Onchain investigator ZachXBT has named U.S.-based Tiffany Milanovich as a caller in support-impersonation scams tied to at least $5 million in stolen crypto. Notable incidents include a June 2026 Trezor drain of roughly $1.2 million and an October 2025 Coinbase theft of about $500,000. The report says an accomplice provided phishing-panel infrastructure and that Milanovich publicly flaunted proceeds while much of the stolen crypto remains dormant onchain.
Onchain Sleuth Links US-Based 'Support' Scammer Tiffany Milanovich to $5M in Crypto Thefts

Onchain investigator ZachXBT has publicly identified a U.S.-based threat actor, Tiffany Milanovich, as a central participant in an organized support-impersonation campaign that investigators say netted at least $5 million in stolen cryptocurrency.
How the Scheme Worked
According to ZachXBT's report, Milanovich operated as a "caller," placing phone calls while impersonating customer-support staff from hardware-wallet and centralized-exchange teams. The caller convinced victims to surrender access or approve withdrawals, then recorded herself taunting victims after funds were drained. The report describes the activity as part of a coordinated operation that combined spoofed emails, social-engineering phone calls and phishing-panel infrastructure.
Notable Incidents
June 2026: The group allegedly drained a victim's Trezor hardware wallet, taking roughly $1.2 million in Bitcoin (BTC) and Ethereum (ETH). The attack reportedly began with a spoofed BitcoinIRA email sent under the alias "Patricia Massie." ZachXBT says most of the stolen funds remain dormant onchain.
October 2025: Another victim lost about $500,000 in Bitcoin after the group targeted and drained a Coinbase account. The investigator reported that Milanovich publicly complained about her share of the proceeds and posted a screenshot of a withdrawal in the ensuing dispute.
Partners, Tactics and Public Displays
ZachXBT's report credits a separate actor, known by the aliases "bled" and "harm," with supplying the phishing-panel infrastructure used to automate and manage attacks. Milanovich is also accused of publicly displaying apparent stolen proceeds on social media—posting luxury purchases, gambling videos and other "flex" content. The investigator alleges some videos may have been edited to exaggerate the scale of gains, and that at least some victim funds were used for casino gambling.
Broader Context and Law Enforcement
The report connects Milanovich to John "Lick" Daghita, whom ZachXBT exposed earlier in the year for allegedly stealing crypto seized by U.S. authorities; Daghita was arrested in Saint Martin in March. ZachXBT recounts a series of retaliatory recordings and public name-calling that escalated on Telegram between the parties.
"These incidents fit into a wider surge in impersonation fraud," the report notes, pointing to large increases in social-engineering attacks targeting crypto users.
Supporting that assessment, FBI data cited in the report show more than 80,000 tech-support and government-impersonation complaints in 2025 with reported losses exceeding $2.9 billion. Chainalysis data referenced by the investigator indicate crypto impersonation scams spiked nearly 1,400% in 2025.
What Investigators Say Now
ZachXBT emphasizes that the organized use of spoofed emails, fake support calls, phishing panels and social-media displays allowed a small group of actors to extract large sums while leaving much of the stolen crypto dormant and visible on public ledgers. Law enforcement and industry monitoring remain critical as onchain tracing attempts to link addresses and spending patterns back to people and services used by the alleged perpetrators.
Takeaway: Users should treat unexpected support calls and unsolicited emails with extreme caution, verify support channels independently, and enable strong wallet-security practices to reduce the risk of social-engineering drains.
Help us improve.




























