Earlier quoted context omitted.
Coinbase themselves called it "a flaw in Coinbase’s SMS Account Recovery process". [1] I don't think they would have used that phrasing if it were individually simjacked phones. [1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...
With only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny." The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special…
How is it possible to update the SMS recover protocol to prevent sim swapping?