Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key if you can.
The craziest one was two people at another firm were sending each other a lot of money, and sent the address over Telegram. The hacker manipulated the address in the message - they checked after the (failed) transaction and the address sent was different than the address in the message received! I think the most likely cause was that the receiver's computer was rooted and the application itself was manipulated on the device, rather than the message contents changed en-route. This is why I recommend both visual and audio confirmation when sending large amounts.