Share this article

Friend.Tech Users Targeted by SIM Swap Attack, Several Ether Drained

Users tie Friend.Tech accounts to real-world X profiles and phone numbers - which increases security risks.

Updated Oct 5, 2023, 6:31 a.m. Published Oct 3, 2023, 11:41 a.m.
(Camilo Jimenez/Unsplash)
(Camilo Jimenez/Unsplash)

Some Friend.Tech users reported that they were the victim of SIM swap attacks over the weekend with the attackers successfully draining thousands of dollars worth of tokens.

The Friend.Tech code itself was not exploited. No users are at immediate risk. The application lets holders buy "shares" of people who hold an account on X which grants buyers certain privileges.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

SIM Swap attacks are a common occurrence and happen when criminals take over control of a mobile phone by tricking service providers to connect that phone number to a SIM card in the hacker’s possession. Swapped phones can then be used for fraudulent activity.

At least two users claimed that were targeted in a SIM swap attack which allowed exploiters to drain over 42 ether , worth nearly $70,000 at current prices, over separate attacks.

“If your Twitter account is doxxed to your real name, your phone number can be found, and this could happen to you,” posted @darengb, a user who got impacted. Their phone carrier is Verizon.

Social application Friend.Tech has become one of the most popular crypto platforms this year, despite the bear market, generating steady revenues and profits for its creators. The application amassed over 100,000 users in under two weeks after going live, as previously reported.

However, security risks remain a large cause of concern for any crypto platform. Hackers may employ techniques from smart contract manipulation or flash loan attacks, to using a traditional method to exploit wealthy users.

Some Friend.Tech users have suggested added security features, such as 2FA, a common SMS or code-based authentication service, that may prevent a repeat of such attacks in the future.

"The SIM swap attack on FriendTech users is a great reminder of the importance of strong security measures, especially for accounts containing valuable digital assets," said Eran Karpen, Co-Founder and CTO at Unplugged, in a message to CoinDesk. "SMS, a technology developed in the 1980s, is relatively simple and vulnerable to attack. In the FriendTech case, the cell carriers were the attack vectors and were tricked into redirecting your phone number to a SIM card they controlled. Two-factor authentication (2FA) with an authenticator app, rather than SMS, authenticates on the device, not the cell carrier, and can mitigate the attack."

"An alternative solution will be to use a secondary "secret" SIM for 2FA via a phone that supports dual SIM or e-SIM. That way, you refrain from using your main SIM attached to your publicly known phone number," Karpen added.

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

MegaETH mainnet to go live Feb. 9 in major test of ‘real-time’ Ethereum scaling

(MegaLabs)

This follows its October 2025 $450 million token sale that was heavily oversubscribed.

What to know:

  • MegaETH, the much-watched high-performance Ethereum layer-2 network, announced that its public mainnet will go live Feb. 9, marking a major milestone for a project that has gained a lot of attention in the scaling landscape.
  • MegaETH positions itself as a “real-time” blockchain for Ethereum, designed to deliver ultra-low latency and massive transaction throughput.