Thai police recently arrested a Chinese man suspected of conspiring with others to use AI face-swapping and SIM card fraud to steal approximately 4,707,000 USDT from an OKX user, with the total amount involved estimated at around RMB 33 million. What makes this case especially worth attention is the complete attack chain: the criminals first obtain the victim’s account and mobile number information, then use AI face-swapping to impersonate the victim to reissue a SIM card, obtain the OTP verification code via SMS, and ultimately take control of the account and transfer away the assets. In the past, many people believed that as long as the password wasn’t leaked, the account would remain safe. But now, the attackers’ target has expanded from “passwords” to “identity.” AI face-swapping solves identity forgery, and SIM card hijacking solves SMS verification—together, they challenge the security of traditional SMS-based verification. Ordinary users should pay attention to three things now: first, enable stronger identity verification offered by the exchange; second, protect your mobile number, email, and API permissions; third, avoid keeping large amounts of assets concentrated in a single exchange account for long periods. This case also suggests that, in the future, exchange security systems may increasingly rely on device identification, behavioral analytics, and abnormal withdrawal interception—not just passwords and verification codes.