The decentralized social platform Friend.tech is facing a wave of SIM swap attacks that have drained approximately $385,000 in Ethereum from user wallets, highlighting critical security gaps in how cryptocurrency holders protect their mobile identities. As Bitcoin trades near $27,983 and Ethereum holds at $1,733, the attacks remind the crypto community that the weakest link in any security chain is often the human element — specifically, the mobile phone number tied to two-factor authentication.
The Exploit Mechanics
SIM swap attacks, also known as SIM jacking, occur when an attacker convinces a mobile carrier to port a victim’s phone number to a new SIM card under the attacker’s control. Once the phone number is hijacked, the attacker can intercept SMS-based two-factor authentication codes, reset passwords, and gain access to cryptocurrency wallets and exchange accounts.
In the Friend.tech attacks, the perpetrators specifically targeted users known to hold significant cryptocurrency balances. The attackers leveraged publicly available information from social media profiles and blockchain analytics to identify high-value targets. By combining social engineering techniques with insider access at mobile carrier stores, they successfully executed port-out requests without the victims’ knowledge.
The attack chain typically follows a predictable pattern: reconnaissance of the target’s online presence, collection of personal information, contact with the mobile carrier through a fraudulent impersonation, and finally, the SIM port execution. Once completed, the attacker has a narrow but critical window to access accounts before the victim notices their phone has lost service.
Affected Systems
The Friend.tech platform, built on Base (Coinbase’s Layer 2 network), relies on phone numbers as a primary authentication mechanism for many of its users. This design choice created a single point of failure that attackers exploited with devastating efficiency. At least a dozen users reported losses ranging from several thousand dollars to over $100,000 in Ethereum.
Beyond Friend.tech, the SIM swap vulnerability extends to any platform that uses SMS-based two-factor authentication. Centralized exchanges like Binance, Coinbase, and Kraken have all seen users fall victim to similar attacks over the past year. The growing interconnectedness of crypto platforms means that a single compromised phone number can cascade into multiple account breaches across different services.
The attacks also exposed weaknesses in mobile carrier verification procedures. Despite years of warnings from cybersecurity experts, many carriers still lack robust authentication for SIM port requests, making social engineering attacks relatively straightforward for determined attackers.
The Mitigation Strategy
Security researchers recommend several immediate actions for crypto users. The most critical step is migrating away from SMS-based two-factor authentication to authenticator apps like Google Authenticator, Authy, or hardware security keys like YubiKey. These methods generate one-time codes locally, making them immune to SIM swap attacks.
Additionally, users should request a SIM port lock or port freeze from their mobile carrier. This adds an extra layer of verification before any port-out request can be processed. Major carriers including AT&T, Verizon, and T-Mobile offer this feature, though it is not enabled by default and must be explicitly requested by the account holder.
For Friend.tech users specifically, the platform has been urged to implement alternative authentication methods that do not rely on phone numbers. Multi-signature wallets and biometric verification are among the proposed solutions that could prevent similar incidents in the future.
Lessons Learned
The Friend.tech SIM swap attacks underscore a fundamental truth in cryptocurrency security: the most sophisticated blockchain cryptography can be rendered useless by a simple phone call to a mobile carrier. As the crypto ecosystem grows, with Bitcoin commanding a market cap exceeding $545 billion and the total market approaching $1.1 trillion, the financial incentives for attackers will only increase.
The incidents also highlight the importance of operational security (OPSEC) for crypto holders. Maintaining a low profile about cryptocurrency holdings, avoiding the linking of phone numbers to high-value accounts, and using dedicated devices for crypto transactions are all practical measures that can significantly reduce attack surface.
User Action Required
If you are a Friend.tech user or hold cryptocurrency in any account protected by SMS-based two-factor authentication, take action immediately. Disable SMS 2FA, enable authenticator app-based verification, request a SIM port lock from your carrier, and consider transferring significant holdings to a hardware wallet. The $385,000 lost in these attacks is a stark reminder that convenience and security rarely coexist in the world of digital assetup>
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making security decisions regarding your cryptocurrency holdings.
385k drained and friend.tech still required phone numbers for auth. linking crypto wallets to twitter handles was basically a public leaderboard for attackers
385K drained and the lesson people actually learned was to not flex their friend.tech bags on twitter. nobody fixed their SIM security
burner_phone_ fr. people were literally posting screenshots of their key holdings then acting surprised when they got sim swapped. opsec was zero
385k drained from friend.tech users and the platform still relies on phone numbers for auth. sms 2fa is security theater and this proves it
simswap_victim friend.tech linking wallets to twitter handles was basically a targeting menu. attackers just scrolled the leaderboard
carrier_leak_ t-mobile gave my friends number to someone in a different state with no ID check. carriers will not fix this until class actions make it expensive
SIM swap attacks are not new but friend.tech made it worse by linking wallets to social profiles. Attackers knew exactly who to target.
linking wallets to twitter handles was the dumbest UX decision of 2023. literally a public targeting list for sim swappers
0xMirror.eth the SS7 vulnerability has been documented since like 2008 and carriers still use it for 2FA delivery. sim swaps will keep working until something replaces SS7 entirely
ss7_ghost carriers wont replace SS7 because its how they do inter-carrier billing. the protocol that enables sim swaps also enables their revenue. its not a bug its the foundation
ss7_ghost SS7 has been broken since 2008 and every carrier knows it. they wont replace it because it works for them. sim swaps are a feature not a bug from their perspective
SMS 2FA in 2023 for crypto accounts is wild. authy or a yubikey costs like 30 dollars
lost 2 eth in one of these attacks. t-mobile gave my number to someone in a store 500 miles away. unreal
use a hardware 2fa key. yubikey costs 50 bucks and makes sim swaps useless. no excuse in 2023
yubikey is the answer but platforms need to make it default. sms 2fa should be deprecated entirely for anything holding funds
sec_ops the real issue was friend.tech using SMS for auth on wallets holding thousands. basic opsec was nonexistent
yubikey costs less than a coffee and people still wont buy one. convenience always wins over security until its too late
Tariq B. a yubikey is 50 bucks and the friend.tech team never even offered hardware 2FA integration. platform-level failure not just user opsec
yubikey is 50 bucks but friend.tech didnt even offer hardware 2FA. blaming users for not buying their own security keys when the platform controlled the auth flow is wild
same thing happened to my buddy. carrier store didnt even verify ID properly. these companies need to be held liable for negligent SIM swaps
tmobile_refund carriers wont care until class actions hit. the ID verification gap is industry-wide not just one carrier
port_out_ friend.tech keys were literally tied to twitter handles. one sim swap and your entire social graph wallet was drained. $385k was probably low
friend.tech was a hype bubble anyway. the social token model incentivized speculation over actual community. not surprised it attracted predators
linking wallet access to twitter handles was the fundamental design flaw. friend.tech built a public leaderboard of targets and acted surprised when attackers used it
Bence T. building a public leaderboard of wallet balances tied to twitter handles and then acting surprised when people got sim swapped. friend.tech was a security nightmare dressed as socialfi
Branislav M. the leaderboard was the real exploit. friend.tech literally published a hit list with dollar amounts next to each name. $385k was inevitable