A look at the booming market for bots that steal 2FA codes, often using SMS services like Twilio, to break into Coinbase, Amazon, PayPal, and bank accounts
VICEJoseph Cox
Context & Ripple Effects
This report closes a loop that VICE opened months earlier, when a hacker paid just $16 to a company called Sakari to reroute a reporter's texts and walk straight through his SMS-based logins. What was then a one-off demonstration has since become an industrialized market: bots that automate code interception against Twilio-style SMS plumbing, aimed at Coinbase, Amazon, PayPal, and bank accounts.
The losses are no longer hypothetical — Coinbase disclosed that a threat actor exploited its SMS multi-factor authentication to steal cryptocurrency from 6,000 customers over roughly three months, and Twilio later confirmed attackers used its own breach to generate login codes for Authy users. The bot market described here is the retail layer of that same supply chain.
First-order effects
Coinbase, Amazon, PayPal, and consumer banks face automated account-takeover attempts at scale, with SMS 2FA functioning as the weakest door rather than a safeguard — Coinbase's 6,000-customer SMS MFA theft shows the direct financial exposure.
Twilio and similar messaging providers find their legitimate bulk-SMS infrastructure repurposed as attack tooling, putting their enterprise reputation and compliance posture on the line.
Second-order effects
Consumer platforms are pushed to deprecate SMS as a second factor in favor of app-based or hardware-backed codes, shifting authentication costs onto users and support teams while shrinking demand for carrier-grade SMS delivery.
Regulators face renewed pressure over who can buy SMS rerouting and messaging tools, following the Sakari case where a $16 purchase defeated a reporter's entire account stack.
Third-order effects
If SMS interception keeps scaling, the industry's trust model migrates away from anything routed through telecom networks — a shift already visible beyond codes, as scammers now bypass banks' KYC checks with stolen biometrics and virtual cameras (facial-scan bypasses), suggesting identity itself becomes the contested layer.
Telecom-adjacent intermediaries like Twilio and small carriers such as Fink Telecom — implicated when a whistleblower revealed 1M+ 2FA messages passing through it — become systemic risk nodes whose security failures propagate to every service relying on them for out-of-band verification.
The trend: Authentication is migrating off SMS and telecom-mediated channels entirely, as the same infrastructure that delivers codes becomes the cheapest way to steal them.
These bots are not just for SMS-based 2FA. Can work for app-based too such as Google Authenticator. Seen bots that target Amazon, PayPal, Apple Pay, Venmo, Bank of America, Chase, etc https://www.vice.com/... https://twitter.com/...
With bots that cost only a few hundred dollars, anyone can start getting around multi-factor authentication, a security measure that many members of the public may assume is largely secure. https://www.vice.com/...
Great reporting! This is among the most realistic phone scams I've heard to trick people into giving up credentials and 2FA codes. Innovating on MFA (and getting rid of pwds in the long run) is key. #infosec #2Fac https://twitter.com/...
“The bot is great for people who don't have social engineering skills,” one OTP bot seller said. Not everyone is “comfortable and persuasive on the phone you see.” https://www.vice.com/... https://twitter.com/...
The ecosystem of these OTP bots is already pretty varied. Contacted one in around August, it went dark response, but now points to another similar bot. https://www.vice.com/... https://twitter.com/...
The calls from the bot are persuasive. Someone is trying to use your PayPal account, please verify you didn't send that money. Enter the code we just texted you (at same time, hacker triggers a legit 2FA code from PayPal). Sense of urgency likely effective https://www.vice.com/..…
The bots are super simple to use. Enter the target's number, and the platform you're trying to break into. Bot handles the rest and then gives you the code too. Here's what it looks like https://www.vice.com/... https://twitter.com/...
Contacted a wealth of orgs targeted by the bots (Amazon, Apple, PayPal, Bank of America, Chase, Coinbase) and asked if they support hardware security keys. Only one said they did, Coinbase. As piece says, raises Qs on whether platforms need to do more https://www.vice.com/... htt…
As for how they work, the bots use either Telegram or Discord. On the backend are sites like Twilio, which can send automated messages and calls. Twilio confirmed it is seeing OTP bots on its platform and taking them down https://www.vice.com/... https://twitter.com/...
Piece includes video of one of the bots in action. Very easy for anyone to use, now essentially any level of skill fraudster can try to bypass 2FA. Raises Qs on whether services need to do more than SMS/app 2FA https://www.vice.com/... https://twitter.com/...
New: underground trade of bots that steal your 2FA codes. Bot places convincing automated call to target. Victim enters code, gets fed to hacker instantly. Dramatically lowers the barrier of entry for bypassing 2FA, no social engineering skills needed https://www.vice.com/...
stop it Paypal, you're drunk. (How does a service that deals with money not think it's a terrible idea to let users log in with just SMS?) https://twitter.com/...
Scammers don't need social engineering skills to steal OTP / 2FA codes — a scam bot can do it for them. How to protect? 1. Orgs need to give users option for FIDO security keys 2. Educate on this scam method 3. Help others use FIDO keys if a match for them https://www.vice.com/..…
Automated voice theft of two factor codes under the guise of fraud prevention is a new, horrifying attack vector for users of SMS 2FA https://www.vice.com/...