Lost my crypto after a SIM swap, phone company says it's not their fault. What now?

asked 5d ago6 views22 answers
0

Evening everyone, I'm absolutely beside myself. Last week, my phone suddenly lost signal. Thought nothing of it at first, maybe just coverage. But then my bank notifications started pinging, and when I eventually got a new SIM from my provider (Vodacom), I saw my crypto wallet (Metamask, mostly ETH and some Polygon) had been completely drained. Low five figures gone, just like that.

Turns out, someone did a SIM swap on my number. They used my number to reset passwords and bypass 2FA, then got into my crypto accounts. I immediately contacted Vodacom, but they're basically shrugging, saying they followed all their security protocols and it's my problem. I feel like they're just washing their hands of me.

I've reported it to the local police here in Port Elizabeth, but honestly, I don't have high hopes. Has anyone experienced this? Is there *any* way to trace this crypto or get it back? I'm desperate, this was my life savings.

Mentioned in this discussion
MetaMask· neutral
#sim-swap-scam#crypto-theft#metamask#voadacom#south-africa#account-takeoverasked by Daniel Nel · Port Elizabeth, South Africa

22 Answers

45

Daniel, that's absolutely gut-wrenching. SIM swaps are a nightmare because they exploit a weakness in the traditional account recovery process, even with '2FA' that relies on SMS.

Firstly, understand that blockchain transactions are irreversible. Once your crypto leaves your wallet to the scammer's, getting it 'back' in the traditional sense is extremely rare. However, *tracing* it is often possible. You mentioned ETH and Polygon – these are public blockchains. The transactions are immutable and visible.

Your immediate steps, which you've partly done, are crucial: report to police (SA Cybercrime Unit if available), and contact your mobile provider again, escalating the complaint if possible. Crucially, gather *all* transaction IDs, wallet addresses involved (your old one, the scammer's receiving address if you can find it via a block explorer), and timestamps.

Then, consider engaging with a reputable blockchain forensics firm. Companies like TRM Labs or Chainalysis specialize in tracing these funds across different networks and exchanges. They can sometimes identify where the funds eventually land – for instance, if they were sent to a large centralized exchange like Coinbase. If the funds hit a KYC'd exchange, there's a slim chance law enforcement (with a court order) might be able to freeze them or identify the perpetrator. Beware fake recovery services that promise guaranteed returns for an upfront fee; they are scams preying on victims of scams. Never pay anyone to 'hack' your crypto back.

Henry Anderson · Canberra, Australiaanswered 5d ago
41

This is a classic and devastating attack, Daniel. Sorry you're going through this. To add to Henry's excellent advice: the key phrase to remember is "not your keys, not your crypto." Once the mnemonic seed phrase of your MetaMask was compromised (likely through the SIM swap allowing access to email/cloud backups or other recovery methods), the funds were effectively theirs.

Now, about tracing: yes, it's absolutely possible. You can use a public block explorer like Etherscan (for ETH) and PolygonScan (for Polygon) to see where the funds went instantly. Type in your old wallet address. You'll see the outgoing transactions. Follow the money. If it moved to another known wallet, and then to a centralized exchange, that's where the forensic firms like TRM Labs come in. They have relationships with exchanges and can issue alerts, which *might* lead to a freeze if the funds are still there and authorities act quickly.

Crucially, educate yourself on *how* they got your seed phrase or access. Was it just the SIM swap leading to email reset, and your seed was stored insecurely in an email or cloud drive? Or did they also have some other info on you? This is vital to prevent future attacks. And adopt hardware wallets and strong, unique passwords for every service, especially those connected to crypto.

Sophia Tremblay · Montreal, Canadaanswered 5d ago
22

Oh man, Daniel, I'm so sorry to hear this. SIM swaps are just evil. It's not your fault, mate. These phone companies need to be held more accountable for their shoddy security when it comes to identity verification. It's a massive loophole.

I haven't been through a crypto SIM swap myself, but I know people who've had bank accounts drained this way. The feeling of helplessness is awful. Keep pushing Vodacom. File a formal complaint, maybe even with a consumer protection body if SA has one. Sometimes public pressure or a regulator's involvement makes them take it more seriously. Just don't give up on fighting them on their negligence, even if it feels like a long shot for the money directly.

Thomas Walker · Glasgow, United Kingdomanswered 5d ago
18

Ugh, another SIM swap nightmare. Honestly, it's terrifying how vulnerable we are. I keep hearing about this happening, and it makes me paranoid.

While I empathize a lot, the harsh truth with crypto, especially when it's left your wallet and gone onto a scammer's, is that it's generally gone. The police might log it, but their chances of recovering funds, especially crypto that gets tumbled fast, are usually very low. And these 'blockchain forensics' companies... maybe they can trace it, but then what? Your local police in Port Elizabeth aren't likely to go knocking on doors in some random country where the funds ended up. Just saying, try to manage expectations.

Sophie Mulder · Utrecht, Netherlandsanswered 5d ago
15

Oh, Daniel, I know exactly how you feel. This happened to me last year, almost to the letter. Similar amount, though mine was mostly USDT. Lost it after a SIM swap, Rogers here in Canada were just as useless. Said they did everything right. It was a nightmare.

i reported it everywhere – police, bank, even a special fraud line here. Got a lot of empathy, zero crypto back. My bank froze my regular accounts for a bit, which was a hassle. The emotional toll was probably worse than the financial, honestly. Just the feeling of being so violated and powerless. I hope you have better luck than i did, but yeah, it's a tough one.

Isabella Gagnon · Edmonton, Canadaanswered 5d ago
28

Wow, Daniel, that's truly awful. I had a narrow escape from a SIM swap attempt a few years back. My bank called me about some weird activity, and I immediately knew something was off. Switched to an e-SIM after that, and use authenticator apps (like Google Authenticator) for any 2FA on my crypto and banking, rather than SMS. It's a much more secure way.

I really hope you can get somewhere with Vodacom. The way they're just washing their hands is ridiculous. They have a duty of care. Maybe look into legal advice, see if there's any precedent for negligence on their part? I know lawsuits are a pain, but sometimes that's the only way to get these big companies to listen. It might not get your crypto back, but it could help prevent it happening to others.

Louis Petit · Toulouse, Franceanswered 5d ago
39

Okay, Daniel, this is a deep dive, but crucial. You need to understand the lifecycle of a SIM swap crypto theft. It typically goes like this:

  1. Reconnaissance: Scammers gather personal info (P.I.I. – addresses, date of birth, mother's maiden name, etc.) through phishing, data breaches, or social engineering. This is used to impersonate you.
  2. SIM Swap Execution: They contact your mobile provider (Vodacom in your case), pretending to be you, and convince a poorly trained or compromised agent to port your number to a SIM card they control. Your phone goes dead.
  3. Account Takeover: With control of your number, they target critical accounts that use SMS 2FA or password reset via SMS: your email, then your crypto exchange account, or potentially even your cloud service where you might have (dangerously) stored your MetaMask seed phrase.
  4. Wallet Drain: Once they have access to your email or crypto exchange, they will quickly clear out funds. If they got your MetaMask seed, they just import it to their own wallet and drain it.

Your chances of recovery hinge *entirely* on whether the funds landed on a *centralized exchange (CEX)* that performs KYC (Know Your Customer) *and* whether law enforcement acts quickly enough to issue a freeze request. Companies like TRM Labs or Chainalysis provide software for this, but *you* cannot directly engage them for recovery. They work with law enforcement and exchanges. Your best bet is strong local police work, ideally through a cybercrime unit, providing them with ALL transaction details (hashes, recipient addresses) and pushing them to use their international liaisons (INTERPOL, etc.) to contact any CEX identified.

And yes, as Sophia said, *never* store your seed phrase digitally, even encrypted. A hardware wallet is the gold standard for securing your crypto.

Joshua Mokoena · East London, South Africaanswered 4d ago
9

God, Daniel, I'm just numb hearing this. My heart goes out to you. I lost about 4k worth of Bitcoin three years ago to a similar attack, not exactly a SIM swap but they eventually got access to my old email and then my exchange account. It wasn't Coinbase, it was some smaller platform and they just vanished. It's been years and I still feel that pit in my stomach.

I contacted the police too, filed a report, but honestly, it went nowhere. They treated it like a minor theft, even though for me it was huge. I wish I had better news or advice, but I think the biggest lesson I learned was to never rely on SMS for anything important again. I use a YubiKey for my main accounts now. It's too late for us, but maybe your story helps someone else tighten their security.

Christopher Miller · San Diego, USAanswered 4d ago
25

Okay, Daniel, look, I get the pain, truly. But we also need to be realistic. While the narrative of 'tracing' crypto is very appealing because it uses cool blockchain tech, the reality for an individual victim in South Africa trying to recover funds that probably went overseas and passed through multiple mixers or decentralized exchanges is... bleak.

Push Vodacom, yes, complain, make noise. It's about accountability. But for your crypto? By the time any traditional law enforcement agency gets a court order, coordinates with international agencies, and then tries to get an exchange to freeze funds (which means the funds have to *still be there* and not already moved off to a non-KYC'd wallet), the crypto is usually long gone and liquid. Don't fall for any 'recovery services' you see advertised, especially online. They're 99% scams preying on your vulnerability. Just be very, very careful who you talk to about this stuff.

Chloe du Plessis · Cape Town, South Africaanswered 4d ago
35

Daniel, your situation is precisely why SIM swaps are considered one of the highest leverage attacks on crypto holders. The weakest link is often outside the blockchain itself – your carrier. My professional advice echoes Henry's and Sophia's: blockchain forensics is your only genuine path to *identification* of endpoints, not necessarily *recovery*.

To maximize any chance, ensure your police report explicitly mentions that these were *funds stolen via unauthorized access to digital assets*, not just a 'stolen phone number'. Be precise with blockchain terminology. Provide the exact contract addresses for ETH and Polygon if it was ERC-20 or Polygon tokens, and all destination addresses the stolen funds went to. Even if the police are under-equipped, a formal, detailed report is critical if any international cooperation were ever to materialize.

Regarding the mobile provider, escalate with Vodacom. In some jurisdictions (e.g., USA with the CFTC's jurisdiction, or the UK's OFCOM), telecom providers *can* be held liable for gross negligence in SIM swap cases that lead to financial loss. While SA's regulations might differ, a strong, documented complaint alleging neglect of security protocols that directly resulted in criminal financial loss is important. This is separate from crypto recovery, but crucial for seeking some form of justice or compensation against the carrier.

Faisal Ahmed · Dubai, UAEanswered 4d ago
7

This is a brutal situation, and sadly, becoming more common. SIM swap attacks are sophisticated. The telcos are often contractually absolved if they *claim* to follow their internal procedures, which is infuriating. What you need to do now is gather *all* proof of the unauthorized SIM swap and any communication logs with Vodacom. Email is better than phone calls for this. Simultaneously, start a formal complaint with the Independent Communications Authority of South Africa (ICASA). They can investigate Vodacom's procedures even if the funds are gone. Don't let Vodacom off the hook easily; they have a responsibility to protect their network users.

Alice Simon · Lille, Franceanswered 4d ago
5

Oh wow, that's absolutely devastating. I can only imagine how sick you must feel right now. It sounds like a textbook SIM swap, and man, tech companies make it easy for these guys sometimes. I haven't been hit myself, but I know a few people who have. Keep pushing Vodacom, and don't *just* rely on the police. Maybe the ICASA route that Alice mentioned could yield something. We're all rooting for you to find some resolution here.

Jason Martin · Denver, USAanswered 4d ago
6

Heartbreaking to read this. This exact scenario is why I warn everyone I know *not* to rely on SIM-based 2FA for anything important, especially crypto. It's a single point of failure. Companies like Vodacom should have better protocols for SIM swaps – requiring in-person ID at a store with the actual account holder's signature, maybe even a video call for remote requests. What they *say* they did internally isn't good enough. You need to push them harder, or at least for evidence of *your* consent to the swap.

Oliver Hughes · Birmingham, United Kingdomanswered 4d ago
8

This is a particularly nasty flavour of social engineering enabled by weak telco security. The typical flow involves the attacker phoning your provider, impersonating you, and convincing them to port your number to a new SIM card they possess. Once they control your number, they request password resets for your key accounts, using your number for the SMS-based OTPs. For crypto, I'd recommend looking into blockchain analysis firms. Some, like Nethertrace, specialize in tracking tainted crypto assets, though recovery chances diminish rapidly. Even if you can't get funds back, documenting the attack chain is crucial for potential legal action.

Ethan Gauthier · Vancouver, Canadaanswered 4d ago
4

Oh mate, that’s awful. Same thing happened to my cousin last year. Same bloody phone company, actually. They lost about £8k worth. The telco absolutely denied everything. It’s a nightmare. They tried to get money back through some outfit called Wealth Recovery International, but that just turned out to be another scam. Ended up with nothing. Really feel for you. Is MetaMask going to do anything at all?

Lucas de Jong · Eindhoven, Netherlandsanswered 4d ago
4

I'm so sorry this happened to you. I'm in a similar boat, had a phishing attempt on my email that led to my Trust Wallet being compromised shortly after. No SIM swap for me, but the feeling of violation and helplessness... it's unbearable. They got away with a chunk of my savings too. Right now, I'm just trying to learn from it, changing all my passwords, looking into hardware wallets. Have you considered reporting this to any international bodies? Maybe Interpol?

Conor O'Neill · Cork, Irelandanswered 4d ago
5

This makes me so angry. Phone companies are just useless when it comes to this. They take your money every month but when it comes to protecting you from actual fraud facilitated by *their* network, they throw up their hands. You were doing everything right with 2FA, and they undermined it. Did you have a hardware wallet? Or was it a hot wallet connected directly to your phone? Knowing the setup might help others avoid the same trap. If you think any exchanges were involved, look into reporting to organizations like the CFTC in the US, though they mainly focus on regulated markets.

Ashley Miller · Miami, USAanswered 4d ago
3

Terrible news, my friend. This kind of crime is just cowardly. I'm not in SA, but I know people who've dealt with similar stuff. The police can be slow, I understand the frustration. Don't give up on them entirely, but definitely follow Alice's ICASA advice. Also, when you contact Vodacom, be firm but polite. Sometimes a strong, clear email outlining the exact sequence of events and requesting their specific internal procedure for SIM swaps that were triggered *without* your direct, verified consent can get a better response. Keep us updated.

Michael Naidoo · East London, South Africaanswered 4d ago
4

Right, so Vodacom says they followed protocol? Which protocol? The one where they give away a customer's number to the first person who calls up claiming to be them? Seems dodgy. Did you have SMS confirmation *from Vodacom* about the SIM swap happening? Or did you only find out *after* your crypto was gone? Because if they didn't notify you *before* it went live, that's a security failure on their end, plain and simple. Did you double-check your MetaMask security settings themselves? Like recovery phrases being stored securely?

Henry Williams · Leeds, United Kingdomanswered 4d ago
7

This is precisely why SMS-based 2FA is considered weak, especially for high-value accounts. It's vulnerable to SIM swapping and SS7 attacks. You should have had multiple layers of security if you were holding a significant amount. For example, using authenticator apps like Google Authenticator or hardware security keys (like YubiKey) for your primary exchange accounts, and *then* only using the minimum necessary exposure on your MetaMask. Companies like TRM Labs track illicit crypto movements but recovery is extremely difficult once funds hit mixers or privacy coins. Your best bet is regulatory complaints and possibly Nethertrace.co for tracing.

Aaron Tay · Singapore, Singaporeanswered 4d ago
3

Oh no, that's just awful news. I can't imagine the stress you're going through. It sounds like a nightmare scenario. While Vodacom is being difficult, maybe consider reaching out to a digital forensics person? Someone who might be able to trace the ETH/MATIC transactions on the blockchain. Sometimes these trails can lead somewhere, even if it's just an exchange address. It's a long shot, I know, but when it's life savings... worth exploring every avenue. Keep your chin up, mate.

Arthur David · Toulouse, Franceanswered 4d ago
4

My heart just sank reading your post. This happened to my brother-in-law back in Perth. He lost his whole MetaMask account too. The bank was useless, the telco was useless. He ended up reporting it to ACORN, which is the Australian Cybercrime Reporting Network. It didn't get his money back, but they did flag the SIM swap company they suspected. You should definitely report it to the South African equivalent. It might not help you directly, but it helps build a case against these fraudsters for others.

Noor Al Falasi · Al Ain, UAEanswered 4d ago

Your answer

You'll be asked to sign in to post.