Crypto news

11.08.2026
18:48

An American woman found herself at the center of a high-profile $5 million crypto heist: the scheme, the victims, and traces of luxury.

The world of digital assets has once again been shaken by a brazen scam that exposed vulnerabilities in even the most protected wallets. At the center of the investigation is U.S. citizen Tiffany Milanovich, whom my colleague and analyst ZachXBT directly links to the theft of funds totaling at least $5 million. This is not about code hacking or smart contract exploits, but rather classic—yet no less devastating—social engineering.

Milanovich, according to my investigation, played the role of a "call operator" in a criminal group. Her task was to impersonate customer support staff of crypto services and convince victims to hand over control of their assets. After draining the accounts, she reportedly recorded videos mocking the victims—a detail that paints a portrait not just of a fraudster, but of a cynical criminal confident in his impunity.

Attack Mechanics: From Fake Emails to Empty Wallets

The scheme in which Milanovich participated was refined to the smallest detail. The group, operating under the pseudonyms "bled" and "harm," created phishing websites mimicking real platforms. Victims included owners of both hardware wallets and accounts on centralized exchanges. In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum stored on a Trezor. The attack began with a fake email purportedly from BitcoinIRA, highlighting the attackers' level of preparation. Notably, a significant portion of the stolen funds has still not been withdrawn from on-chain addresses, leaving a theoretical possibility for tracking them.

Another episode, dated October 2025, brought the group $500,000 in Bitcoin stolen from a Coinbase account. Milanovich, according to available data, even complained about her "small share" at the time and published transaction screenshots, indicating her active involvement in profit distribution.

Traces of Luxury and the Broader Threat Picture

What did Milanovich do with the stolen funds? Judging by her social media activity, she did not hesitate to spend money on luxury goods and gambling. Casino bets using victims' money, as well as "boastful" videos edited to exaggerate the scale of the thefts, became her calling card. Moreover, my investigation reveals a connection between Milanovich and John "Lick" Dagita, who was arrested in Saint Martin in March after charges related to the theft of cryptocurrency seized by U.S. authorities.

This case is just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support and government agency staff in 2025 alone, with losses exceeding $2.9 billion. Chainalysis data indicates a nearly 1400% year-over-year increase in such schemes in the crypto sector. This is a troubling signal: while the industry improves technical defenses, fraudsters are betting on the human factor.

My insight: This story is a reminder that even the most advanced wallets are useless if the user hands over the keys themselves. The crypto community needs to stop relying solely on technology and start actively implementing multi-factor authentication and user education. Until we change the security culture, such schemes will thrive, and victims will lose millions.