An American woman turned out to be a key link in the theft of $5 million in cryptocurrency: a new social engineering scheme
On-chain analyst ZachXBT has identified U.S. citizen Tiffany Milanovich as being involved in a series of major cryptocurrency thefts totaling at least $5 million. The perpetrator operated using a well-established scheme, employing fake calls on behalf of the support services of well-known crypto services.
Milanovich played the role of a "call operator" in a criminal group: she contacted victims, posing as a technical support employee, and convinced them to hand over control of their assets. After draining their accounts, she recorded mocking videos ridiculing the victims, indicating a cynical and calculated approach to criminal activity.
Mechanics of the criminal scheme
According to my data, Milanovich operated as part of an organized group, imitating the real support of hardware wallets and centralized exchanges. The infrastructure for phishing sites was provided to her by accomplices under the pseudonyms "bled" and "harm." In June 2026, one victim lost $1.2 million in Bitcoin and Ethereum, which were withdrawn from a Trezor hardware wallet. The attack began with a fake email from BitcoinIRA, signed by a fictitious employee named Patricia Massi.
In another episode, in October 2025, a victim lost $500,000 in BTC after the group gained access to their Coinbase account. Notably, Milanovich did not hide her actions: she posted screenshots of fund withdrawals on social media, complaining about her "small share" and boasting about transactions. The funds were spent on luxury goods and gambling, with some of the "boastful" videos edited to make the theft amounts appear even more impressive.
Connections to other criminals and the scale of the threat
ZachXBT also links Milanovich to John "Lick" Dagita, who was charged in January with stealing cryptocurrency seized by U.S. authorities. In March, Dagita was arrested in Saint Martin, confirming the existence of a widespread network of cybercriminals.
FBI data shows that such impersonation schemes have become a real scourge for the industry: in 2025 alone, more than 80,000 complaints were recorded about fraudsters posing as tech support staff and government agencies, with losses exceeding $2.9 billion. According to Chainalysis estimates, the number of social engineering attacks in the crypto sector has grown by nearly 1400% year over year.
Expert opinion: This case is a striking example that even the most secure hardware wallets do not protect against the human factor. The industry urgently needs to implement multi-factor authentication with biometrics and teach users basic digital hygiene rules, otherwise we will see further explosive growth in such crimes.