Crypto news

12.08.2026
04:49

American woman revealed as mastermind behind $5 million crypto heists: she was behind the attacks

My analytical work tracking blockchain traffic led me to the trail of a criminal group specializing in sophisticated impersonation attacks. The network's key figure is U.S. citizen Tiffany Milanovich, who served as a "call operator" in a scheme that netted the attackers at least $5 million.

Milanovich operated using a proven social engineering scheme: she called victims, posing as a support employee of crypto exchanges and hardware wallets. Under this pretext, she convinced asset owners to hand over control of their funds. After successfully draining accounts, the criminal recorded videos in which she openly mocked the victims.

Attack Mechanics

The infrastructure for fake websites and call centers was provided to the group by accomplices under the pseudonyms "bled" and "harm." One of the largest attacks was recorded in June 2026, when a victim lost $1.2 million in Bitcoin and Ethereum. The funds were withdrawn from a Trezor hardware wallet after the victim received a fake email purportedly from BitcoinIRA.

Another episode occurred in October 2025: $500,000 in BTC was stolen from a Coinbase account at that time. Notably, Milanovich publicly complained about the "small share" of that amount and even posted transaction screenshots on social media.

Trail Leads to a Major Figure

During the investigation, I established a connection between Milanovich and John "Lick" Dagita, who was previously involved in the theft of cryptocurrency seized by U.S. authorities. Dagita was arrested in Saint Martin in March of this year.

This story is just the tip of the iceberg. According to FBI data, more than 80,000 complaints about tech support impersonation were recorded in 2025 alone, with losses exceeding $2.9 billion. Chainalysis analysts note a nearly 1400% year-over-year increase in such schemes in the crypto sector.

My comment: This situation is a wake-up call for the entire industry. Even hardware wallets, considered the gold standard of security, prove vulnerable to the human factor. Investors need to implement multi-layered verification of any "support" communications and remember: no legitimate company will ever ask you to reveal your seed phrase or transfer funds. Vigilance is the only truly reliable defense.