Crypto news

11.08.2026
17:33

American woman found herself at the center of a $5 million cryptocurrency theft scheme: details revealed

Analyst ZachXBT has revealed the identity of American Tiffany Milanovich, involved in a series of cyberattacks in which attackers stole at least $5 million in digital assets. The scheme was built on fake calls purporting to be from crypto service support teams.

Milanovich played the role of a "call operator" in an organized group. She called victims, posing as a tech support employee, and convinced them to hand over control of their funds. After draining accounts, she recorded videos mocking the victims, indicating a cynical approach to her activities.

Attack Mechanics

The group operated through fake websites mimicking the interfaces of hardware wallets and centralized exchanges. The phishing infrastructure was provided by accomplices under the pseudonyms "bled" and "harm." One attack in June 2026 led to a loss of $1.2 million in Bitcoin and Ethereum: the victim lost funds from a Trezor wallet after receiving a fake email from BitcoinIRA signed with the name Patricia Massie. Notably, a significant portion of the stolen assets has not yet been withdrawn and remains on traceable addresses.

In October 2025, the group struck again: a victim lost $500,000 in BTC after their Coinbase account was hacked. According to the data, Milanovich complained about her small share and even published screenshots of withdrawals, confirming her direct involvement in the distribution of funds.

Spending and Connections

Milanovich did not hide her expenses: on social media, she showcased purchases of luxury goods and casino bets made with the victims' money. Some of the "boastful" videos were edited to make the theft amounts appear even larger. The analyst also links her to John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities and was arrested in March on Saint Martin.

These cases are just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support staff and government agencies in 2025 alone, with losses exceeding $2.9 billion. According to Chainalysis, the number of such schemes in the crypto sector grew by nearly 1400% over the year.

My analysis: The rise in impersonation attacks is a troubling signal for the entire industry. Even experienced users fall for it when attackers combine social engineering with phishing. Key defenses are multi-factor authentication and cold storage, but most importantly—never trust incoming calls, even if they look official.