Crypto Thief's Prison Sentence Extended to 12 Years After Failing to Repay $20M

A hand banging a gavel.

A New York court has significantly increased the prison sentence for Nicholas Truglia, a 27-year-old convicted cryptocurrency thief, from 18 months to 12 years after he failed to repay over $20 million in court-ordered restitution to his victim. The case represents one of the most significant prosecutions related to SIM swapping attacks, which have seen a dramatic surge in recent years.

Truglia was originally convicted of stealing cryptocurrency from Michael Terpin, CEO of Transform Group, through a SIM-swapping scheme. The initial 2022 sentence included 18 months in prison, three years of supervised release, and an order to pay more than $20 million in restitution. The conviction follows a pattern of similar high-profile cryptocurrency thefts, including a recent $37 million theft by a Canadian teenager using similar techniques.

During a resentencing hearing, Judge Alvin K. Hellerstein imposed the extended sentence after determining that Truglia had made no effort to repay the stolen funds, despite evidence suggesting he possessed assets valued at over $61.8 million. “You’d rather be in jail than part with ill-gotten money,” said Judge Hellerstein. “The fact that you didn’t pay a single cent indicates to me that it’s all a sham.”

The crime involved a SIM-swapping technique, whereby Truglia manipulated mobile carriers into transferring Terpin’s phone number to a new SIM card. The transfer enabled him to gain unauthorized access to the victim’s phone and associated cryptocurrency accounts. SIM swapping has become increasingly concerning for mobile carriers and security experts, leading to enhanced security measures such as T-Mobile’s implementation of improved SIM Protection features.

The vulnerability of traditional SMS-based two-factor authentication to SIM swapping has prompted cybersecurity experts to recommend more secure authentication methods. Major technology companies, including Google Cloud, are moving toward mandatory multi-factor authentication to better protect users from such attacks.

The case has drawn attention to legal questions surrounding cryptocurrency fraud, double jeopardy considerations, and the enforcement of restitution orders in digital asset cases. The substantial increase in sentence length represents a judicial response to non-compliance with court-ordered financial obligations in cryptocurrency-related criminal cases.

Sources: USA Herald, Cointelegraph, Goonus Insights, Decripto, Law360