Device and Account Hygiene for Solana Holders: SIM Swaps, 2FA and Hot Wallets
Your accounts are part of your wallet
Even self-custody leans on accounts: the email you used for an exchange, the carrier holding your phone number, the cloud account that backs up your phone. A thief who takes those can often reach the rest. This guide covers the layers around your wallet. For the wallet itself, see storing QNT safely.
Two factor methods ranked
CISA's phishing-resistant MFA fact sheet (October 2022) lists forms of multifactor authentication from strongest to weakest. At the top is phishing-resistant MFA: FIDO/WebAuthn and PKI-based. Next is app-based authentication with number matching or token-based codes. Weaker is app-based push without number matching, and SMS or voice codes sit among the most exposed. CISA describes threats including phishing, push bombing, SS7 exploitation (intercepting codes sent by text or voice) and SIM swap. It calls phishing-resistant MFA the gold standard, while noting that any MFA is better than none. The FTC similarly says two factor authentication makes it harder for scammers to log in even if they have your password.
Practical order for your exchange and email accounts: a hardware security key if supported, then an authenticator app, then SMS only if nothing else is offered. See hardware wallets for device basics.
SIM swap and port-out fraud
CISA defines a SIM swap as social engineering in which attackers convince a carrier to move your number to a SIM they control, giving them your calls and texts. A port-out is a similar transfer to another provider. A law firm analysis of the FCC's November 2023 order says wireless providers must verify customers before SIM changes and port-outs, notify customers before the change takes effect, and offer all customers a free option to lock their accounts against SIM changes and port-outs. I could not load the FCC's own page, so this rests on that secondary summary; ask your carrier how to turn on its lock. Steps:
- Ask your carrier for a number lock, port-out protection or account PIN.
- Do not use your phone number as the only way to recover email or exchange accounts.
- If your phone suddenly loses service unexpectedly, call the carrier from another phone straight away and tell your exchange.
Browser extension and computer risks
A wallet extension lives in the same browser where you open random links. I did not find a primary source quantifying extension risk, so treat this as common sense rather than a statistic: install only wallets from their official site, remove extensions you do not use, keep the browser and system updated, and avoid browsing risky sites in the profile that holds your wallet. The FTC advises automatic updates for security software and phone software. The FBI warns never to grant remote access to unknown people and notes fake support sites appear in online searches, so type addresses yourself or use bookmarks.
Hot wallet and savings
Split your holdings by purpose.
| Hot wallet | Savings wallet | |
|---|---|---|
| Use | Trying new apps and small buys | Holdings you rarely move |
| Keys | Software wallet on your phone or browser | Hardware wallet, offline backup |
| Connect to apps? | Yes, sparingly | Almost never |
| Amount | Only what you can afford to lose | The rest, per your own plan |
Never reuse one recovery phrase for both. A hot wallet draining should cost you only the hot wallet. See setting a memecoin budget.
Housekeeping that pays off
- Use a unique long password for each account, stored in a reputable manager.
- Back up phone and computer data, as the FTC advises, but never include your recovery words.
- Lock your phone with a strong passcode and enable automatic updates.
- Check connected apps monthly with the revoke routine.
Keep records for taxes too; see record keeping overview. This is education, not financial advice.
Sources and further reading
- CISA: implementing phishing-resistant MFA (October 2022)
- FTC Consumer Advice: how to recognize and avoid phishing scams
- FBI IC3 PSA: technical and customer support fraud
- Davis Wright Tremaine: FCC SIM swap and port-out rules (secondary summary)
Reported as of 2026-10-09. Device support, menus and fees change, so check the vendor pages before relying on any detail. This is education, not financial advice, and nothing here predicts any price. The QNT memecoin is independent of Quantinuum Ltd, the real company.
Frequently asked questions
Is SMS two factor still worth using?
It beats no second factor, and CISA says any MFA is better than none, but it lists SMS and voice among the most exposed because of SIM swap and SS7 attacks.
What is the strongest two factor method?
CISA calls phishing-resistant MFA, meaning FIDO/WebAuthn or PKI-based methods, the gold standard.
What is a SIM swap?
CISA describes it as attackers convincing a carrier to transfer your number to a SIM they control, which lets them receive your calls and texts.
Why use two wallets?
A small hot wallet limits the damage if you sign something bad, while savings stay offline.
Keep reading
- How to Store QNT Safely: Wallets and Security
Learn how to keep your QNT tokens secure on Solana: choose a wallet you control, back up the seed phrase offline and avoid common ways people lose funds. - Hardware Wallets for Solana Holders: What They Protect and What They Do Not
How a hardware wallet keeps keys offline, what signing on the device screen means, how Ledger and Trezor support Solana, and the blind signing trade-off. - A Revoke and Review Routine for Solana Token Delegations and Connected Apps
What a Solana token delegate is, why disconnecting a site is not the same as revoking, and a simple monthly routine to review approvals. - The 20 Point Holder Security Checklist for Solana Tokens
A printable 20 item self-custody checklist covering recovery phrases, devices, approvals, scams and accounts, with links to the deeper guides.
All How to buy and stay safe guides | Back to top | Search the site
Main pages: What is QNT? | Token information | How to buy | FAQ