A U.S. citizen has found herself at the center of a scheme to steal $5 million in cryptocurrency: details revealed
American Tiffany Milanovich, according to my investigation, is linked to a series of attacks on cryptocurrency users that resulted in the theft of at least $5 million. The perpetrator operated using a well-established social engineering scheme, posing as a support staff member of major crypto services.
Milanovich served as a "call operator": she called victims, posing as a tech support employee, and convinced them to hand over control of their assets. After draining their accounts, she recorded videos mocking the victims and published them online, showing complete disregard for their losses.
Attack Mechanics
The criminal group Milanovich was part of mimicked the operations of real support services for hardware wallets and centralized exchanges. Infrastructure for phishing sites was provided by accomplices under the pseudonyms "bled" and "harm." In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum stored on a Trezor wallet. The attack began with a fake email from BitcoinIRA, signed by a fictitious employee named Patricia Massi. Notably, most of the stolen funds have not yet been moved and remain on on-chain wallets, indicating possible inexperience or caution on the part of the attackers.
In October 2025, the group struck again: a victim lost $500,000 in Bitcoin after funds were withdrawn from their Coinbase account. On that occasion, according to leaks, Milanovich complained about her "small share" and posted transaction screenshots, trying to downplay the scale of her involvement.
Spending and Connections
My research shows that Milanovich did not hide her lifestyle: on social media, she openly bragged about purchases of luxury goods and casino bets made with the victims' money. Moreover, some of the "boastful" videos were edited to make the theft amounts appear even more impressive than they actually were.
A connection has also been established between Milanovich and John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities. In March, Dagita was detained in Saint Martin, confirming the activity of this network.
These incidents are just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support and government agency staff in 2025 alone, with losses exceeding $2.9 billion. According to Chainalysis, the number of such schemes in the crypto sector has grown by nearly 1400% year over year. This is a troubling signal: even experienced users are not immune to attacks where the key factor is not code vulnerability, but trust in a voice on the other end of the line.
My comment: The rise of such attacks underscores the critical importance of verifying any requests to transfer funds, especially if they come via phone or email. No legitimate support service will ever ask you to hand over control of your wallet or reveal your seed phrase. The industry needs to more actively implement educational programs and technical safeguards, such as hardware wallets with multisignature support, to reduce the effectiveness of social engineering.