Crypto news

11.08.2026
18:13

An American woman found herself at the center of a $5 million cryptocurrency theft: how the group operated

In the world of cryptocurrency crime, increasingly sophisticated schemes are emerging, and the latest incident is a clear confirmation of this. My analysis of the chain of events, published as part of an independent investigation, points to U.S. citizen Tiffany Milanovich as a key figure in the theft of at least $5 million from digital asset holders. This is not about code hacking or an exploit, but about classic social engineering perfected to a fine art.

The Mechanics of the Crime

Milanovich, according to my data, played the role of a "call operator." She called victims, posing as a customer support employee of crypto services, and convinced them to hand over control of their funds. After draining the accounts, she recorded videos mocking the victims. The scheme was well-oiled: the group, which included accomplices under the pseudonyms "bled" and "harm," created phishing sites imitating real platforms, while Milanovich provided the "human factor."

One of the attacks in June 2026 led to the loss of $1.2 million in Bitcoin and Ethereum from a Trezor hardware wallet. The attackers used a fake email from BitcoinIRA, signed with the name Patricia Massi, to gain trust. Notably, a significant portion of the stolen funds remains untouched to this day—the assets remain in on-chain wallets, which suggests possible inexperience on the part of the perpetrators or a wait for the right moment to launder them.

In October 2025, another victim lost $500,000 in Bitcoin from their Coinbase account. Milanovich, apparently, complained about her "small share" and even published screenshots of the withdrawals, indicating her active involvement in profit distribution.

Traces and Trends

My observations show that Milanovich did not hide her spending: luxury purchases and casino bets using the victims' money appeared in her social media. Moreover, she is connected to John "Lick" Dagita, who was previously suspected of stealing cryptocurrency seized by U.S. authorities. Dagita was detained in Saint Martin in March.

This case is just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support staff in 2025, with losses exceeding $2.9 billion. According to Chainalysis, the number of such schemes in the crypto sector grew by nearly 1400% year over year. It is obvious that the industry is facing a new wave of threats, where the main attack vector is not technology, but user trust.

My verdict: as long as investors rely on "hot" wallets and do not verify the legitimacy of calls, such groups will thrive. Hardware security is only half the battle; the other half is a cool head and total verification of any contact.