How a SIM swap stole $23.8 million: the phone number that unlocked everything
In 2018 a crypto investor lost about $23.8 million without ever losing his phone. A crew simply got his phone number moved to a SIM card they held.[1] This case file covers how a stolen phone number opens accounts, how one of the people involved ended up with a 12-year sentence, and the control that would have stopped it.
What happened
In 2018 a group of people targeted a cryptocurrency investor. They arranged for his mobile phone number to be linked to a SIM card in their possession, so that calls and texts meant for him went to them instead.[1]
With control of his number, the group got into his accounts and took about 3 million cryptocurrency tokens, worth roughly $23.8 million at the time.[1] The person reported to be the ringleader was a 15-year-old at the time.[1]
Nicholas Truglia, a Florida man then in his early 20s, played the money role. The stolen tokens were sent to his account, where he converted them into bitcoin and split the proceeds among the people involved. He kept about $673,000 for himself.[1][2]
How it worked
A SIM card is what ties a phone number to a physical phone. Carriers can move a number to a new SIM, which is useful when a customer loses a phone. A SIM swap is when a criminal gets that transfer done without the real owner's permission, often by persuading or paying someone at the carrier, or by passing its identity checks with stolen personal details.
Once the number moves, the victim's phone goes quiet and the criminal's phone starts receiving everything. That matters because many online accounts use a text message code as the second step of logging in, or as the way to reset a forgotten password. If the text goes to the wrong phone, the second step protects nothing. In this case, taking over the number was the key that let the group reach the investor's accounts.[1]
The victim later sued his mobile carrier over its security. A California judge dismissed his claim for $200 million in damages in 2020 but allowed other parts of the case to continue.[1]
What it cost
Truglia was arrested in 2018 and was also sent to California to face separate charges over a different SIM swap involving about $1 million.[1] On December 2, 2022, he was sentenced to 18 months in prison for his role in the $23.8 million theft and ordered to repay more than $20 million within 60 days.[1] The alleged ringleader separately agreed in a civil settlement in November 2022 to pay $22 million.[1]
Truglia did not pay. Court records showed he had more than $53 million in assets, and after his release he moved money and bought luxury goods. He was detained again in May 2023, released in November 2024, and still made no payments.[2] Prosecutors pointed to a video interview in which he suggested he could keep stolen crypto even after a long prison term.[2]
In July 2025 a judge resentenced him to 12 years in prison, well above the 51 to 63 months that federal guidelines recommended, citing his refusal to pay and his efforts to hide assets.[2]
The missing control
The missing control: multi-factor sign-in that does not rely on text messages, backed by a port and SIM lock on the phone account. An authenticator app or hardware security key stays with the owner even if the phone number is stolen, and a carrier lock makes the number itself far harder to move.
Either layer would have broken this theft. With app-based or key-based sign-in, hijacking the number would not have delivered the codes needed to get into the accounts. With a carrier PIN or lock that blocks SIM changes and number transfers without extra verification, the number would have been much harder to hijack in the first place. The accounts treated the phone number as proof of identity, and the phone number turned out to be the weakest link.
What to do in your business
- Move off text message codes. For email, banking, payroll and admin accounts, switch 2-step sign-in to an authenticator app or security key wherever the service allows it.
- Lock your mobile accounts. Ask your carrier to add a PIN and turn on any SIM or number-transfer lock for every company phone and the owner's personal line.
- Remove phone numbers as a recovery option. Where a service lets you reset a password by text, replace that with backup codes kept in a safe place.
- Treat sudden loss of signal as an alarm. Tell staff that if their phone unexpectedly shows no service, they should call the carrier from another phone right away.
- Keep personal details off public pages. Limit what owners and finance staff share online, since birthdays, addresses and phone numbers help criminals pass carrier checks.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.