they can't move your coins out — it's the safety net that saves SIM-swap victims. See how to set up a withdrawal whitelist.

A few things you can do carrier-side

Since a SIM swap targets the carrier, that link in the chain has a few points you can harden ahead of time:

None of this is airtight (a human process can always, in the end, be broken), but every extra layer raises the difficulty of being swapped. The real reassurance still comes back to that one line from earlier: don't stake your account's primary verification on SMS.

In the UK and Australia, the rules are on your side — if you use them

Most advice about SIM swaps is written for the US market and stops at "ring your carrier and ask for a PIN." In two of the largest English-speaking markets there is something more concrete to ask for, and a regulator behind it.

United Kingdom. Moving a number to another network runs on a PAC — a Porting Authorisation Code. Ofcom requires your provider to issue one within two hours of a phone request covering fewer than 25 numbers, which is convenient for you and equally convenient for anyone impersonating you. So the question worth asking your provider is not "can I have a PIN" but two sharper ones: how do you verify me before you hand out a PAC, and can you put a port-out PIN on this account. Providers differ. Some send a one-time password to the SIM itself and make you read it back — which an attacker without your phone cannot do. EE offers a secure state in which automated PAC requests fail outright and a SIM swap has to go through a store with ID, or a replacement posted to the registered account holder's address. That is a materially higher bar than a call centre conversation, and you have to ask for it.

Australia. Since 30 June 2022, telco rules require stronger identity checks on "high-risk" transactions — replacement SIMs and changes to account details — using multiple forms of authentication, the way banking already does. These are enforceable, not advisory: Exetel was fined $695,000 for porting 73 numbers to cybercriminals without checking ID, the largest penalty issued under the porting rules. What that means for you is that if a carrier moves your number without properly identifying the person asking, they have broken a rule, and that fact belongs in your complaint.

Ask the specific question. "Please secure my account" gets you a note on a file. "What authentication do you require before issuing a PAC or a replacement SIM, and can you add a port-out PIN?" gets you an answer you can act on — including the answer "we don't", which tells you something about where your number lives.

Elsewhere in the English-speaking world the mechanism will have a different name, but the question is the same. Ask what stands between a stranger on the phone and your number.

These signals mean drop everything

A SIM swap often leaves a window of a few seconds to a few minutes — reacting fast can save you:

The moment you suspect it, act: use another phone or network to contact your carrier, report the SIM lost, and take back control of the number; at the same time, log in as fast as you can to change your password, freeze the account, and kick devices off. For the full first-ten-minutes order of operations, see what to do in the first ten minutes after an account is stolen, and when you're panicking you can follow the hacked-account response decision tree step by step.

In one lineThe fragility of SMS 2FA isn't your fault — it's baked into the channel. What you can do, and most should do, is give your account a key that doesn't travel over the phone network. This piece is about account security only and isn't investment advice of any kind.

FAQ

What is a SIM swap?

A SIM swap, also called a SIM re-issue attack, is when an attacker social-engineers your carrier's support staff into re-issuing or transferring your phone number onto a SIM they control. Once it works, your number goes dead and every SMS code sent to it lands with them. It doesn't need to hack your phone — it attacks the carrier's human process.

Why is an SMS code the weakest 2FA?

Because the SMS channel itself can be bypassed: your number can be ported away in a SIM swap, codes can be intercepted by phone malware, and carrier support can be social-engineered. Authenticator apps and security keys keep the "second key" local on your device, off the phone network that can be hijacked, so they're far safer. SMS is usable, just not as your only verification method.

So should I still turn SMS 2FA on?

You can keep it, but demote it to a backup rather than your only method. Set up an authenticator app or security key as your primary verification first, and leave SMS as a fallback for recovery. Adding a PIN / service password on the carrier side, and reacting fast to any unexpected SIM-change or loss-of-service text, further lowers the odds of being swapped.

Can an authenticator app be stolen too?

The authenticator's rotating code is generated locally on your phone and never goes through SMS, so a SIM swap can't steal it. Its main risk is the phone itself being lost or infected, so do two things: copy the backup recovery codes offline when you bind it, and keep the phone locked and clean. For how to move it when you change or lose a phone, see the notes on "migrating 2FA to a new phone."

Will these settings screens change?

Yes. Binance and carrier interfaces and feature names get adjusted now and then. This piece covers the principles and the trade-offs; for the exact location of any setting, go by what Binance's official pages and your carrier currently show, and search the relevant keyword if you can't find it.

CM
Cheng Mo · Zhenku Editorial

"Cheng Mo" is a pen-name and doesn't represent any licensed expert. What we do is explain the principles of account security and Binance's public settings in an order an ordinary user can follow, and walk through the steps ourselves to check them where we can. We don't give investment advice; if you spot something we got wrong, please tell us via corrections.

Sources