Image Credits:Afrikons Media
Fintech

This Encryption Pattern Can Keep Mobile Money Apps Safe From SIM-Swap Fraud

Thandiwe Moyo1:45 PM SAST · August 7, 2026

Binding a wallet to a device-held key rather than a phone number defeats the attack outright, and two operators have now shipped it.

SIM-swap fraud works because the phone number is the identity. An attacker socially engineers a replacement SIM at a retail outlet, receives the one-time password, and empties a wallet before the victim notices their handset has lost signal. Losses across four African markets exceeded an estimated $70 million last year.

The countermeasure now shipping at two operators severs that link. At enrollment, the app generates a keypair in the handset's secure element; the private key never leaves the device and is not recoverable from a new SIM. High-value transactions require a signature from that key in addition to any SMS factor. Swap the SIM and the attacker gets the number, the OTP, and nothing they can spend.

"It is not a new idea, it is a deployment problem," said Kagiso Mahlangu, a security engineer who has advised two of the rollouts. "Every mid-range Android since about 2019 has the hardware. The obstacle was that operators did not want a recovery flow that could genuinely lock a customer out, and there is no way around that trade-off. You have to pick."

The recovery path is where implementations differ and where the residual risk sits: an in-person branch visit is secure and painful, while a remote re-enrollment reintroduces exactly the social-engineering surface the design removes. Operators that have chosen convenience are, security researchers warn, rebuilding the vulnerability one support ticket at a time.

Why the offline-first bet is reshaping African AI · The Build Loop

Topics:sim swapfraudencryptionauthentication

When you purchase through links in our articles, we may earn a small commission. This doesn't affect our editorial independence.



Thandiwe Moyo

Security Correspondent

Thandiwe Moyo covers cybersecurity, breaches, and the defenders trying to stay ahead of them for Afrikons. She has spent the last six years tracking financially motivated intrusion crews operating across the continent.

View Bio

Loading the next article