Advanced
Vitalik Buterin@vitalik.eth
9/11/2023

Finally got back my T-mobile account (yes, it was a sim swap, meaning that someone socially-engineered T-mobile itself to take over my phone number).

In reply to @vitalik.eth
Andrew Miller@socrates1024
9/11/2023

welcome back :) terrifying tho

In reply to @vitalik.eth
Vitalik Buterin@vitalik.eth
9/11/2023

Main learning re twitter was: > A phone number is sufficient to password reset a Twitter account even if not used as 2FA. Can completely remove phone from Twitter. I had seen the "phone numbers are insecure, don't authenticate with them" advice before, but did not realize this

In reply to @vitalik.eth
Trish🫧@trish
9/11/2023

I had my sim “protected” by T-Mobile. The lost my pin but it was so too easy for me to get access to my account, I left. I’m so sorry that happened to you.

In reply to @vitalik.eth
manansh ❄️@manansh
9/11/2023

Scary…

In reply to @vitalik.eth
phil@phil
9/11/2023

Sorry that happened to you. Glad that the damage was mitigated quickly.

In reply to @vitalik.eth
Dan Cortes@typeof.eth
9/11/2023

I don’t love Google Fi (mainly cause coverage isn’t as good), but two things that keep me here are free roaming and 2fa. Makes sim swapping much more difficult.

In reply to @vitalik.eth
Christian@cristi
9/11/2023

Welcome back! X needs to urgently implement better account security to prevent against this sort of attack. Are phone carriers in the US so easily susceptible to social engineering? In europe they ask for my full SSN equivalent + billing address to perform a sim swap.

In reply to @vitalik.eth
9/11/2023

have you seen efani.com? i’ve had a good experience

In reply to @vitalik.eth
LitTurnip@litturnip
9/11/2023

Always tmobile..

In reply to @vitalik.eth
Garrett@garrett
9/11/2023

Why aren’t you using an authenticator app or security key?

In reply to @vitalik.eth
Syed Shah 🏴‍☠️🌊@syed
9/11/2023

The best part of the hack was it took a lot of power away from you in terms of how much people listen to what you say without thinking. There will be a layer of critical thinking that's been strengthened. So a + for the community.

In reply to @vitalik.eth
Zuphioh@zebra
9/11/2023

Sim Swaps becoming a very frequent issue in this space, crazy how many people are getting impacted by it lately

In reply to @vitalik.eth
Farzad@005
9/11/2023

Not used authenticator apps?

In reply to @vitalik.eth
Chopper@chopper
9/11/2023

Highly suggest switching providers. T-mobile is run by boomers who have no understanding of the technology & related exploits. I believe the CEO even blocked customers for bringing this to their attention.

In reply to @vitalik.eth
JonnyRingo.eth ⚰️@jonnyringo
9/12/2023

Really glad to hear there wasn't any other collateral damage!

In reply to @vitalik.eth
Thomas D. Pellegrin (🥝,🔪)@aviationdoctor.eth
9/12/2023

Looks like everyone dropped the ball here. X shouldn’t enable phone recovery by default, it’s an obsolete practice. T-Mobile should use PINs to thwart social engineers (we’ve known about SIM swaps for years) + special procedures for public figures who are obvious targets (flag set=call escalation, added verif).

In reply to @vitalik.eth
Tony@at
9/12/2023

YubiKeys are what you need 👍 Yes they can be used on X

In reply to @vitalik.eth
Adrienne@adrienne
9/12/2023

Do you guys think mobile companies keep a list of high profile, likely targets for sim swaps? I would hope so but this makes me think they most certainly don’t, at least not T mobile 😒

In reply to @vitalik.eth
thebestwallet@thebestwallet
9/12/2023

Anything beyond twitter was attacked ?

In reply to @vitalik.eth
Daddy@daddy
9/12/2023

Hi vitalik, Are you going to refund the people who got affected from it?

In reply to @vitalik.eth
chrisb (boscolo.eth)@boscolo.eth
9/12/2023

I'm sorry to hear about your experience, @vitalik.eth! I was sim swapped in 2019, so I understand the frustration. The experience motivated me to launch @3num. Our goal is to upgrade traditional SMS and voice protocols to more secure, crypto-native alternatives. 📱🔒

In reply to @vitalik.eth
Jack Su@jacksu
9/12/2023

Have you taken control of your Twitter account yet?

In reply to @vitalik.eth
nixo@nixo
9/12/2023

have seen a lot of this sim swaps but no post mortems on best practices to quickly recover your accounts - would really love to see something like this. i have no idea who you'd even reach out to in this situation

In reply to @vitalik.eth
GabrielAyuso.eth ⌐◨-◨@gabrielayuso.eth
9/12/2023

I might be biased but Google Fi is most likely the most secure carrier to hold your mobile number since it's backed by Google account security.

In reply to @vitalik.eth
Dan Finlay@danfinlay
9/12/2023

Had you given T Mobile any special recovery instructions? I understand they will accept them (like a special password to provide to reset). Am curious if the social engineering bypassed any special notes.

In reply to @vitalik.eth
Barto Molina@bartomolina
9/12/2023

Unfortunately many services still require a phone number. I wonder if at this point using a virtual number (Google Voice, Skype…) is safer. I’ve been using one for the past few years and at least they do a good job by filtering scam calls/sms. Not sure if sim swap would be possible with these

In reply to @vitalik.eth
Paulus@paulus
9/12/2023

Sorry that happened.

In reply to @vitalik.eth
Zirar@zida
9/12/2023

North Korea hackers!!

In reply to @vitalik.eth
w3tester@w3tester
9/12/2023

This is why we built valid3.id. When you are posting links or money related contents, you should sign them with your key. No more phishing attacks as the hackers don’t have your private key to generate the signature. It works like this👇 === https://sign.valid3.id/#/pnizhjQV

In reply to @vitalik.eth
Jam ☀️@jameshih
9/12/2023

Some mobile operators in Taiwan require you to physically be at a store location with your double IDs (National card and Med card) and a personal stamp to initiate a SIM card change. It’s almost impossible to do a SIM card swap that way, it’s even hard for one to change his or her own SIM card sometimes. 😂

In reply to @vitalik.eth
9/12/2023

It is frustrating these types of hacks where people unfairly lose their digital assets. Until this is fixed we will not be offering a valid technology for the next internet. People want security, protection and guarantees of their property...

In reply to @vitalik.eth
lastpiece.x@standpoint.eth
9/12/2023

How did they get your phone number in the first place though?

In reply to @vitalik.eth
web3d3v | sonsOfCrypto.com@web3d3v
9/12/2023

I every time is dapp requiring phone number I die inside a little Looking at you friend.tech, argent !

In reply to @vitalik.eth
Pope@pope
9/12/2023

How long did it take? Did t-mobile change back to original sim?

In reply to @vitalik.eth
web3d3v | sonsOfCrypto.com@web3d3v
9/12/2023

Every time I come across dapp requiring phone number I die inside a little Looking at you friend.tech, Argent !

In reply to @vitalik.eth
Xrami@td
9/12/2023

Difference of Decentralisation and centralisation 🤔

In reply to @vitalik.eth
9/12/2023

sim carts matters

In reply to @vitalik.eth
9/12/2023

Glad you got it resolved

In reply to @vitalik.eth
Ehsan@kehsan
9/12/2023

Thanks for sharing 🙌🏼

In reply to @vitalik.eth
9/12/2023

So sorry you had to experience that Vitalik!

In reply to @vitalik.eth
MD HASAN@0001
9/12/2023

That's really sad

In reply to @vitalik.eth
EverlastingOS 🛡️@everlastingos.eth
9/12/2023

Crazy man, this is why we need Farcaster and Feeds social.

In reply to @vitalik.eth
Andrii @gl
9/12/2023

I think it’s good that we are moving towards greater anonymity and there are more and more opportunities to buy anonymous mobile numbers

In reply to @vitalik.eth
Schubert@1000
9/12/2023

What do you think about L2 eth wallets like argent mobile,that use email instead of seed phrase? Easily Emil can be hacked by sim swap I think 🤔

In reply to @vitalik.eth
Petr Malyukov@richmal.eth
9/12/2023

@vitalik.eth Unfortunately, this is often the problem of all analog operators, where it assigns a static number and is tied to personal data and operators do not fight this problem. I use Web3 Phone Service dcalls.org

In reply to @vitalik.eth
Vinay Vasanji@vinayvasanji
9/12/2023

Given your profile, it's probably wise to switch from T-Mobile to a carrier like Efani https://www.efani.com/

In reply to @vitalik.eth
Buuvei@buuvei
9/12/2023

Good to have you back

In reply to @vitalik.eth
Mick King@smolinkling
9/12/2023

It's good to have you back...

In reply to @vitalik.eth
Don Corleone@godfather
9/12/2023

Be safe vitalik

In reply to @vitalik.eth
Fauziiacong@fauziiacong
9/12/2023

Your X account yesterday, is it true that it was hacked?

In reply to @vitalik.eth
Sebas@sebas
9/12/2023

They can’t simply sim swap your farcaster account 🫡

In reply to @vitalik.eth
9/12/2023

That's wild, how archaic the phone number system is

In reply to @vitalik.eth
rustedpopcorn@rustedpopcorn
9/12/2023

It’s always T-mobile lol

In reply to @vitalik.eth
Milad@milord
9/12/2023

Be careful bro 🙏

In reply to @vitalik.eth
9/12/2023

Hey vitalik. How it is possible ? You have a swap for scam $Warpcast on base network. I thought it is real until i checked it on Debank

In reply to @vitalik.eth
9/12/2023

Very good But you mistake for sell t mobile

In reply to @vitalik.eth
Natasha@natasha
9/12/2023

Glad u re back

In reply to @vitalik.eth
Arvin@arvin
9/12/2023

Now is that you vitalik ?

In reply to @vitalik.eth
Joel🏴(🦇,🔊,🦖)@joelzhou
9/12/2023

It's horrible experience, try to transfer your number to other more secure provider, if there's one.

In reply to @vitalik.eth
Arash@arashb
9/12/2023

Thanks for sharing

In reply to @vitalik.eth
m0ham3dx@m0ham3dx
9/12/2023

Connecting a completely randomly named email acc and voip number verification, adds another layer of sec, since ur in the public eye, most if not all ur personal details are public, c wat im saying ?

In reply to @vitalik.eth
9/12/2023

how is it possible Very unprofessional I cant believe this😐

In reply to @vitalik.eth
9/13/2023

سید اکانتت بگا رفته بودا ، کلی آدم دیگه رو هم بگا دادی 👏👍