SMS codes are the most common form of two-factor authentication on crypto exchanges, and the weakest. The problem is not only SIM swapping, which the FBI has recorded falling for three years. It is real-time phishing, and against that neither SMS nor an authenticator app helps.