A U.S. citizen turned out to be a key link in the theft of $5 million in cryptocurrency.
On-chain analyst ZachXBT's investigative work has uncovered a new facet of organized crypto fraud. U.S. citizen Tiffany Milanovich has been identified as a direct participant in a criminal scheme that cost victims at least $5 million. Her role was that of a "call operator": she phoned victims, posing as a customer support representative for crypto services, and convinced them to hand over control of their assets.
During the fraudulent activities, Milanovich not only drained accounts but also recorded videos mocking her victims, demonstrating a cynical attitude toward other people's property. According to the investigation materials, she operated as part of an organized group, and her cover was simulating the work of real technical support for hardware wallets and centralized exchanges.
Mechanics of the criminal scheme
The infrastructure for fake websites and calls was provided by Milanovich's accomplices, known under the pseudonyms "bled" and "harm." In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum stored on a Trezor hardware wallet. The attack began with a fake email purportedly from BitcoinIRA, signed by a certain Patricius Massi. Notably, a significant portion of the stolen funds has still not been withdrawn and remains on-chain, offering hope for their recovery.
Another episode dates to October 2025, when a victim lost $500,000 in Bitcoin after the group gained access to their Coinbase account. Milanovich, apparently, was not satisfied with her share and even published screenshots of the withdrawals, complaining about the "small take."
Traces of luxury and gambling
According to the investigation, Milanovich openly showcased on social media what she spent the stolen money on: luxury brand items and casino bets. Moreover, some of the "boastful" videos were edited to make the theft amounts appear even more impressive than they actually were. This points to the criminal's psychological profile, for whom not only profit matters but also public recognition.
The investigation also links Milanovich to John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities. In March, Dagita was detained in Saint Martin, confirming the existence of a sprawling network of malicious actors.
These events illustrate a troubling trend: the FBI recorded more than 80,000 complaints about impersonation of tech support staff in 2025, with losses exceeding $2.9 billion. According to Chainalysis estimates, the number of such schemes in the crypto sector has grown by nearly 1400% over the past year. Clearly, the industry needs not only stronger technical protection but also user education: as long as trust in the "voice on the phone" remains a vulnerability, stories like these will keep happening.
My conclusion: this case is a vivid example of how social engineering remains the most dangerous attack vector despite all technological innovations. Investors should remember a simple rule: no legitimate support service will ever ask you to transfer funds or disclose your seed phrase. Vigilance is the only truly reliable safe.