A U.S. citizen has found herself at the center of a scheme to embezzle $5 million in cryptocurrencies — investigation details
American Tiffany Milanovich, according to an independent investigation by blockchain analyst ZachXBT, is linked to a series of cyberattacks in which attackers stole at least $5 million in digital assets. The scheme, built on fake calls from crypto service support teams, is striking in its audacity and scale.
Milanovich played the role of a "call operator" in the criminal group. She called victims, posing as a tech support employee, and convinced them to hand over control of their funds. After draining accounts, the attacker did not hesitate to record videos mocking the victims, indicating the cynical nature of the criminal activity.
Attack Mechanics: From Phishing to Full Control
The criminal group operated in a coordinated manner. Milanovich imitated the work of real support services for hardware wallets and centralized exchanges. The infrastructure for phishing sites was provided by accomplices under the pseudonyms "bled" and "harm." In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum stored on a Trezor wallet. The attack began with a fake email from BitcoinIRA, signed by a nonexistent employee, Patricia Massi. Notably, a significant portion of the stolen funds has still not been withdrawn and remains on-chain.
In October 2025, the group struck a Coinbase client, stealing $500,000 in BTC. Milanovich, according to the investigation data, complained about her "small share" and even published transaction screenshots, confirming her direct involvement.
Spending and Connections: Luxury, Casinos, and Criminal Acquaintances
The stolen funds went toward luxury purchases and gambling. Milanovich did not hide her spending on social media, placing casino bets with the victims' money. Moreover, some of the "boastful" videos were edited to make the theft amounts look even more impressive than they actually were.
The investigation also links Milanovich to John "Lick" Dagita, who was accused in January of stealing cryptocurrency seized by U.S. authorities. In March, Dagita was arrested in Saint Martin, highlighting the international nature of this criminal network.
My comment: Such schemes are a vivid indicator of the growing threat of social engineering in the crypto industry. The FBI recorded more than 80,000 complaints about impersonation of tech support and government agency employees in 2025 alone, with losses exceeding $2.9 billion. Chainalysis data shows that the number of such attacks in the crypto sector has grown by nearly 1400% year over year. This is an alarming signal for all market participants: even the most secure wallets will not help if the user hands over their keys to scammers themselves. Verifying any request through independent channels is not paranoia, but a necessary security measure.