Crypto news

12.08.2026
00:07

An American woman found herself at the center of a scheme to steal $5 million in cryptocurrencies: details revealed

On-chain analyst ZachXBT has identified U.S. citizen Tiffany Milanovich as a key figure in a criminal group that stole over $5 million in digital assets. The scheme relied on phishing calls made in the name of crypto service support teams.

Mechanics of the Deception

Milanovich served as a "call operator": she called victims, posing as a tech support employee, and convinced them to hand over control of their funds. After draining accounts, she recorded videos mocking the victims. The infrastructure for fake websites and calls was provided by another group member operating under the pseudonyms "bled" and "harm."

In June 2026, one victim lost $1.2 million in Bitcoin (BTC) and Ethereum (ETH) — the funds were withdrawn from a Trezor hardware wallet. The attack began with a fake email from BitcoinIRA, signed with the name Patricia Massie. Another attack in October 2025 cost a victim $500,000 in BTC, withdrawn from a Coinbase exchange account. Notably, a significant portion of the stolen funds remains untouched and still sits on-chain.

Traces of Luxury and Gambling

Milanovich did not hide her spending: on social media, she boasted about purchases of luxury goods and casino bets made with the victims' money. ZachXBT also links her to John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities. In March, Dagita was arrested in Saint Martin.

This case is just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support and government agency staff in 2025 alone, with losses exceeding $2.9 billion. Chainalysis notes a nearly 1,400% increase in such schemes in the crypto sector over the year.

My analysis: The rise of such attacks is a troubling signal for the industry. Users must be critical of any incoming calls and emails, even if they look official. Cold storage and two-factor authentication are not a panacea when attackers manipulate the human factor. The industry needs stricter verification standards and educational campaigns to protect retail investors.