A U.S. citizen has found herself at the center of a scheme to embezzle $5 million in cryptocurrency: investigation details
Analytical work in the field of blockchain investigations has uncovered another high-profile story linked to cybercrime. U.S. citizen Tiffany Milanovich has been identified as a key figure in a fraudulent group that stole at least $5 million from cryptocurrency holders. Her role in this scheme was that of a so-called "call operator," meaning the person who directly contacted victims.
The attack method was classic but refined to the point of automation: Milanovich called victims posing as a customer support employee of crypto services and convinced them to transfer control of their assets to wallets controlled by the attackers. After successfully draining the accounts, she recorded videos with mocking comments directed at her victims, indicating cynicism and a complete lack of moral boundaries.
Infrastructure and Scale of the Attacks
The entire operation was streamlined. Milanovich operated as part of a group where her accomplices, under the pseudonyms "bled" and "harm," created phishing websites mimicking the interfaces of real support services for hardware wallets and centralized exchanges. One of the attacks, which occurred in June 2026, resulted in the loss of $1.2 million in Bitcoin and Ethereum from a Trezor wallet. It all began with a fake email from BitcoinIRA, signed with the name Patricia Massi.
Notably, a significant portion of the stolen funds has still not been withdrawn from on-chain addresses, leaving a theoretical possibility for tracking and recovery. In another episode, dated October 2025, a victim lost $500,000 in BTC after the group gained access to their Coinbase account. Milanovich, according to available data, complained about her "small share" at the time and even posted transaction screenshots on social media.
Traces of Luxury and Connections to Known Figures
The investigation shows that Milanovich did not try to hide her sudden wealth. On social media, she openly displayed purchases of luxury items and casino bets made with the victims' money. Moreover, some "boastful" videos were edited to exaggerate the actual amounts stolen.
Of particular note is Milanovich's connection to John "Lick" Dagita, who was previously accused of stealing cryptocurrency seized by U.S. authorities and was detained in March on Saint Martin. This points to the formation of persistent criminal clusters in this sphere.
Such schemes are just the tip of the iceberg. The FBI recorded more than 80,000 complaints about impersonation of tech support and government agency employees in 2025 alone, with losses exceeding $2.9 billion. According to Chainalysis analysts, the number of such attacks in the crypto sector grew by nearly 1400% over the past year.
This story is yet another reminder that the human factor remains the weakest link in digital asset security. Even the most reliable hardware wallets are powerless if the user themselves discloses access under pressure from social engineering. Investors should treat any incoming calls and messages critically, even if they look official, and always verify information through channels listed on the official websites of services.