Contents:
SIM card replaced by hackers
Verizon SMS verification may be a security vulnerability?
Vitalik has also experienced SIM Swap before
On October 3, @darengb posted on social media platform X (formerly twitter) that "I just had my SIM card swapped and 22 ETH stolen." It is reported that all the keys owned by the user on friend.tech and the keys of the user held on other people's accounts have been sold, and the remaining ETH in the user's wallet has been exhausted. "If your Twitter account is searched for your real name, your phone number will be found, and this may happen to you." @darengb added.

SIM card replaced by hackers
The real name and phone number were searched from the Twitter account, and then the friend.tech account key was stolen. The logic behind this was that the SIM card bound to the user was replaced by the hacker.
@darengb also recounted the details of his friend.tech hack in his tweet, "Earlier today, I started getting spam every minute, which caused me to turn my phone to silent (I guess that's the point), so I didn't see the text message from Verizon telling me someone was trying to access my account. It happened so quickly that Verizon barely gave me any time to react. I opened FriendTech and thought there was an error because my chat room was empty. I tried to check Octav and then saw other people's tweets about SIM card swaps on the FT, and that's when I realized what was going on."

This incident also triggered heated comments in the community, among which @IncomeSharks posted, "The same thing happened to me, and those people sent me spam text messages first. Because the operator will not wait for me to approve the request, if I don’t reply within 10 minutes, they will approve the SIM card swap. Mobile operators are too bad! Sim swapping should not be a problem."

@AloshyAkasoto said, “This is not just a friend.tech issue, it’s also because their wallet provider privy allows users to register using their phone numbers. Unfortunately, phone numbers are the weakest link in network security. The same vulnerability may exist in all dApps that use privy as a wallet provider.”

Verizon SMS verification may be a security vulnerability
However, as early as September 18, @Montana_Wong tweeted: “I’m a fan of friend.tech, but I’m afraid to hold funds there because 1. your wallet balance is public information 2. it uses SMS for authentication With a high enough balance, you become a target for SIM swaps… hackers will throw away the keys you hold and take out your USD.”

The telecommunications industry behind friend.tech is Verizon. Verizon was approved by the U.S. Patent and Trademark Office in 2019. The patent mentioned a data system related to blockchain and virtual SIM cards. According to the patent document, this system will provide a special user account for the virtual SIM card (vSIM) and can activate the SIM card on the device. After the SIM card is activated, a message will be published on the blockchain network to confirm the activation.
Related reading: "Verizon applies for blockchain patent for virtual SIM card to improve activation speed and security"
Virtual SIM cards are not new. They can be used to register on some devices that do not provide physical SIM cards and use the operator's network. For example, Apple's Apple Watch has used virtual SIM cards. The blockchain confirmation technology provided by Verizon will increase the activation speed and security. The blockchain can encrypt user data and ensure that only one device is using the vSIM card at the same time.
Last January, Verizon posted a recruitment information for a partner manager on LinkedIn, indicating that the company plans to enter the fields of NFT, Web 3 and the metaverse. In response to the SIM card swap incident, @CryptoWithNick said that Verizon has implemented a new feature “Num Lock” to combat SIM card swapping.

However, community members still questioned this, and @wholeisticguy posted that "the process and technology are fundamentally insecure and no one can guarantee it. SMS, your SIM card, and your phone number are not secure and cannot be guaranteed. Never use these to protect anything, and anything that uses them to guarantee security is insecure."

Vitalik has also experienced SIM Swap before
Losses caused by SIM card swaps are not new. BlockBeats reported on September 10 that Ethereum co-founder Vitalik’s Twitter account was hacked and phishing links were posted. According to ZachXBT, hackers stole a total of about $691,000. On September 12, Vitalik posted on social media that he had recovered his T-mobile account and confirmed that the previous attack was a SIM card swap attack.

Vitalik explained that as far as X is concerned, holding the phone number is enough to reset his account password. He had seen the advice that "phone numbers are not safe, don't use them for authentication" before, but he didn't realize the problem. It is currently speculated that the mobile phone number was leaked when registering Twitter Blue.
