Skip to main content
Patterdale Recovery Limited
All case studies
Cryptocurrency ScamSIM Swap2FA BypassMobile Security

Recovered £82,500 - SIM Swap Attack - Crypto Wallet Theft

Client's phone number was hijacked via SIM swap, allowing attackers to bypass 2FA and steal cryptocurrency holdings.

01

How they were scammed

Attackers gathered personal information about the client from social media and data breaches, then contacted their mobile provider impersonating the client. They successfully transferred the phone number to a new SIM card. With control of the phone number, they bypassed SMS-based two-factor authentication on the client's email, cryptocurrency exchange accounts, and banking apps, stealing £150,000 in Bitcoin and Ethereum over a 3-hour window.

02

When they contacted us

The client contacted us the morning after the attack, when their phone showed "No Service" and they discovered all their cryptocurrency exchange accounts had been emptied.

03

Our investigation

Hui Ying Hsieh's blockchain forensics team traced the stolen cryptocurrency from the client's exchange accounts through multiple wallets and exchanges. We identified that 60% of the funds were sent to a single exchange with strong KYC requirements, while the rest was dispersed through smaller amounts across multiple wallets. Our legal team simultaneously investigated the mobile provider's role in the SIM swap.

04

Challenges faced

The SIM swap happened during a weekend, delaying the initial response. The mobile provider initially denied liability, claiming the attacker passed all security verification questions. Some funds were sent through mixers, making direct tracing impossible for approximately 15% of the stolen amount.

05

Breakthrough moment

We discovered the mobile provider had recently changed their SIM swap verification procedures, reducing security checks to cut costs. This negligence formed the basis of a strong legal claim. Additionally, the large concentration of funds at a single KYC exchange enabled effective freezing action.

06

Successful recovery

The KYC exchange froze £65,000 after we served a freezing order. Our legal action against the mobile provider resulted in a settlement of £17,500 for their negligence in the SIM swap process. Total recovery: £82,500 (55%). The mobile provider has since enhanced their SIM swap security procedures.

Lessons learned

  • SMS-based 2FA is vulnerable to SIM swap attacks - use authenticator apps instead
  • Mobile providers may not have adequate security for SIM swap requests
  • Limiting personal information on social media reduces SIM swap risk
  • Cryptocurrency exchanges should use hardware security keys, not SMS, for 2FA

Prevention tips

  • Replace SMS-based 2FA with authenticator apps (Google Authenticator, Authy) or hardware keys
  • Set a SIM swap PIN or password with your mobile provider
  • Monitor your phone service - report unexpected "No Service" immediately
  • Use unique email addresses for financial accounts, separate from your primary email
Call 24/7Free consultation