By Abigail Mbah
A viral claim circulating on X has sparked fresh debate about whether lending your phone’s hotspot to a stranger could drag you into a cybercrime investigation. On 25 August, a user known as Talk2veee posted that sharing a hotspot risk implicating the host because “it’s your IP address and everything that will pop up if they are being tracked.”
The caution is not limited to social media. At Ikeja Mall one afternoon, a user known as Adekunbi (@Adhekunbi) was approached by a woman who asked her to turn on her hotspot because she was out of data. Adekunbi offered instead to buy data for her directly from her bank account and asked for the number. The woman claimed she could not remember it because she had just gotten the line, then quietly walked away. “She wan run me street she no know say me sef i be street,” Adekunbi later wrote, capturing the wariness many now feel about handing over network access to strangers.
Replies to the original post quickly split. Some users warned that police or the network provider would first contact the number linked to the connection. Others pushed back, pointing out that Nigerian mobile networks already share public IP addresses among many customers through a system called Carrier-Grade NAT (CGNAT).
To cut through the noise, Technext spoke with two telecom engineers and a digital rights lawyer. Their explanations clarify both the technical reality and what Nigerian law actually requires.
How hotspot sharing works in practice
When someone connects to your phone’s hotspot, your device assigns them a private IP address—typically in the 192.168.x.x range. Your phone then acts as a router. Using Network Address Translation (NAT), it forwards the guest’s internet traffic through its own cellular connection.
From the outside world, websites, servers, or investigators, the traffic appears to originate from your phone’s public-facing IP address. The guest’s private address stays hidden inside the hotspot network.
Arinzechukwu Miracle Okoli, an electrical and electronic engineering graduate focused on wireless and telecom systems, likens it to a residential building. The public IP is the street address visible to everyone outside. Each connected device gets its own internal flat number (the private IP). Your phone is the doorman: it stamps outgoing requests with the public address and routes replies back to the correct device.
Nigerian operators such as MTN and Airtel add another layer with CGNAT. Because public IPv4 addresses are limited, the networks share a single public IP among multiple unrelated subscribers at the same time.
Exact sharing ratios are not published and change with network load, but the principle is the same: the public IP linked to your phone may already be used by other customers before anyone joins your hotspot.
Both engineers; Chukwuka Chijioke Jerry and Okoli emphasised that a public IP address by itself cannot identify a single subscriber, let alone the person who used a particular device. Investigators usually need additional data such as precise timestamps and port numbers to narrow the connection to one account. Even then, the trail points to the subscription, not necessarily the individual who was online at that moment.
Telcos generally cannot see which specific devices are connected to a customer’s personal hotspot. That detail, if recorded at all, sits on the host’s phone rather than in the operator’s systems.
What the law requires
Digital rights lawyer Muhammed Bello Buhari, founder of Internet for Rights and NAFASI Project Officer at Magamba Network, confirmed that agencies such as the Economic and Financial Crimes Commission (EFCC) and police cybercrime units routinely contact the registered account holder when an investigation leads back to a SIM or data subscription. Being the first person, they speak to does not mean automatic guilt.
“Nigerian criminal jurisprudence does not recognise vicarious or automatic criminal liability for simply owning an internet subscription,” Buhari said.
The Constitution’s presumption of innocence under Section 36(5) still applies. Prosecutors must prove both the act and the intent, typically by linking device forensics, login records and other digital evidence to a specific person. Computer-generated evidence must also meet the certification standards in Section 84 of the Evidence Act.
Buhari flagged a related everyday risk: second-hand phones, laptops or routers bought from unverified sellers. These devices carry unique hardware identifiers such as IMEI numbers.
If a device was previously stolen or used in fraud, it may still be flagged in security databases. An unsuspecting buyer who inserts their own SIM or connects the device to their network can face questioning until they produce proof of legitimate purchase, receipts or a bill of sale, showing they acquired it after any criminal activity.
In short, sharing a hotspot does not transfer criminal responsibility. It can, however, make the account holder one of the first people investigators contact. The same applies to second-hand devices that carry residual flags.
Everyday encounters like the one at Ikeja Mall show why many people now think twice before saying yes. Understanding how IP addresses, CGNAT and evidence rules actually work helps separate online alarm from legal reality.



