Body: I had a friend get hit by a SIM swap last month. The attacker convinced his mobile carrier to port his number to a new SIM, then used SMS recovery codes to get into his email. From there, it was a short path to his community-hub account. They drained a balance he had been waiting to withdraw. Cleaning it up took weeks, and it made me rethink my own setup. SMS-based two-factor authentication is still the default at many community-hubs, but it is a serious vulnerability. Here is what I have changed since then, and what I think is worth considering if you play regularly. Check what your community-hub actually supports for two-factor authentication The first step is to look at the security settings inside your community-hub account. If the only option is SMS, treat that as a weak point. SMS codes travel over the phone network, and a SIM swap means someone else receives them. Email codes are slightly better only if your email account is locked down with its own strong two-factor method. Authenticator apps such as Google Authenticator or Authy are the standard for a reason. They generate codes on your device, not over the air. If your community-hub supports an authenticator app, switch to it immediately. The setting is usually under account security or login verification. If the community-hub only offers SMS, you can still reduce the risk with the steps below, but I would think twice before keeping a large balance there. Put a port-out PIN on your mobile carrier account Your mobile carrier is the next layer. Most major carriers let you set a PIN or passcode on your account. This is separate from your phone unlock code. It is a verbal password you must give to customer service before any account changes, including porting your number to a new SIM. Call your carrier and set it up. Make it unique, and do not use something visible on social media. Some carriers also let you enable a port freeze or number lock, which blocks porting until you remove the freeze yourself. I enabled both after my friend's incident. It takes ten minutes and closes the easiest door. Secure your email before anything else Your email is the master key. If someone gets into it, they can request password resets for your community-hub and many other services. Use a strong, unique password for your email, and enable the strongest two-factor method it offers. An authenticator app is good. A hardware security key such as a YubiKey is better if your email provider supports it. I moved my main email to app-based codes and removed SMS recovery entirely. That single change makes a SIM swap far less damaging, because the attacker cannot use my phone number to reset my email password. Treat security questions as passwords, not facts Security questions based on your mother's maiden name, first pet, or childhood street are easy to find online. I now store fictional answers in my password manager. For example, my first pet answer might be a random phrase that has nothing to do with any real pet. This prevents someone from calling support and using public information to pass a verification check. If your community-hub or email provider still uses security questions, change the answers to something only you know, and save them in your password manager rather than trying to remember them. What I would skip I would not rely on SMS as your only second factor anywhere, especially for email or financial accounts. I would also avoid reusing passwords across community-hubs, because a breach at one site can expose your login elsewhere. A password manager makes unique passwords practical. Finally, do not assume a small balance makes you safe. Attackers often test accounts with small deposits first, then return later when you have more funds. No method is perfect, but layering these steps moves you from low-hanging fruit to a much harder target. For a forum like ours where we talk about session habits and session-budget management, account security is a foundational habit worth getting right. What is your setup? Anyone using a hardware key for their community-hub or email?