Vitalik Buterin recovers T-Mobile account

After confirming he was a victim of a SIM swap attack that led to a phishing fraud on X (previously Twitter), Ethereum co-founder Vitalik Buterin has now restored his T-Mobile account.

“Finally got back my T-mobile account (yes, it was a sim swap, meaning that someone socially-engineered T-mobile itself to take over my phone number),” Buterin said on Warpcast, a client for the decentralised social protocol Farcaster, where account recovery may be controlled through an Ethereum address.

Despite warnings about the unsafe nature of phone numbers for authentication in the crypto field, given the ubiquity of SIM swap attacks, Buterin didn’t realise that a phone number was enough for malicious actors to reset his X account, even if it wasn’t used for two-factor authentication.

“A phone number is sufficient to password reset a Twitter account even if it is not used as 2FA,” Buterin pointed out. “I had previously seen the ‘phone numbers are insecure, don’t authenticate with them’ advice but had not realised this.”

2FA is a security mechanism for gaining access to a variety of online accounts that requires users to submit two distinct authentication methods to prove themselves, such as a password and an authenticator app code.

