New bank login technology using SIM cards seeks to take the place of SMS OTP codes

LastPass alerts users about a new phishing scam involving a counterfeit DocuSign page

If you do online banking, you’re likely familiar with the drill. You enter your password, then wait for that six-digit code that’s supposed to verify your identity. But here’s the thing—scammers have become adept at using those codes against us.

For instance, a phony bank representative might call you to coax you into reading that code aloud. Or a phishing website could trick you into entering it there. Even more alarmingly, a SIM-swap attack can give a criminal control over your phone number, making those texted security codes—well, accessible.

According to the Federal Trade Commission, reported losses due to fraud reached $15.9 billion in 2025, up from $12.5 billion in 2024. Imposter scams topped the list, with over $3.5 billion lost to this type of fraud in 2025.

However, there’s a new phone-based verification method that might change the landscape for these codes. Glide.id recently introduced the public beta of MagicalAuth, a cryptographic authentication system compatible with AT&T, T-Mobile, and Verizon on both iOS and Android devices. But, for it to be integrated into your banking experience, banks and services need to adopt this technology first.

So, let’s break down how this works and what it could mean for your banking experience in the future.

Understanding the Vulnerability of Six-Digit Codes

Your bank sends you a one-time password via text, often called an SMS OTP, expecting you to enter it as proof of access to your number. The thing is, “a texted code is a shared secret,” says Eran Haggiag, CEO of Glide.id. The creation and transmission of that code involve several steps—each one a potential point for interception or coercion.

MagicalAuth takes a different route. Instead of sending you a code, it utilizes cryptographic credentials embedded in the SIM or eSIM of your phone. “It relies on a secret that’s built into the SIM in your phone and never leaves it,” Eran explains, similar to what you might find in a credit card chip.

Authentication involves the bank confirming the expected SIM is present via the carrier network, rather than relying on you to communicate a secret. This method allows for a faster, smoother process, eliminating the need for a code and the waiting game that often comes with it.

The Impact of SIM-Based Verification on Banking

Each SIM has a carrier-issued cryptographic key, which MagicalAuth uses to tackle authentication challenges. There’s no need for an app download or user configuration; the integration takes place on the bank’s side. The first time you encounter the system, you would see a consent screen indicating that your phone number and physical device are being used for verification. After that, the process operates quietly in the background, significantly speeding things up.

Addressing the SIM-Swap Risks

A reasonable concern arises: if this technology hinges on the SIM for verification, what happens during a SIM-swap attack? In such cases, a criminal can transfer your number to a new SIM, rendering you unable to receive calls or texts while the attacker uses your number on their own device. Glide claims that MagicalAuth actively monitors for SIM changes in real-time, preventing authentication for a brief period after a number transition. This pause allows the legitimate owner to notice and resolve any issues, thus making it harder for stolen numbers to compromise your accounts.

Additionally, carriers like AT&T can provide signals about recent SIM activity to help banks determine the legitimacy of a login attempt, making swift scams more challenging to execute.

Can Scammers Still Deceive You?

Unfortunately, stronger verification won’t completely eliminate social engineering. A scammer could still impersonate your bank, and with the rise of AI-generated voices, these calls can feel increasingly authentic. I’ve even discussed various manipulative tactics with banking security experts—there are still points of vulnerability. However, with MagicalAuth, the one-time code becomes a non-issue, as there’s nothing for scammers to steal or phish.

As Eran points out, while it enhances security, it doesn’t eradicate fraud entirely. Scammers can still persuade people to transfer money voluntarily, but the system is designed to reduce some of the easier tricks they usually exploit.

Switching Your Phone or SIM

When you replace your phone, or switch to a new SIM or eSIM, that can affect the verification process. Your carrier may need to re-evaluate that your number and device match before processing sensitive logins. Although typically, this step occurs behind the scenes, if discrepancies appear, the bank may require additional verification, which can feel like a hassle but serves as an important safeguard against fraud.

Current Availability of MagicalAuth

Right now, Glide has made MagicalAuth available for iOS and Android on AT&T, T-Mobile, and Verizon. However, not all customers will be able to use it just yet. Smaller carriers and prepaid users might not have access at this stage. The practical rollout timeline depends greatly on individual banks’ decisions to implement this new system.

How to Stay Safe Until then

As banks weigh the switch to SIM-based verification, there are still steps you can take to protect your accounts that rely on text codes.

1) Use Passkeys When Possible

If your bank supports them, consider using passkeys. They’re built to resist phishing attempts since there’s no code to type in that could be captured by a malicious site.

2) Secure Your Wireless Account

Set a PIN or password for your account with your carrier. Check for features like number locks that can help prevent unauthorized SIM transfers.

3) Keep Verification Codes Private

If your bank still sends codes, never share them. If a caller claiming to be from your bank requests one, hang up and call back using an official number.

4) Take Phone Service Interruptions Seriously

A sudden loss of phone service could indicate malicious activity; don’t hesitate to reach out to your carrier if this happens.

5) Consider Identity Theft Protection

Identity theft protection services can help monitor and address any unauthorized use of your information. Freezing your credit can also prevent anyone from opening new accounts in your name.

6) Use Strong Antivirus Software

Even with improved security measures, scammers will still try phishing. Good antivirus software can serve as a crucial line of defense against malware.

7) Limit Your Personal Information Online

Reducing the personal information available online can deter scammers who might otherwise use that data to manipulate you. Data removal services can help in this regard.

Final Thoughts

Scammers pulling off fake bank calls isn’t a new trend. They often aim to coax you into sharing security codes that land in your texts. But with the advent of SIM-based verification, if there’s no code sent, scammers lose a significant tool in their kit. I also appreciate that this approach doesn’t require you to navigate another app or be an expert in security.

That said, stay vigilant; convincing scammers can still mislead you into transferring money yourself, especially with sophisticated technologies at their disposal. Removing that six-digit code, however, could substantially hamper their ability to take over accounts.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News