Loading prices…
STKR NewsSTKR News0 of 3 free this month
Markets

SIM-Swap Fraudster Who Spent Stolen Crypto on Gold Grills and Dubai Trips Jailed

A recent prison sentence for a SIM-swapping accomplice highlights the persistent danger of phone-based security and why builders must move beyond SMS for identity verification.

Originally on Decrypt →
AB

Adrian Boysel

Contributor

Oct 9, 2026

4 min read

Photo illustration / STKR News

We have a tendency in this industry to treat security like a technical problem that can be solved with a better algorithm. But the reality is that the weakest link in your stack isn't your code—it is the local telecom store employee making fifteen dollars an hour. A recent sentencing in the UK serves as a blunt reminder of how fragile our digital wealth really is when tied to a legacy phone number.

The Anatomy of a Low-Tech Heist

Ajay Shinjin, a 21-year-old from London, was recently sentenced to three years and nine months for his role in a SIM-swapping scheme that netted nearly $265,000 in cryptocurrency. While Shinjin wasn't necessarily the mastermind, he was the point of contact for the stolen funds, helping to move assets after a coordinated attack on BT customers in late 2021.

The mechanics of the crime were frustratingly simple. By hijacking the mobile phone numbers of unsuspecting victims, the group bypassed two-factor authentication (2FA) for various crypto exchanges and wallets. Once they had control of the phone number, the rest of the security dominoes fell. They reset passwords, logged in, and drained accounts.

What followed was a stereotypical spending spree that feels almost like a parody of the 'crypto bro' lifestyle. Shinjin spent the proceeds on gold grills, high-end designer clothing, and luxury trips to Dubai. It is a story we have heard a hundred times, but the takeaway for founders isn't about the flashy spending—it is about the ease of the entry point.

The SMS Illusion

As builders, we often prioritize user experience (UX) over absolute security. We want to reduce friction. Using a phone number for account recovery or 2FA is the ultimate low-friction move. Everyone has a phone number. Everyone knows how to receive a text. But as this case demonstrates, SMS is not a security layer; it is an open door for anyone with enough social engineering skills to talk a customer service rep into porting a number.

We are still building on top of a legacy telecommunications infrastructure that was never designed to be the gatekeeper for millions of dollars in liquid assets. The BT customers involved in this case weren't targeted because they had weak passwords. They were targeted because their identity was tied to a piece of hardware—a SIM card—that can be cloned or moved with a single phone call.

What This Means for Founders

If you are building an application in the crypto or AI space right now, you have a responsibility to look at this case and ask yourself: "If my user loses their phone, can a thief take their life savings?" If the answer is yes, your security architecture is failing.

  • Deprioritize SMS 2FA: It is time to stop treating SMS as a primary security measure. Push users toward hardware keys like YubiKeys or app-based authenticators that are tied to a device's secure enclave rather than a carrier signal.
  • Implement Time-Locks: One of the reasons these heists are so successful is the speed of crypto. If Shinjin's team hadn't been able to move the funds instantly, the victims might have had a chance to freeze their accounts. Founders should consider mandatory delay periods for large withdrawals or changes to security settings.
  • Identity is Not a Phone Number: We need to shift the paradigm of identity toward decentralized identifiers (DIDs) or biometric-locked local storage. A phone number is just a leased identity from a corporation.

The Human Element

The investigation into Shinjin revealed that this wasn't just about technical prowess. It was about exploitation. The group targeted specific individuals, likely using leaked databases or social media footprints to identify high-value targets. This is a reminder that privacy is a subset of security. The less information a criminal has about who uses your platform and what they hold, the harder it is for them to execute a targeted SIM swap.

Shinjin was caught because he left a digital trail connecting his lifestyle to the stolen funds. But for every Shinjin that gets three years in prison, there are dozens of others who are smarter, more decentralized, and far more patient. We cannot rely on the police to recover these funds. In crypto, the moment the transaction is confirmed, the money is gone. The grills and the Dubai flights were just the final act of a tragedy that started with a simple text message.

Takeaway for the Weekend

Security is not a feature; it is a fundamental requirement. If you are a founder, stop trusting the telecom companies to protect your users. Transition your platform to WebAuthn or hardware-based security. If you are a user, go into your settings right now and remove your phone number as a recovery method. The convenience of SMS is not worth the risk of losing everything to someone who just wants a new set of gold teeth.


Read the original at Decrypt →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses