The U.S. Department of Justice (DOJ) has initiated civil forfeiture proceedings to recover more than $5 million in Bitcoin obtained through SIM swapping attacks between October 2022 and March 2023. The attacks targeted five victims across the United States, with criminals exploiting mobile authentication vulnerabilities to gain control of phone numbers and intercept two-factor authentication codes to facilitate cryptocurrency transfers. The case follows a broader pattern of escalating SIM swap attacks that cost victims $48 million in 2023 alone.
According to the DOJ’s investigation, the stolen cryptocurrency was tracked to online casino wallets, where perpetrators used circular transactions as a laundering technique. The method involved conducting multiple transfers within casino-related accounts to obscure the origin of the funds. The use of online gambling platforms for money laundering has prompted many casinos to implement mandatory two-factor authentication requirements to enhance security measures.
“The stolen funds were traceable to online casino wallets, with perpetrators using circular transactions to launder criminal proceeds,” said U.S. Attorney Jeanine Ferris Pirro in announcing the civil forfeiture complaint.
SIM swapping has emerged as a significant threat vector in cryptocurrency theft, exploiting vulnerabilities in mobile carrier security protocols. The technique involves criminals gaining unauthorized access to victims’ phone numbers, which are commonly used for authentication in cryptocurrency transactions and wallet access. In response to these threats, some carriers like AT&T have introduced enhanced security features such as Wireless Account Lock to prevent unauthorized SIM transfers.
The DOJ’s action represents part of its broader initiative to address cryptocurrency-related crimes through civil forfeiture mechanisms. The department’s strategy includes tracing and recovering digital assets while disrupting the networks responsible for these schemes. The enforcement action comes as cryptocurrency platforms increasingly adopt more secure authentication methods, with some providers implementing passkey authentication systems to reduce reliance on vulnerable SMS-based verification.
The case encompasses attacks conducted over a six-month period, resulting in the theft of cryptocurrency assets from multiple victims. The perpetrators’ use of online gambling platforms for money laundering demonstrates the evolving tactics employed in cryptocurrency-related crimes, highlighting the need for enhanced security measures across both telecommunications and financial services sectors.