Crypto news

11.08.2026
22:50

An American woman found herself at the center of a $5 million theft: a new identity swap scheme in the crypto industry.

An analytical report has revealed the involvement of U.S. citizen Tiffany Milanovich in a series of cryptocurrency thefts totaling at least $5 million. The scheme, built on fake calls impersonating support services, exposed systemic vulnerabilities in the protection of digital asset users.

During a thorough investigation, it was established that Milanovich played the role of a "call operator": she called victims, posing as a tech support employee, and convinced them to hand over control of their funds. After draining the accounts, the perpetrator recorded videos mocking the victims, indicating a cynical and calculated approach to criminal activity.

Mechanics and Scale of the Attacks

The criminal group, of which Milanovich was a part, imitated the operations of real support services for hardware wallets and centralized exchanges. The infrastructure for phishing sites was provided by accomplices under the pseudonyms "bled" and "harm." In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum when funds were withdrawn from a Trezor hardware wallet. The attack began with a fake email purportedly from BitcoinIRA, signed with the name Patricia Massie.

Notably, most of the stolen funds have not yet been moved: the assets remain in on-chain wallets, leaving law enforcement a chance to track and recover them. In October 2025, another victim lost $500,000 in Bitcoin after funds were withdrawn from a Coinbase exchange account. At that time, Milanovich openly complained about her small cut and even published transaction screenshots on social media.

Spending and Connections

The investigation showed that Milanovich did not hide her spending: she purchased luxury goods and made large casino bets with the victims' money. Some "boastful" videos were edited to make the theft amounts appear even more impressive than they actually were. Additionally, experts link Milanovich to John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities. Dagita was arrested in March on Saint Martin.

Such schemes reflect a troubling trend of rising impersonation fraud. According to FBI data, in 2025 alone, more than 80,000 complaints were recorded regarding impersonation of tech support staff and government agencies, with losses exceeding $2.9 billion. Individual analytical reports indicate an almost 1,400% increase in such attacks in the cryptocurrency sector over the past year.

My expert opinion: this case is a striking example that social engineering remains the most dangerous attack vector, bypassing even the most advanced technical protections. The industry urgently needs to implement multi-factor authentication and educate users on basic security principles, otherwise such losses will become the new norm.