Why SMS Codes Are the Weakest 2FA: What a SIM Swap Really Is
"But I had SMS codes turned on — how did I still get hacked?" That's the line you hear most in groups of people who've been hit. The trouble is the first half of it: an SMS code looks like a lock, but it's the easiest of these second factors to get around. Whether it's weak isn't down to you — it's down to the phone network that carries the code to your handset. This piece makes clear where it's weak, how a SIM swap steals your number, and the one thing you most need to do: don't let SMS be your only second key.
First, what 2FA actually protects
Two-factor auth (2FA) works on the idea that "knowing the password isn't enough — you also have to prove you're holding a second thing". That second thing might be an SMS code texted to your phone, a rotating code that changes every 30 seconds in an authenticator app, or a security key plugged into your computer. What it protects is the scenario where your password has already leaked: even if someone credential-stuffs or phishes your password, without this second key they still can't log in.
The crux is this: the strength of the whole 2FA setup is decided by how secure that "second key" itself is. And that's exactly SMS's problem — its key is delivered to your phone number, and a phone number is easier to take from you than you'd think.
What a SIM swap really is
A SIM swap (also called a port-out or SIM re-issue attack) comes down to one line: someone moves your phone number onto a SIM of their own. The whole thing needs no hacking of your phone — it attacks the carrier's human process. The usual script goes like this:
- Scrape your details first. Through leaked data, social media and phishing, they piece together your name, phone number and identity info — enough to impersonate you.
- Contact the carrier as you. They call support or walk into a store claiming the phone was lost or the SIM broke, and ask for a replacement SIM or to port the number to a new card. A slick social-engineering pitch plus the details they've gathered is sometimes enough to pass the checks.
- Your number dies, their card comes alive. The moment the swap goes through, your SIM suddenly loses signal and shows no service, while every text and call to that number now goes to their phone.
- The harvest begins. They take your number around the web triggering "reset password by SMS code", and the codes pour in to them — exchange, email, bank, taken over one by one.
What makes it frightening: your phone and your password may not have been touched at all — they've simply plugged the "pipe" that delivers your codes into their own end. By the time you notice your phone has inexplicably lost signal, the account is often already gone.
Where SMS is weak: not just SIM swaps
SIM swaps are the most famous, but the fragility of the SMS channel doesn't stop there:
- Codes can be intercepted by phone malware. If your phone has malicious software installed, or something has been granted permission to read texts, the code can be quietly read and forwarded right under your nose.
- Carrier support staff are people who can be social-engineered. No matter how strict the process, it can't fully withstand a slick con paired with gathered personal details — the SIM-replacement check is inherently open to being broken.
- The phone network itself has a history of flaws. The underlying signalling network that carries SMS has been shown over the years to have problems that can be abused to intercept texts, and an ordinary user can do nothing about it.
- Numbers change hands for all sorts of reasons. Deactivation and recycling, changing numbers without unbinding, second-hand numbers — your old number can end up with a stranger, still tied to a pile of accounts you never unbound.
Compare it with the other two and the gap is obvious:
- Authenticator app (like Google Authenticator or Authy): the rotating code is computed locally on your phone and never goes through the phone network, so a SIM swap that steals your number can't steal it.
- Security key / Passkey: built on a physical device or device binding, it not only skips SMS but blocks phishing at the mechanism level — it never hands over anything like a "code" that can be relayed. This is the strongest grade there is; for how to set one up, see security keys and Passkeys.
So the takeaway is blunt: SMS isn't unusable, it just shouldn't be used alone. It's fine as a fallback, wrong as your only second key. To compare all three side by side, go straight to the 2FA method comparison table — the SIM-swap-resistance column sorts them out at a glance.
How to demote SMS to a backup
There's no need to agonise over "should I turn SMS off." The right move is to bind a stronger primary verification to the account and push SMS down into the backup slot:
- Bind an authenticator app first. In Binance's security settings, enable the authenticator (such as Google Authenticator), scan the code to bind it as prompted, and set it as your primary 2FA method. For the full steps and how to move it to a new phone, see the complete 2FA guide.
- Write down the backup recovery codes. When you bind the authenticator you'll be given a backup key / a set of recovery codes — copy them out offline and keep them safe. With those in hand, changing or losing your phone won't lock you out, so you won't have to fall back on SMS to bail you out.
- Add a security key too if you can. For anyone holding a fair amount, a security key / Passkey is worth setting up — it takes care of phishing resistance in one stroke.
- Keep SMS as a backup. Once your primary verification is standing, SMS goes from being your "only channel" to a "last-resort fallback," and its fragility is no longer a fatal single point of failure.
A few things you can do carrier-side
Since a SIM swap targets the carrier, that link in the chain has a few points you can harden ahead of time:
- Add a PIN / service password to your number. Many carriers let you set a separate service password or SIM PIN that has to be verified before a sensitive action like a SIM re-issue or transfer goes through. Setting one raises the bar for a social-engineered swap straight away. Ask your carrier for the exact name and how to set it up.
- Don't use your phone number as the catch-all recovery method everywhere. For accounts that support an authenticator or security key, don't rely on the number alone — especially your email. If your email can be recovered by phone number, then taking your number hands the attacker your email too.
- Cut down how publicly your number is exposed. Leave your phone number off social platforms and public profiles where you can, so it's harder for an attacker to assemble your details.
- Remember to unbind when you change or drop a number. Move the accounts tied to an old number over to a new one or to an authenticator, one by one — don't leave an "ex-number" out there still holding a string of accounts.
None of this is airtight (a human process can always, in the end, be broken), but every extra layer raises the difficulty of being swapped. The real reassurance still comes back to that one line from earlier: don't stake your account's primary verification on SMS.
In the UK and Australia, the rules are on your side — if you use them
Most advice about SIM swaps is written for the US market and stops at "ring your carrier and ask for a PIN." In two of the largest English-speaking markets there is something more concrete to ask for, and a regulator behind it.
United Kingdom. Moving a number to another network runs on a PAC — a Porting Authorisation Code. Ofcom requires your provider to issue one within two hours of a phone request covering fewer than 25 numbers, which is convenient for you and equally convenient for anyone impersonating you. So the question worth asking your provider is not "can I have a PIN" but two sharper ones: how do you verify me before you hand out a PAC, and can you put a port-out PIN on this account. Providers differ. Some send a one-time password to the SIM itself and make you read it back — which an attacker without your phone cannot do. EE offers a secure state in which automated PAC requests fail outright and a SIM swap has to go through a store with ID, or a replacement posted to the registered account holder's address. That is a materially higher bar than a call centre conversation, and you have to ask for it.
Australia. Since 30 June 2022, telco rules require stronger identity checks on "high-risk" transactions — replacement SIMs and changes to account details — using multiple forms of authentication, the way banking already does. These are enforceable, not advisory: Exetel was fined $695,000 for porting 73 numbers to cybercriminals without checking ID, the largest penalty issued under the porting rules. What that means for you is that if a carrier moves your number without properly identifying the person asking, they have broken a rule, and that fact belongs in your complaint.
Elsewhere in the English-speaking world the mechanism will have a different name, but the question is the same. Ask what stands between a stranger on the phone and your number.
These signals mean drop everything
A SIM swap often leaves a window of a few seconds to a few minutes — reacting fast can save you:
- Your phone loses signal with no warning, or shows "No SIM" / "Not registered on network," while you haven't touched the card or missed a bill.
- You get a carrier notification you never asked for — a "SIM replacement complete," "number transferred," or "SIM changed" message.
- Your email or an exchange suddenly floods you with "verification code," "password reset," or "login from a new location" alerts that you didn't trigger.
The moment you suspect it, act: use another phone or network to contact your carrier, report the SIM lost, and take back control of the number; at the same time, log in as fast as you can to change your password, freeze the account, and kick devices off. For the full first-ten-minutes order of operations, see what to do in the first ten minutes after an account is stolen, and when you're panicking you can follow the hacked-account response decision tree step by step.
FAQ
What is a SIM swap?
A SIM swap, also called a SIM re-issue attack, is when an attacker social-engineers your carrier's support staff into re-issuing or transferring your phone number onto a SIM they control. Once it works, your number goes dead and every SMS code sent to it lands with them. It doesn't need to hack your phone — it attacks the carrier's human process.
Why is an SMS code the weakest 2FA?
Because the SMS channel itself can be bypassed: your number can be ported away in a SIM swap, codes can be intercepted by phone malware, and carrier support can be social-engineered. Authenticator apps and security keys keep the "second key" local on your device, off the phone network that can be hijacked, so they're far safer. SMS is usable, just not as your only verification method.
So should I still turn SMS 2FA on?
You can keep it, but demote it to a backup rather than your only method. Set up an authenticator app or security key as your primary verification first, and leave SMS as a fallback for recovery. Adding a PIN / service password on the carrier side, and reacting fast to any unexpected SIM-change or loss-of-service text, further lowers the odds of being swapped.
Can an authenticator app be stolen too?
The authenticator's rotating code is generated locally on your phone and never goes through SMS, so a SIM swap can't steal it. Its main risk is the phone itself being lost or infected, so do two things: copy the backup recovery codes offline when you bind it, and keep the phone locked and clean. For how to move it when you change or lose a phone, see the notes on "migrating 2FA to a new phone."
Will these settings screens change?
Yes. Binance and carrier interfaces and feature names get adjusted now and then. This piece covers the principles and the trade-offs; for the exact location of any setting, go by what Binance's official pages and your carrier currently show, and search the relevant keyword if you can't find it.
Sources
- Binance Help Center · entries on two-factor verification and account security (binance.com/en/support, go by the current official page)
- Binance security page · security feature descriptions (binance.com/en/security)