A U.S. citizen has found herself at the center of a scheme to steal $5 million in cryptocurrency: new details of the investigation
American Tiffany Milanovich, according to my independent analysis, is directly involved in a series of attacks on digital asset owners, resulting in the theft of at least $5 million. This is a well-coordinated scheme using fake calls purporting to be from crypto service support teams.
Milanovich served as a so-called "call operator." She called victims, posing as a technical support employee, and convinced them to hand over control of their funds. After draining the accounts, the attacker not only did not hide but also recorded videos mocking the victims, indicating her complete confidence in impunity.
Mechanics of the criminal group
She operated as part of an organized group. Milanovich imitated the support services of hardware wallets and centralized exchanges, while the infrastructure for phishing sites was provided by accomplices under the pseudonyms "bled" and "harm." This scheme was refined to the point of automation.
One of the most high-profile incidents occurred in June 2026, when a victim lost $1.2 million in Bitcoin and Ethereum. The funds were withdrawn from a Trezor hardware wallet. The attack began with a fake email purportedly from BitcoinIRA, signed by a certain Patricius Massi, highlighting the attackers' level of preparation. Notably, a significant portion of the stolen assets has still not been moved and remains on traceable addresses.
Another attack, dated October 2025, brought the group $500,000 in Bitcoin. In that case, funds were withdrawn from a victim's account on the Coinbase exchange. According to available data, Milanovich even complained about her "small share" and published transaction screenshots, attempting to downplay the scale of her involvement.
Traces of luxury and gambling
An analysis of Milanovich's spending leaves no doubt about her motivation. The stolen funds were spent on luxury brand items and casino gambling. She placed large bets with the victims' money, and some of the "boastful" videos were edited to make the theft amounts appear even larger than they actually were.
The investigation also links Milanovich to John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities. Dagita was detained in Saint Martin in March, indicating possible international connections of this group.
This story is just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of technical support and government agency employees in 2025 alone, with losses exceeding $2.9 billion. According to Chainalysis, the number of such schemes in the cryptocurrency sector grew by nearly 1400% over the year. This is a systemic threat that requires not only technical but also educational measures from the industry.
My comment: This case is a striking example of how social engineering remains the weakest link in the protection of digital assets. No hardware wallet will save you if the user themselves hands over control of their funds. Investors should remember a simple rule: no legitimate support service will ever ask you to transfer funds or disclose your seed phrase. Verify any requests through official communication channels, and such schemes will lose their effectiveness.