Crypto news

12.08.2026
04:15

A U.S. citizen found herself at the center of a $5 million crypto theft: how the scheme worked

My team and I at Cryptalist closely monitor high-profile incidents in the digital assets space, and the latest investigation by renowned on-chain detective ZachXBT has uncovered a blatant case of fraud. U.S. citizen Tiffany Milanovich has been named a key figure in a criminal group that stole at least $5 million from cryptocurrency holders. Her role was that of a "call operator": she phoned victims, posing as a customer support representative for crypto services, and convinced them to hand over control of their funds.

The scheme was particularly cynical in that, after draining the accounts, Milanovich recorded videos mocking the victims. The criminal group operated in a coordinated manner: a second member, operating under the aliases "bled" and "harm," provided the phishing infrastructure—fake websites that mimicked real hardware wallet platforms and centralized exchanges.

Attack Mechanics: From Trezor to Coinbase

One documented attack occurred in June 2026: a victim lost $1.2 million in bitcoin (BTC) and Ethereum (ETH) stored on a Trezor hardware wallet. The attack began with a phishing email allegedly sent on behalf of BitcoinIRA and signed by a certain Patricia Massi. Notably, a significant portion of the stolen funds has not yet been moved and remains on on-chain addresses, offering hope for potential tracking and recovery.

A second attack, dated October 2025, netted the group $500,000 in bitcoin. The funds were withdrawn from a victim's account on the Coinbase exchange. According to the investigation data, Milanovich even complained about her "small share" and posted transaction screenshots, demonstrating her involvement.

Traces of Luxury and Casinos

Analysis of Milanovich's social media activity showed that she did not hide her spending. The stolen funds went toward luxury items and online casino bets. Moreover, some of the boastful videos were edited to make the theft amounts appear even larger than they actually were.

The investigation also links Milanovich to John "Lick" Dagita, who was already accused in January of stealing cryptocurrency seized by U.S. authorities. In March, Dagita was detained in Saint Martin, indicating a possible connection between these episodes.

Scale of the Threat and Conclusions

This scheme is just part of a troubling trend. The FBI recorded more than 80,000 complaints about impersonation of tech support staff and government agencies in 2025 alone, with losses exceeding $2.9 billion. Chainalysis data confirms explosive growth: the number of such scams in the crypto sector rose by nearly 1400% over the year.

This case is a stark reminder that social engineering remains the most dangerous attack vector. Even the most reliable hardware wallets will not protect you if the user themselves hands over keys or access data. Always verify the identity of callers through official communication channels, and remember: no legitimate support service will demand urgent transfers or disclosure of seed phrases. In a world where scammers are becoming increasingly sophisticated, vigilance is your greatest asset.