Case file · FTX DRAIN 2022

The FTX hack: how a fake ID and a SIM swap drained $400 million on bankruptcy day

Published 2026-09-29 · 4 min read · Missing control: No SMS codes guarding exchange funds

On the same day the FTX crypto exchange filed for bankruptcy, hundreds of millions of dollars in digital assets were drained from its wallets, and prosecutors say the job started with a fake ID at a phone store.[1][2] This case file covers what happened in those hours, how taking over one phone number opened the door, what came of the prosecution, and the one control that was missing.

What happened

FTX, one of the world's largest cryptocurrency exchanges, collapsed in early November 2022 and filed for bankruptcy on November 11. Longtime turnaround executive John J. Ray III took over as chief executive to manage the wreckage.[1]

Within hours, cryptocurrency began flowing out of FTX wallets in transfers no one at the company had approved. The theft ran over several hours across November 11 and 12.[1] Blockchain analysis firm Elliptic valued the unauthorized transfers at about $477 million; FTX's administrators put the figure at $413 million, and a later federal indictment put it at about $400 million.[1][3]

The new management said publicly that there had been unauthorized access to certain assets and that it was working with law enforcement.[3] For more than a year, it was unclear who had done it. In early February 2024, federal prosecutors unsealed an indictment charging 3 people with the theft.[1][4]

How they got in

The method was a SIM swap: getting a mobile carrier to move someone's phone number onto a SIM card the attacker controls. Once that happens, calls and text messages meant for the victim go to the attacker instead.[1]

Prosecutors say the crew had a member walk into a mobile carrier's retail store carrying a fake ID that bore her photo and an FTX employee's personal details, and persuade staff to hand over control of the employee's phone number.[2][4] With the number in hand, the crew could receive the one-time codes that services send by text message to confirm a login. According to the indictment, they used that access to reach FTX accounts and move the cryptocurrency out.[1][4]

The weak link was not a flaw in FTX's software. It was the assumption that whoever holds a phone number is the person who owns it, an assumption a store clerk, a convincing ID and a cover story can break.

How it was caught

Investigators tied the FTX theft to a group that prosecutors say carried out SIM swaps against many victims. The indictment charged 3 people with wire fraud conspiracy and aggravated identity theft.[1][4]

On May 16, 2024, Emily Hernandez of Colorado Springs, the member who prosecutors say presented the fake IDs at stores, pleaded guilty in federal court in Washington, D.C., to wire fraud and aggravated identity theft.[2] She was paid $2,500 for her part, a tiny slice of a theft worth hundreds of millions.[2] Her plea agreement suggested a likely prison range of 41 to 51 months, and she agreed to cooperate. The other 2 defendants pleaded not guilty at the time.[2] The same crew is also accused of taking nearly $600,000 from another victim.[2]

The missing control

The missing control: never letting a text-message code be the thing that protects accounts able to move large sums. Use a hardware security key or authenticator app tied to the device, not to the phone number.

A text-message code is only as safe as the phone number it goes to, and phone numbers can be moved by talking to a carrier. A physical security key or an app-based login check stays with the device the employee holds, so moving the number would have gained the attackers nothing. Adding a rule that large transfers need approval from more than one person would have been a second line, making a single hijacked account unable to empty the wallets alone.

What to do in your business

Watch the case
FTX was robbed of $400M the day it went bankrupt, via a fake IDDrops 2027-01-17
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Krebs on Security: Arrests in $400M SIM-swap tied to heist at FTX?
  2. Yahoo Finance: Guilty plea in $400 million FTX SIM swap scheme
  3. Elliptic: $477 million in unauthorized transfers from FTX
  4. CNBC: Three people indicted in $400 million FTX hack conspiracy