3 minBusiness
Banks may replace texted security codes with SIM-based authentication
A new authentication system called MagicalAuth uses cryptographic keys stored on SIM cards to verify identity, potentially replacing SMS one-time codes that scammers exploit.
Online banking may soon lose one of its most familiar rituals: the six-digit code sent by text message. A new authentication system, MagicalAuth, is now in public beta across major U.S. carriers and could replace SMS-based verification with a method that relies on the cryptographic key embedded in your phone's SIM card.
The system, developed by Glide.id, is designed to eliminate the vulnerabilities that have made texted codes a favorite target for fraudsters. Scammers often pose as bank representatives to trick customers into reading codes aloud, use phishing sites to harvest them, or launch SIM-swap attacks to take control of a victim's phone number. The Federal Trade Commission reported that Americans lost $15.9 billion to fraud in 2025, up from $12.5 billion the previous year, with imposter scams alone accounting for more than $3.5 billion in losses.
MagicalAuth works differently. Instead of sending a code that a user must read and type, the system uses a cryptographic credential stored on the SIM or eSIM. During login, the bank or service can ask the carrier network to confirm that the expected SIM is present, without requiring the user to relay any secret. Eran Haggiag, founder and CEO of Glide.id, described the approach as similar to the chip in a credit card: the secret never leaves the SIM.
For consumers, the process is designed to be invisible. There is no app to download, no setting to change, and no enrollment step. The first time a user encounters MagicalAuth, a consent screen explains that their phone number and device possession are being used for verification. After that, authentication happens in the background in a fraction of a second, faster than waiting for a text message to arrive.
The system also addresses SIM-swap fraud, a growing threat in which criminals move a victim's phone number to a new SIM to intercept codes. Glide says MagicalAuth monitors for SIM changes in real time. If a number moves to a new SIM, the system blocks authentication for a short window, giving the legitimate owner time to notice the problem and recover the number. AT&T, one of the carriers supporting the beta, says its network can provide information about recent SIM activity before a sensitive login is approved, allowing banks to require additional checks if a number was recently moved.
Banks and other services still need to integrate MagicalAuth before customers encounter it during a login. The beta is available across AT&T, T-Mobile, and Verizon on both iOS and Android. While the technology could reduce the risk of SIM-swap attacks and phishing, experts caution that social engineering remains a threat. Scammers can still impersonate bank employees, and AI-generated voices can make those calls more convincing. Stronger authentication reduces the attack surface, but it does not eliminate the human factor.
