The FTX hack: how a fake ID and a SIM swap drained $400 million on bankruptcy day
On the same day the FTX crypto exchange filed for bankruptcy, hundreds of millions of dollars in digital assets were drained from its wallets, and prosecutors say the job started with a fake ID at a phone store.[1][2] This case file covers what happened in those hours, how taking over one phone number opened the door, what came of the prosecution, and the one control that was missing.
What happened
FTX, one of the world's largest cryptocurrency exchanges, collapsed in early November 2022 and filed for bankruptcy on November 11. Longtime turnaround executive John J. Ray III took over as chief executive to manage the wreckage.[1]
Within hours, cryptocurrency began flowing out of FTX wallets in transfers no one at the company had approved. The theft ran over several hours across November 11 and 12.[1] Blockchain analysis firm Elliptic valued the unauthorized transfers at about $477 million; FTX's administrators put the figure at $413 million, and a later federal indictment put it at about $400 million.[1][3]
The new management said publicly that there had been unauthorized access to certain assets and that it was working with law enforcement.[3] For more than a year, it was unclear who had done it. In early February 2024, federal prosecutors unsealed an indictment charging 3 people with the theft.[1][4]
How they got in
The method was a SIM swap: getting a mobile carrier to move someone's phone number onto a SIM card the attacker controls. Once that happens, calls and text messages meant for the victim go to the attacker instead.[1]
Prosecutors say the crew had a member walk into a mobile carrier's retail store carrying a fake ID that bore her photo and an FTX employee's personal details, and persuade staff to hand over control of the employee's phone number.[2][4] With the number in hand, the crew could receive the one-time codes that services send by text message to confirm a login. According to the indictment, they used that access to reach FTX accounts and move the cryptocurrency out.[1][4]
The weak link was not a flaw in FTX's software. It was the assumption that whoever holds a phone number is the person who owns it, an assumption a store clerk, a convincing ID and a cover story can break.
How it was caught
Investigators tied the FTX theft to a group that prosecutors say carried out SIM swaps against many victims. The indictment charged 3 people with wire fraud conspiracy and aggravated identity theft.[1][4]
On May 16, 2024, Emily Hernandez of Colorado Springs, the member who prosecutors say presented the fake IDs at stores, pleaded guilty in federal court in Washington, D.C., to wire fraud and aggravated identity theft.[2] She was paid $2,500 for her part, a tiny slice of a theft worth hundreds of millions.[2] Her plea agreement suggested a likely prison range of 41 to 51 months, and she agreed to cooperate. The other 2 defendants pleaded not guilty at the time.[2] The same crew is also accused of taking nearly $600,000 from another victim.[2]
The missing control
The missing control: never letting a text-message code be the thing that protects accounts able to move large sums. Use a hardware security key or authenticator app tied to the device, not to the phone number.
A text-message code is only as safe as the phone number it goes to, and phone numbers can be moved by talking to a carrier. A physical security key or an app-based login check stays with the device the employee holds, so moving the number would have gained the attackers nothing. Adding a rule that large transfers need approval from more than one person would have been a second line, making a single hijacked account unable to empty the wallets alone.
What to do in your business
- Find where text codes guard money. List your bank, payroll, payment and email accounts, and check which ones still rely on a code sent by text.
- Switch to an app or a key. Move those accounts to an authenticator app or a physical security key, and remove the phone number as a backup login where you can.
- Lock your mobile numbers. Ask your carrier to add a port-out PIN or number lock on the business and owners' phone lines.
- Require 2 people for big transfers. Set your bank and payment accounts so large or new-recipient payments need a second approver.
- Watch for sudden loss of signal. Tell staff that if their phone unexpectedly shows no service, they should report it right away; it can be the first sign of a hijacked number.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.