WhatsApp Signal Telegram account hijack through SIM swap
A SIM swap transfers your phone number to a new SIM card in an attacker's control. Once that happens, any messaging app that relies on SMS or phone-number-based login becomes vulnerable. The three most popular encrypted messaging apps - WhatsApp, Signal, and Telegram - each have different vulnerabilities and different protections.
WhatsApp: SMS verification code takeover
WhatsApp ties each account to a phone number. When you reinstall WhatsApp or log in on a new device, the app sends a six-digit SMS verification code to that number. An attacker who controls your SIM receives that code. They enter it, and WhatsApp activates on their device. Your own session gets logged out simultaneously.
WhatsApp offers two-factor authentication with a six-digit PIN. This PIN is separate from SMS. It is required whenever the account is registered on a new device, even if the SMS code is successfully entered. Without this PIN, the takeover fails. Enabling it blocks the most common SIM swap hijack.
WhatsApp also has "two-step verification recovery email." If you forget your PIN, a recovery email can reset it. This creates a possible bypass if the attacker also controls your email account. Protect both.
Signal: re-registration risk without Registration Lock
Signal is widely considered the most private mainstream messenger. Its account recovery system relies on the phone number for re-registration. If an attacker uses your phone number to register on Signal, the app sends an SMS verification code to that number - which now goes to the attacker.
The critical protection is Signal's Registration Lock. This feature requires a PIN to re-register your phone number with Signal. Without the PIN, even with the SMS code, the attacker cannot complete registration. Registration Lock is disabled by default. You must turn it on in Signal settings.
If you lose both your SIM and your Registration Lock PIN, recovery is difficult. Signal does not offer PIN recovery. You must either know the PIN or wait 30 days - after which the PIN requirement expires and the number can be re-registered. A determined attacker who controls your SIM can then wait the month out.
Signal also offers the option to remove your phone number from your Signal profile. Your Signal ID becomes a unique username. This does not change the fact that the phone number is still used for account registration. The username is merely a display alias.
Telegram: SMS login and cloud access
Telegram stores your messages in the cloud by default. It does not use end-to-end encryption for regular chats - only for "Secret Chats." This design means logging into Telegram on any device gives access to your full message history, groups, and contacts.
Telegram's login process begins with an SMS code sent to your phone number. Enter that code, and you are in. No additional step. This is the most bare-bones protection of the three apps.
Telegram offers two-factor authentication with a password. Enable it in Settings > Privacy and Security > Two-Step Verification. This password is required after the SMS code is entered. Without it, the attacker stops at the SMS code. With it enabled, your account remains secure even if the SIM is swapped.
Telegram also has "Login Approval" for new devices. When enabled, you receive a notification in your Telegram app whenever a new device tries to log in using your number. You can approve or reject it remotely. This provides a real-time warning that someone is attempting access.
Telegram allows setting up "Active Sessions" management so you can see and terminate all sessions from your current device. A SIM swap attacker cannot do this unless they first pass two-factor authentication.
Privacy and extortion risks
A hijacked messaging account exposes more than just chat history. Attackers can read private conversations, download shared photos and files, and impersonate you to your contacts. The impersonation risk is often more damaging than the reading.
Attackers use the hijacked account to message your family, friends, or colleagues asking for money or personal information. They claim you are in an emergency. Victims trust the message because it comes from your real account.
Sometimes the attacker extorts you directly. They threaten to leak intimate conversations or photos to your contacts or employer. If you used the app for business, stolen messages can contain financial details, trade secrets, or client data.
For Signal and WhatsApp, encrypted backups stored on your device may also be accessible if the attacker has your phone passcode. For Telegram cloud chats, all history is accessible immediately upon login.
What you can do
Enable WhatsApp two-step PIN. Turn on Signal Registration Lock. Set a Telegram two-factor password. These three actions stop the attacker dead even after a SIM swap. They are not difficult. Many people simply skip them.
If you lose your number to a SIM swap, act before the attacker completes a login on any app. Contact your carrier immediately. Use another device to log into each app and force-logout any sessions. Change your account passwords. Do not wait.
The risk is real. The fix is simple. The time to act is before the swap happens.
Not financial advice. rosiesol.xyz publishes market data and general information about Rosie. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.