Your bank may soon stop sending six-digit codes via text for authentication, thanks to a new cryptographic technology designed to enhance security and reduce fraud risks.
If you bank online, you are likely familiar with the routine: entering your password and then waiting for a six-digit code to arrive via text message. This extra step is intended to verify your identity, but scammers have found ways to exploit these codes. They may impersonate bank representatives, tricking you into revealing the code, or use phishing sites to capture it. Additionally, SIM-swap attacks can give criminals control over your phone number, making those texted security codes vulnerable.
According to the Federal Trade Commission, reported losses due to fraud reached $15.9 billion in 2025, up from $12.5 billion in 2024. Imposter scams were the most frequently reported type of fraud, accounting for over $3.5 billion in losses last year.
In response to these growing threats, Glide.id has introduced a new authentication system called MagicalAuth, which aims to reduce reliance on SMS one-time passwords (OTPs). Currently in public beta, this cryptographic authentication method is compatible with major carriers such as AT&T, T-Mobile, and Verizon, and is available on both iOS and Android devices. However, banks and other services must integrate this technology before users can experience it during logins.
MagicalAuth operates differently from traditional SMS OTP systems. Instead of sending a code, it utilizes cryptographic credentials linked to the SIM or eSIM in your phone. Eran Haggiag, founder and CEO of Glide.id, explains that the system relies on a secret embedded in the SIM card, which never leaves the device, similar to the chip in a credit card.
During authentication, the bank or service can confirm the presence of the expected SIM through the carrier network, eliminating the need for users to relay a code. “After that, verification happens quietly in the background in a fraction of a second, so the experience is faster and smoother than waiting on a text,” Haggiag noted.
One concern with this technology is the potential for SIM-swap attacks, where a criminal gains control of your phone number by transferring it to another SIM. Glide.id has addressed this issue by monitoring for recent SIM changes before allowing authentication. “When that happens, we don’t allow the new SIM to authenticate for a short window,” Haggiag explained. This temporary pause gives the legitimate owner time to notice the issue and recover their number.
AT&T’s Shawn Hakl, SVP and head of product at AT&T Business, emphasized the importance of verifying recent SIM activity before sensitive logins. “If a phone number was recently moved to a new SIM or eSIM, that is an important signal,” he said. This information can prompt banks to require additional identity verification or temporarily pause transactions, which is crucial since SIM-swap fraud often relies on speed.
While MagicalAuth aims to eliminate the need for SMS codes, it does not completely eradicate the risk of fraud. Scammers can still manipulate individuals into authorizing transactions directly. Haggiag cautioned that stronger authentication does not eliminate social engineering tactics, which can be particularly effective when combined with AI-generated voices that make impersonation more convincing.
For users, the transition to MagicalAuth means fewer moments spent waiting for a texted code. If a user gets a new phone or replaces their SIM, the carrier may need to re-verify that the phone number and device are still correctly matched before allowing a sensitive login. In cases where verification cannot be completed, banks or apps should have fallback identity checks to ensure legitimate customers are not locked out.
Currently, Glide’s MagicalAuth works across major carriers, but it may not support all wireless customers, particularly those with smaller carriers or prepaid plans. The rollout of this technology is not universal, as banks must individually adopt it. Glide aims to encourage banks to move away from SMS authentication, making MagicalAuth the primary method for supported users.
In the meantime, users are encouraged to enhance their account security. If your bank still relies on texted codes, consider using passkeys, which are designed to resist phishing. Setting up a PIN or password with your carrier and checking for port-out protection features can also help safeguard your phone number.
In conclusion, while the introduction of SIM-based verification through Glide.id’s MagicalAuth could significantly enhance security by eliminating the need for texted codes, users must remain vigilant against other forms of fraud. Scammers continue to evolve their tactics, and maintaining awareness is crucial in protecting personal information and financial assets. As this technology develops, it has the potential to make online banking safer and more efficient.
For more information on this topic, refer to CyberGuy.

