TL;DR - A SIM swap can empty a wallet in minutes, but the address the crypto lands in still carries a traceable pattern that screening tools and exchanges can flag before it gets laundered.
On July 16, 2025, a federal judge cleared Michael Terpin's $24 million SIM-swap lawsuit against AT&T for trial, set for March 3, 2026, eight years after hackers hijacked his phone number and drained his crypto in minutes.
Most coverage of that case is about carrier liability: who pays when a phone company hands your number to a stranger. It skips the part that actually matters to anyone this happens to next. Once the coins leave your wallet, where do they go, and can anything be done about it before they're gone for good?
How a SIM Swap Actually Empties a Wallet
The attacker doesn't touch your device. They call your mobile carrier, pose as you, and port your number to a SIM card they control. From there they intercept the SMS codes your exchange or wallet app sends for two-factor authentication and password resets. Twenty minutes of social engineering at a phone store, and they own your number.
No malware. No phishing link.
Once the attacker has your number, they reset the passwords protecting your exchange account or hot wallet, add a withdrawal address they control, and pull the funds. Self-custody wallets without SMS-based recovery are safer, but any account tied to a phone number for login or 2FA is exposed the moment the swap happens.
Where Does the Stolen Crypto Go First?
Straight into a chain of wallets built to confuse anyone watching. The Department of Justice's 2026 forfeiture case over five SIM-swap victims traced this exact pattern: thefts between October 29, 2022 and March 21, 2023, with the stolen bitcoin routed through multiple wallets before consolidating into one address that funded a Stake.com casino account. Investigators counted at least 32 transactions in a single 48-hour window, March 20-22, 2023, all designed to break the paper trail.
The DOJ's 2026 forfeiture case traced stolen bitcoin through a consolidation wallet into a casino account, 32 transactions in 48 hours.
A casino deposit isn't an accident. Online gambling accounts convert crypto to cash with less scrutiny than most exchanges, which makes them a common exit ramp for stolen funds. That pattern is exactly what a screening pass on the receiving address would surface, long before any conversion happens.
Can Screening Catch It Before It's Laundered?
Yes, if someone runs the check. A block explorer shows the raw list of transfers in and out of an address, but it doesn't tell you whether that address has touched a mixer, a sanctioned entity, or a cluster of wallets already tied to theft. Screening a wallet with Plastron checks all three at once, across Ethereum and six other chains, and returns the exposure picture in one pass instead of a raw transaction list you have to interpret yourself.
Plastron's dataset currently tags over 3,900 labeled addresses by risk type, cross-checked against a live OFAC SDN list that has grown to 780 sanctioned crypto addresses as of this week. A wallet that received funds from a known SIM-swap consolidation address inherits that exposure the moment the transfer lands, the same way it would for stolen-funds exposure from any other hack.
The gap isn't technical. It's that most victims, and most exchanges receiving the downstream funds, never run the check until after the money has moved twice more.
What the Terpin Case Actually Settles
Nothing about recovering the coins. Terpin's suit argues AT&T is liable under the Federal Communications Act for handing his number to a hacker, not that the stolen crypto itself can be clawed back. A jury verdict, whenever it lands, sets a precedent for carrier negligence. It does nothing for the wallet the money sat in on its way to wherever it ended up.
Self-custody victims have it worse. There's no bank to reverse the transfer and no custodian obligated to investigate. The only lever left is tracing the destination address fast enough to flag it before an exchange or a casino cashes it out, which is a screening problem, not a legal one. Compare that to how 16 blockchains can freeze a wallet without an exchange in the loop at all; SIM-swap proceeds rarely touch one of those chains before they're already gone.
What To Do in the First Hour
Call your carrier immediately and lock the account against further SIM changes. Then contact every exchange where you hold funds and report the compromise before any linked withdrawal address gets added elsewhere.
Screen the withdrawal address the moment you spot it in your transaction history. Report the theft to the FBI's Internet Crime Complaint Center with that address attached. If the destination wallet later shows up in an exchange deposit, that report is what gets a freeze request taken seriously instead of ignored. The same logic applies to anyone who later gets a deposit flagged, worth checking against what actually triggers a high-risk flag versus a genuine hit.
An hour matters more than a lawsuit. The lawsuit takes years. The wallet moves in minutes.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.