CustodyStress
Archive › Physical coercion
Part of the CustodyStress archive of observed Bitcoin custody incidents
CS-00451

The attacker used the SIM swap to bypass 2FA on the victim's exchange account

Blocked
Case description
An August 2017 documented incident describes a Bitcoin holder SIM-swapped by an attacker who had obtained their phone number from an exchange data breach. The attacker used the SIM swap to bypass 2FA on the victim's exchange account and transferred 3.5 BTC before the victim could contact the carrier to block the swap.
Custody context
Stress conditionPhysical coercion
Custody systemMobile or software wallet
OutcomeBlocked
DocumentationUnknown
Year observed2017
CountryUnknown
Structural dependencies observed
Single point of failureThird-party platform dependency
What this illustrates
There was only one way in. When that path was gone, so was access. Access was not recoverable.
Outcome interpretation
Access was not possible under the reported conditions.
Source
Publicly Reported
Evidence type
Forum post
Related cases involving physical coercion
105 cases involve physical coercion 572 cases involve mobile or software wallet View archive statistics →
This archive documents observed custody survivability failures. It does not attempt to document all Bitcoin losses or security incidents. Submit a case
← All cases
Framework references
Terms guide
Survives
Access remained possible under the reported conditions.
Constrained
Access remained possible, but only with delay, dependence, or significant difficulty.
Blocked
Access was not possible under the reported conditions.
Indeterminate
There was not enough information to determine the outcome.
Single-person knowledge
Recovery depended on information or capability held by one individual who was unavailable.
Institutional dependence
Recovery depended on a third-party institution or service that was inaccessible or uncooperative.
Documentation gap
Recovery depended on instructions that were missing, incomplete, or unclear.
Authority mismatch
The person with legal authority to act did not have operational access, or vice versa.
Original text
Rate this translation
Your feedback will be used to help improve Google Translate