Crypto news

11.08.2026
21:12

An American woman turned out to be a key link in the theft of $5 million in cryptocurrency — details of the scheme

On-chain analyst ZachXBT has identified U.S. citizen Tiffany Milanovich as a member of a criminal group that stole at least $5 million in digital assets.

Milanovich served as a "call operator": she called victims, posing as a customer support representative of crypto services, and convinced them to hand over control of their funds. After draining their accounts, she recorded videos mocking the victims, indicating the cynical nature of the criminal activity.

Attack Mechanics

The perpetrator operated as part of an organized group, imitating the real technical support of hardware wallets and centralized exchanges. The infrastructure for phishing sites was provided by accomplices under the pseudonyms "bled" and "harm." In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum stored on a Trezor hardware wallet. The attack began with a fake email from BitcoinIRA, signed with the name Patricia Massie. Notably, most of the stolen funds have not yet been withdrawn and remain under the attackers' control on-chain.

In October 2025, another victim lost $500,000 in BTC after the group gained access to their Coinbase account. Milanovich, according to the data, complained about her small share and even published screenshots of the withdrawals, confirming her active involvement in the process.

Traces of Luxury and Gambling

The investigation showed that Milanovich openly displayed on social media what she spent the stolen money on: luxury goods and casino bets. She placed large bets with the victims' money, and some of the "boastful" videos were edited to make the theft amounts appear even larger than they actually were. The analyst also links her to John "Lick" Dagita, who was accused in January of stealing cryptocurrency seized by U.S. authorities. In March, Dagita was detained in Saint Martin.

These schemes are part of a worrying trend of rising impersonation fraud. The FBI recorded more than 80,000 complaints about fake tech support and government agency staff in 2025 alone, with losses exceeding $2.9 billion. Chainalysis noted that the number of such attacks in the crypto sector increased by nearly 1400% over the year.

My take: This story highlights that even hardware wallets do not protect against social engineering—the main vulnerable link is always the human. Investors should implement multi-factor authentication and agree on a "stop word" with family for calls claiming to be from support, to minimize the risks of such attacks.