New SIM-based authentication may soon replace texted bank security codes
Glide.id has opened public beta for MagicalAuth, a cryptographic login system that uses a phone’s SIM to verify bank users, aiming to reduce reliance on SMS one-time passwords.
Scammers exploiting SMS one-time passwords have driven fraud losses into the billions, according to the Federal Trade Commission. In response, Glide.id launched the public beta of MagicalAuth, a cryptographic authentication method that relies on a secret embedded in a phone’s SIM or eSIM rather than sending a six-digit code. The system works by having the carrier verify that the expected SIM is present, using a cryptographic key to answer a challenge during login.
Carriers can also flag recent SIM swaps, temporarily pausing authentication to give the legitimate owner time to react. While the approach eliminates the need for users to read or type a code, banks must still integrate the API, and support is currently limited to AT&T, T-Mobile and Verizon customers on iOS and Android. Wider rollout depends on individual banks adopting the method, and fallback verification will remain for unsupported carriers or devices.
Why it matters
Replacing texted codes with SIM-based checks could curb a major avenue for banking fraud.
In this story
