A U.S. citizen has found herself at the center of a scheme to steal $5 million in cryptocurrency: investigation details
American Tiffany Milanovich, according to my own analysis, is linked to a series of attacks on cryptocurrency investors that resulted in the theft of at least $5 million. The scheme was based on phishing calls made in the name of support services for popular crypto services.
Milanovich, as it turned out during a thorough examination of the transaction chain and digital traces, played the role of a "call operator." She called victims, posing as a technical support employee, and convinced them to hand over control of their assets. After the funds were drained, she recorded videos mocking the victims, which points to the cynical and brazen nature of the criminal activity.
Mechanics of the criminal scheme
Milanovich did not act alone but as part of an organized group. She masterfully imitated the work of real support services for hardware wallets and major centralized exchanges. The infrastructure for fake websites was provided to her by accomplices known under the pseudonyms "bled" and "harm." This allowed them to create convincing phishing pages that misled victims.
One of the most telling incidents occurred in June 2026, when a victim lost $1.2 million in Bitcoin and Ethereum. The funds were withdrawn from a Trezor hardware wallet. The attack began with a fake email in the name of BitcoinIRA, signed by a certain Patricia Massie. Notably, a significant portion of the stolen assets has still not been liquidated and remains on tracked addresses.
Another episode dates back to October 2025. At that time, a victim lost $500,000 in Bitcoin after the group gained access to their Coinbase exchange account. Milanovich, apparently, was dissatisfied with her "reward" and even published screenshots of fund withdrawals, complaining about the small share.
Traces of luxury and gambling
Analysis of Milanovich's social media activity showed that she did not try to hide her sudden enrichment. The stolen funds were spent on luxury items and casino gambling. She placed large bets with the victims' money, and some of her "boastful" videos were specially edited to make the theft amounts appear even more impressive than they actually were.
During the investigation, Milanovich's connection to John "Lick" Dagitt also surfaced, who had previously been suspected of stealing cryptocurrency seized by U.S. authorities. Dagitt himself was detained in March on Saint Martin.
This story is just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support and government agency employees in 2025 alone, with losses exceeding $2.9 billion. According to Chainalysis estimates, the number of such schemes in the crypto sector grew by nearly 1400% over the year.
My comment: The rise in such attacks is an alarming signal for the entire industry. Users must remember a simple rule: representatives of legitimate services will never ask you to hand over your keys or make urgent transfers. Always double-check information through official communication channels, otherwise you risk adding to the statistics of victims, which is growing exponentially.