Crypto news

12.08.2026
04:34

US crypto scammer: how a 'call operator' and her accomplices stole $5 million

My investigations in the field of crypto security have uncovered a new high-profile scheme: U.S. citizen Tiffany Milanovich has found herself at the center of a criminal group that stole at least $5 million in digital assets. The method is classic, but refined to perfection: fake calls impersonating crypto service support teams.

Milanovich played the role of a "call operator." She would call victims, posing as a tech support employee, and convince them to hand over control of their funds. After draining their accounts, she did not hesitate to record videos mocking the victims—a detail that underscores the cynicism of this group.

The Mechanics of the Criminal Scheme

The entire operation was built on imitating the work of real support services for hardware wallets and centralized exchanges. The infrastructure for phishing sites was provided to the group by Milanovich's accomplices, known under the pseudonyms "bled" and "harm." This indicates a high level of organization: each participant was responsible for their own segment—from technical setup to psychological pressure on victims.

One of the attacks, carried out in June 2026, brought the criminals $1.2 million in Bitcoin and Ethereum. The victim lost funds from a Trezor hardware wallet. Notably, the attack began with a fake email purportedly from BitcoinIRA, signed by a certain Patricius Massi—likely to lend legitimacy. At the same time, most of the stolen funds have not yet been withdrawn and remain on traceable addresses.

Another attack, which occurred in October 2025, cost the victim $500,000 in Bitcoin. The funds were withdrawn from her account on the Coinbase exchange. Milanovich, apparently, was dissatisfied with her "fee"—she complained about the small share and even published transaction screenshots, trying to demonstrate the scale of the operation.

Traces of Luxury and Connections to Other Criminals

Milanovich was not known for modesty. On social media, she openly showed what she spent the stolen money on: luxury goods and gambling at casinos. The bets were made with the victims' money. Moreover, part of the "boastful" videos was edited to make the theft amounts appear even larger than they actually were—typical behavior for attracting attention in the criminal underworld.

My data also points to a connection between Milanovich and John "Lick" Dagita. In January, I already publicly accused him of involvement in the theft of cryptocurrency seized by U.S. authorities. In March, Dagita was detained in Saint Martin, which confirms the seriousness of these accusations.

This story is just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support staff and government agencies in 2025 alone, with losses exceeding $2.9 billion. According to Chainalysis, the number of such schemes in the crypto sector grew by nearly 1400% over the past year. This is a troubling signal for the entire industry.

My expert conclusion: The rise in impersonation attacks is a direct consequence of insufficient user awareness and weak protection at the level of customer experience. Exchanges and wallet manufacturers must implement multi-factor authentication and teach clients to recognize such threats. Otherwise, we will see even more massive losses in the coming years.