$18.5 billion. That is what flows through Binance on a quiet day, according to its own spot-and-derivatives books. Bybit clears $9.2 billion. OKX $4.9 billion. Bitget — which incidentally holds a full operating license from Poland's KNF — does $6.1 billion. The figure you will never see in any of those press releases is the median size of a successful SIM-swap haul, because every exchange compliance team treats that number like a NATO cable.

Four people were just arrested in Poland over crypto SIM-swap attacks. ZachXBT, doing what ZachXBT does, traced part of the laundering route and linked it to an on-chain operator known as Merry. Most of the coverage you will read will be about the arrests. A smaller fraction will be about the tracing. Almost none of it will be about the only question that matters.

Why, in 2026, is a phone number still capable of moving six figures?

Your Phone Number Should Not Be Able to Move Six Figures, and It Often Can

Listen. I am going to spare you the SIM-swap mechanics explainer because if you are reading this you already know how it works — social engineer a telco rep, port the number, intercept the SMS code, walk into the account. The interesting question is not how the attack works. The interesting question is why the attack still works on accounts holding life-changing money in 2026.

Here is the part that almost nobody in the crypto press will say out loud. Binance's last reserve verification audit was published 2025-03-01. Bybit's was 2025-03-12. Bitget's was 2025-02-20. OKX's was 2025-03-01. Every major centralized venue in the top tier of the public Proof-of-Reserves theater can demonstrate, with a Merkle tree and a Big Four signature, that the coins are there. I want to concede that fully. The reserves are there. The audits are real. By any reasonable read of public posture, the security teams at these venues are serious.

None of that matters when the front door is a six-digit code delivered over a 1990s-era SS7 network to a phone number controlled by a customer service rep at a telco that was last audited on its identity-verification flow at some point during the Obama administration.

This is the part that breaks people when they finally understand it. The exchange is not your weak link. The exchange is a hardened bank vault sitting at the end of a hallway whose door is held shut by a Post-It note. Anyone who has spent ten minutes thinking about retail crypto OPSEC has reached the same conclusion — SMS-2FA is the architecture's self-replicating bug. Knowing this and shipping it as the default flow anyway is, technically speaking, a choice.

Free Download
Crypto Market Cycle Cheat Sheet 2026
Entry signals, exit rules & DCA calculator — based on 3 previous cycles.

The Polish Arrests Will Not Fix the Architecture That Made Them Possible

I want to be precise about what the Polish arrests actually accomplish, because the celebratory takes I have already seen — "law enforcement finally getting it!" — are confusing two different problems.

Catching the people who did the SIM-swap is a downstream problem. It is a justice problem. It is, sure, a deterrence problem if you squint. Solving it does not change the fact that the attack vector remains open and that the next four people who decide to try it will not be deterred by the previous four. The economics work because the upside is genuinely large and the technical bar is genuinely low. ZachXBT tracing the laundering route through whatever mixer-and-bridge configuration Merry was running is, again, downstream. The chain is transparent. The chain has been transparent for fifteen years. Transparency is good for documenting what happened. Transparency has done absolutely nothing to prevent it from happening again.

The upstream problem is that exchanges still ship SMS-2FA as the default recovery flow. Not the optional flow. The default flow. The flow your sister, who does not read crypto Twitter, will end up with because it is the first thing the signup wizard shows her. Some of these venues let you turn it off in settings if you know to look. Some require you to keep it on "for account recovery" even when you have a hardware key configured, which means the hardware key is decorative.

The grim joke — and I am going to call it a grim joke because I cannot find a less honest word — is that Bitget operates under a full Polish KNF license while Polish prosecutors are arresting people whose business model targets users on platforms that ship the same SMS-as-recovery defaults. The license tells you about reserve transparency, capital adequacy, AML procedure. It does not tell you anything about the attack surface a casual user actually faces. Tier-2 licenses do not require phishing-resistant recovery flows. That is the regulatory gap, and the gap is the reason the arrests do not fix anything structural.

What You Tell Your Family About Why You Use a Ledger

If you are the person in your family who got into crypto, you are also the person in your family who has had this conversation. The one where a parent, a spouse, a sibling asks you — gently or not so gently — why you are carrying around what looks like a USB stick that you do not let out of your sight.

Here is the framing that lands. The fundamental question is not "is Bitcoin a scam." The fundamental question is who you are trusting to hold the key. When the key is your phone number, your custodian is the telco — and the telco's security model was designed for a world where the worst thing someone could steal from your account was your voicemail. When the key is your email password, your custodian is whoever can call the email provider's recovery line. When the key is a hardware wallet stored offline and confirmed on its own display, your custodian is the device firmware and the physical security of a small piece of silicon in your drawer.

That framing is what makes the conversation work. Most family members do not need to understand elliptic curves. They need to understand custody as a chain of trust, and they need to see that you have moved the chain off the most fragile link in the system — the one a teenager with a convincing voice and a stolen photocopy of someone's ID can break.

A Ledger or a Trezor — and I will mention the GridPlus Lattice1 for readers who want a co-signer abstraction layer — moves the trust anchor from a telco rep to silicon you control. The firmware can still have bugs. The supply chain can still be attacked. But the attack surface goes from "anyone with a convincing voice" to "someone who has physically obtained your device and broken its secure element." That is two orders of magnitude harder. The people who do it for a living do not target a $4,000 wallet.

For serious capital — the family-office tier, the founder-with-token-allocation tier — the qualified custodian path exists. Coinbase Custody runs as a New York DFS-chartered trust company. Fidelity Digital Assets sits under the same DFS posture. Anchorage Digital holds an OCC federal trust charter and was, for a long stretch, the only crypto bank in the country with one. These are not "exchanges with a custody product bolted on." They are custodians whose entire balance-sheet structure is regulated as custody, and whose operational defaults assume the attacker has already compromised the customer's phone, email, and a portion of their support staff. The cost is meaningful — basis-point fees on AUM — but the cost is the point. You are paying for the threat model.

I would reverse this position the day a major exchange ships a default signup flow that does not include SMS-2FA, that does not permit re-enabling SMS-2FA after enrollment, and that requires hardware-key registration before deposits clear. Until that day, the position holds. The arrests in Poland are good. They do not change the recommendation.

This piece started as a take on the Polish arrests and the ZachXBT trace, and it turned into the conversation a lot of people in the crypto world have been having for years — with their parents, their spouses, the friend who keeps their cap-table tokens on Binance because "it is easier." The arrests are a news event. The architecture is the story. If you remember one thing, remember that your phone number is not your friend.

FAQ

Can a hardware wallet still be drained through SIM-swap?

Not directly. A hardware wallet's signing keys never leave the device, so an attacker who controls your phone number cannot push a transaction without your physical confirmation on the device screen. The risk path becomes indirect — phishing a seed-phrase entry, supply-chain device tampering, or convincing you to approve a malicious transaction in a fake dApp UI. None of these are SIM-swap. The phone-number attack surface is decoupled from the signing flow, which is the entire point of using one.

Is a qualified custodian like Coinbase Custody safer than self-custody for normal users?

For normal users with five-figure holdings the honest answer is "differently risky." Coinbase Custody, Fidelity Digital Assets, and Anchorage Digital are regulated as trust companies — NY DFS for the first two, OCC federal charter for Anchorage — and their operational model assumes sophisticated attackers. The tradeoff is that you swap self-sovereignty for institutional process, and the minimum balances are not retail-friendly. For most readers, a hardware wallet plus a withdrawal allowlist on the exchange is the better fit.

Why do exchanges still allow SMS-2FA if it is this exploitable?

Two reasons, both unflattering. First, support cost — the recovery flow for users who lose their hardware key, authenticator app, or email access is expensive, and SMS is the cheapest fallback. Second, regulatory inertia — no major Tier-2 regulator has yet required phishing-resistant authentication as a licensing condition, including the Polish KNF that licenses Bitget. Until that regulatory bar moves, the default stays. Telling users to "turn it off in settings" is not a strategy. It is a liability transfer.

Does on-chain tracing actually recover stolen funds?

Sometimes. ZachXBT-grade tracing produces leads that exchanges can act on when laundered funds touch a KYC-enforced venue — Binance requires KYC at deposit, and most Tier-2 licensed venues do too. The recovery rate is meaningful for amateur attackers and approximately zero for professional ones who route through mixers, cross-chain bridges, and non-KYC exit ramps. Tracing is documentation, not prevention. It tells you what happened. It does not stop the next one.

Is a Ledger or Trezor still safe given past firmware controversies?

Both manufacturers have had security disclosures over the years, which I consider a feature rather than a bug — opaque manufacturers do not have public CVE histories. The relevant question is not "has there ever been a vulnerability" but "is the secure-element architecture sound today and is the firmware update process transparent." Both clear that bar. The GridPlus Lattice1 adds a co-signer abstraction layer that some users find worth the additional setup complexity.

What should I do tonight if I am worried about my exchange account?

Turn off SMS-2FA in every venue that lets you. Enable a hardware security key or an authenticator app instead. Set a withdrawal address allowlist with a multi-day timelock if the exchange supports it — Binance, Bybit, and OKX all do in some form. Move anything you are not actively trading off the exchange and into a hardware wallet you control. None of this requires technical skill beyond reading the settings page carefully. The whole thing is one evening of work.

Does using a non-KYC exchange like MEXC change the SIM-swap calculus?

It changes the laundering-recovery calculus, not the attack-prevention calculus. MEXC does not require KYC for deposits at its standard tier, which means stolen funds laundered through it are harder to claw back. From the victim's side it makes no difference whether the venue holding your account is KYC'd — the attacker is going after the phone number, not the compliance posture. The defense is the same: kill SMS-2FA, register a hardware key, lock the withdrawal allowlist.