📈 Get daily crypto insights that make you smarter about your money

Friend.tech SIM Swap Attacks Expose $385,000 in Ethereum Vulnerabilities

The decentralized social platform Friend.tech is facing a wave of SIM swap attacks that have drained approximately $385,000 in Ethereum from user wallets, highlighting critical security gaps in how cryptocurrency holders protect their mobile identities. As Bitcoin trades near $27,983 and Ethereum holds at $1,733, the attacks remind the crypto community that the weakest link in any security chain is often the human element — specifically, the mobile phone number tied to two-factor authentication.

The Exploit Mechanics

SIM swap attacks, also known as SIM jacking, occur when an attacker convinces a mobile carrier to port a victim’s phone number to a new SIM card under the attacker’s control. Once the phone number is hijacked, the attacker can intercept SMS-based two-factor authentication codes, reset passwords, and gain access to cryptocurrency wallets and exchange accounts.

In the Friend.tech attacks, the perpetrators specifically targeted users known to hold significant cryptocurrency balances. The attackers leveraged publicly available information from social media profiles and blockchain analytics to identify high-value targets. By combining social engineering techniques with insider access at mobile carrier stores, they successfully executed port-out requests without the victims’ knowledge.

The attack chain typically follows a predictable pattern: reconnaissance of the target’s online presence, collection of personal information, contact with the mobile carrier through a fraudulent impersonation, and finally, the SIM port execution. Once completed, the attacker has a narrow but critical window to access accounts before the victim notices their phone has lost service.

Affected Systems

The Friend.tech platform, built on Base (Coinbase’s Layer 2 network), relies on phone numbers as a primary authentication mechanism for many of its users. This design choice created a single point of failure that attackers exploited with devastating efficiency. At least a dozen users reported losses ranging from several thousand dollars to over $100,000 in Ethereum.

Beyond Friend.tech, the SIM swap vulnerability extends to any platform that uses SMS-based two-factor authentication. Centralized exchanges like Binance, Coinbase, and Kraken have all seen users fall victim to similar attacks over the past year. The growing interconnectedness of crypto platforms means that a single compromised phone number can cascade into multiple account breaches across different services.

The attacks also exposed weaknesses in mobile carrier verification procedures. Despite years of warnings from cybersecurity experts, many carriers still lack robust authentication for SIM port requests, making social engineering attacks relatively straightforward for determined attackers.

The Mitigation Strategy

Security researchers recommend several immediate actions for crypto users. The most critical step is migrating away from SMS-based two-factor authentication to authenticator apps like Google Authenticator, Authy, or hardware security keys like YubiKey. These methods generate one-time codes locally, making them immune to SIM swap attacks.

Additionally, users should request a SIM port lock or port freeze from their mobile carrier. This adds an extra layer of verification before any port-out request can be processed. Major carriers including AT&T, Verizon, and T-Mobile offer this feature, though it is not enabled by default and must be explicitly requested by the account holder.

For Friend.tech users specifically, the platform has been urged to implement alternative authentication methods that do not rely on phone numbers. Multi-signature wallets and biometric verification are among the proposed solutions that could prevent similar incidents in the future.

Lessons Learned

The Friend.tech SIM swap attacks underscore a fundamental truth in cryptocurrency security: the most sophisticated blockchain cryptography can be rendered useless by a simple phone call to a mobile carrier. As the crypto ecosystem grows, with Bitcoin commanding a market cap exceeding $545 billion and the total market approaching $1.1 trillion, the financial incentives for attackers will only increase.

The incidents also highlight the importance of operational security (OPSEC) for crypto holders. Maintaining a low profile about cryptocurrency holdings, avoiding the linking of phone numbers to high-value accounts, and using dedicated devices for crypto transactions are all practical measures that can significantly reduce attack surface.

User Action Required

If you are a Friend.tech user or hold cryptocurrency in any account protected by SMS-based two-factor authentication, take action immediately. Disable SMS 2FA, enable authenticator app-based verification, request a SIM port lock from your carrier, and consider transferring significant holdings to a hardware wallet. The $385,000 lost in these attacks is a stark reminder that convenience and security rarely coexist in the world of digital assetup>

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making security decisions regarding your cryptocurrency holdings.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Friend.tech SIM Swap Attacks Expose $385,000 in Ethereum Vulnerabilities”

  1. 385k drained and friend.tech still required phone numbers for auth. linking crypto wallets to twitter handles was basically a public leaderboard for attackers

  2. 385K drained and the lesson people actually learned was to not flex their friend.tech bags on twitter. nobody fixed their SIM security

    1. burner_phone_ fr. people were literally posting screenshots of their key holdings then acting surprised when they got sim swapped. opsec was zero

  3. 385k drained from friend.tech users and the platform still relies on phone numbers for auth. sms 2fa is security theater and this proves it

    1. nina_kensington

      simswap_victim friend.tech linking wallets to twitter handles was basically a targeting menu. attackers just scrolled the leaderboard

  4. carrier_leak_ t-mobile gave my friends number to someone in a different state with no ID check. carriers will not fix this until class actions make it expensive

  5. SIM swap attacks are not new but friend.tech made it worse by linking wallets to social profiles. Attackers knew exactly who to target.

    1. linking wallets to twitter handles was the dumbest UX decision of 2023. literally a public targeting list for sim swappers

      1. 0xMirror.eth the SS7 vulnerability has been documented since like 2008 and carriers still use it for 2FA delivery. sim swaps will keep working until something replaces SS7 entirely

        1. ss7_ghost carriers wont replace SS7 because its how they do inter-carrier billing. the protocol that enables sim swaps also enables their revenue. its not a bug its the foundation

        2. ss7_ghost SS7 has been broken since 2008 and every carrier knows it. they wont replace it because it works for them. sim swaps are a feature not a bug from their perspective

      1. yubikey is the answer but platforms need to make it default. sms 2fa should be deprecated entirely for anything holding funds

        1. sec_ops the real issue was friend.tech using SMS for auth on wallets holding thousands. basic opsec was nonexistent

        2. yubikey costs less than a coffee and people still wont buy one. convenience always wins over security until its too late

          1. Tariq B. a yubikey is 50 bucks and the friend.tech team never even offered hardware 2FA integration. platform-level failure not just user opsec

          2. carrier_skeptic_

            yubikey is 50 bucks but friend.tech didnt even offer hardware 2FA. blaming users for not buying their own security keys when the platform controlled the auth flow is wild

    1. same thing happened to my buddy. carrier store didnt even verify ID properly. these companies need to be held liable for negligent SIM swaps

      1. tmobile_refund carriers wont care until class actions hit. the ID verification gap is industry-wide not just one carrier

        1. port_out_survivor

          port_out_ friend.tech keys were literally tied to twitter handles. one sim swap and your entire social graph wallet was drained. $385k was probably low

  6. friend.tech was a hype bubble anyway. the social token model incentivized speculation over actual community. not surprised it attracted predators

  7. linking wallet access to twitter handles was the fundamental design flaw. friend.tech built a public leaderboard of targets and acted surprised when attackers used it

    1. Bence T. building a public leaderboard of wallet balances tied to twitter handles and then acting surprised when people got sim swapped. friend.tech was a security nightmare dressed as socialfi

      1. Branislav M. the leaderboard was the real exploit. friend.tech literally published a hit list with dollar amounts next to each name. $385k was inevitable

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,281.00+0.1%ETH$2,521.58+0.3%SOL$101.91+0.2%BNB$727.77-0.4%XRP$1.37+0.5%ADA$0.2077-0.3%DOGE$0.0850+0.8%DOT$1.01-3.3%AVAX$7.41-0.5%LINK$11.51+0.0%UNI$6.42+5.7%ATOM$1.62-0.9%LTC$53.69-0.4%ARB$0.14070.0%NEAR$2.37+0.4%FIL$0.8097+1.7%SUI$0.7272+0.2%BTC$77,281.00+0.1%ETH$2,521.58+0.3%SOL$101.91+0.2%BNB$727.77-0.4%XRP$1.37+0.5%ADA$0.2077-0.3%DOGE$0.0850+0.8%DOT$1.01-3.3%AVAX$7.41-0.5%LINK$11.51+0.0%UNI$6.42+5.7%ATOM$1.62-0.9%LTC$53.69-0.4%ARB$0.14070.0%NEAR$2.37+0.4%FIL$0.8097+1.7%SUI$0.7272+0.2%
Scroll to Top