Crypto news

12.08.2026
02:25

A U.S. citizen found herself at the center of a scheme to steal $5 million in cryptocurrency: investigation details

A large-scale on-chain investigation conducted by independent analyst ZachXBT has uncovered the involvement of American Tiffany Milanovich in an organized group that stole at least $5 million from users of crypto services. The scheme, built on fake calls from purported support services, demonstrates how sophisticated attacks on digital asset holders have become.

Milanovich, according to the collected data, served as a "call operator." She contacted victims, posing as a tech support employee, and convinced them to hand over control of their funds. After successfully withdrawing assets, the woman did not hesitate to record videos in which she openly mocked the victims, indicating a complete lack of moral boundaries.

Mechanics of the criminal group

The group operated in a coordinated manner. Milanovich pretended to work in real support for hardware wallets and centralized exchanges. The infrastructure for phishing sites was provided to her by accomplices under the pseudonyms "bled" and "harm." One of the attacks, dated June 2026, resulted in a victim losing $1.2 million in BTC and ETH from a Trezor hardware wallet. Notably, the attack began with a fake email from BitcoinIRA, signed by a certain Patricia Massi.

In another episode, in October 2025, a victim lost $500,000 in bitcoins stored in a Coinbase account. Notably, Milanovich, according to ZachXBT, complained about her "small share" and even published screenshots of withdrawals, trying to emphasize her importance.

Traces of luxury and gambling

Analysis of Milanovich's social media activity showed where the stolen funds went. She openly spent money on luxury goods and placed large bets in casinos, using victims' funds. Moreover, part of the "boastful" videos was edited in such a way that the amounts of the thefts appeared even more impressive than they actually were.

During the investigation, Milanovich's connection to John "Lick" Dagita also surfaced, who was previously detained in Saint Martin on charges of stealing cryptocurrency seized by US authorities. This indicates the existence of a sprawling network operating across different jurisdictions.

Such schemes are just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support employees in 2025, with losses exceeding $2.9 billion. According to Chainalysis, the number of such attacks in the crypto sector increased by nearly 1400% year over year.

My comment: This story is another reminder that even the most secure hardware wallets will not save you if the user themselves hands over control. Social engineering remains the most dangerous attack vector, and the 1400% increase in such schemes indicates that the industry urgently needs to implement stricter verification protocols and educate users on basic digital hygiene. Investors should remember: no legitimate support service will ever ask you to transfer funds or reveal your seed phrase.