On-chain researcher ZachXBT published investigation results on social network X, revealing the identity of American Tiffany Milanovich. She is linked to an organized group that stole at least $5M from digital asset owners. The entire criminal scheme was not based on virtuoso smart contract hacks or blockchain vulnerabilities. The main weapon was aggressive social engineering, where technical tricks merely served as a backdrop for psychological manipulation.
The deception mechanics were perfected down to the smallest details. The victim received a fake alarming email from a well-known crypto exchange or service, reporting unauthorized access to their account. Immediately after that, a call came to their mobile phone. Milanovich played the role of the person calling the victims, introducing herself as a customer support agent. A calm and confident female voice was meant to alleviate panic. This psychological contrast - the intense stress from the alarming notification and the relaxing conversation on the phone - caused even experienced investors to let their guard down. Dictated by the criminal, they entered their seed phrases into phishing panels themselves, after which the balance was completely drained.
Traces of Boasting in Private Chats
Petty pride became the main reason for the group's downfall. Milanovich recorded mocking pranks on the victims right during the calls, as soon as the withdrawal was confirmed. In private Telegram chats, she posted photos of stacks of cash and flashed screens with hundreds of thousands of dollars in casino balances. She even gambled the stolen funds from the victim at Shuffle casino right during the call. After the researcher's inquiry, the platform confirmed the scammer's account had been blocked. To boost her status in the community's eyes, she edited videos. In one of them, filmed in the Ledger Live interface, she pretended to be the owner of a service hot wallet receiving 7.7K JITOSOL.
In June 2026, one of the victims lost $1.2M in Bitcoin and Ethereum. The group emptied a Trezor hardware wallet after sending a fake message from BitcoinIRA in the name of Patricia Massie. Addresses linked to the theft still contain untouched funds. The phishing panel infrastructure for this attack was provided by another member of the group under the nicknames "bled" and "harm".
In February 2026, Milanovich participated in a Discord competition "band 4 band," where criminals showcase balances to prove their superiority. She transferred $100,000 to an Exodus wallet. An address linked to her activity currently holds 631K DAI, funded through instant exchanges of the anonymous cryptocurrency Monero.
At the end of January 2026, ZachXBT identified John Daghita, known as Lick, for stealing $46M of seized US government cryptocurrency. Milanovich, who closely communicated with him, recorded his conversation and posted it online for trolling. In response, Daghita published her real name in a public Telegram channel.
Paper Trail and Legal Prospects
The illusion of anonymity provided by routing funds through Monero and crypto casinos collapsed due to Milanovich's desire to prove her significance in a narrow circle. The detective collected a digital trail, pieced together recordings of boastful calls, and leaked compromising information online. The group member left behind a complete paper trail of chats, recordings, and on-chain data. She herself posted a screenshot of a search and seizure warrant in Connecticut, dated before a series of described incidents. In a separate audio recording, she mentions a booked flight and claims her funds remain untouched.
The collected evidence base has been handed over to the relevant US authorities. The scale of the digital trail left behind makes legal accountability an inevitable stage in concluding this story. The well-constructed social engineering scheme turned out to be vulnerable to the human factor within the criminal group itself.
AI Opinion
From the perspective of machine data analysis, the Milanovich case is a specific example of a broader 2026 trend: the threat has shifted from code to psychology. Data shows that in 2025, the crypto market lost over $1.8B due to fraud and exploits, with most losses linked specifically to social engineering, not protocol hacks. A similar dynamic has been observed in traditional finance: phone scams against elderly depositors remained more profitable than bank robberies for decades. A technical nuance not covered in the article is that the crypto industry lacks a transaction revocation mechanism, so a psychological attack becomes irreversible the moment the transaction is signed. Food for thought: can call verification ever neutralize a calm human voice as a tool of trust?
end-content




