"Exposed by Braggadocio": ZachXBT Reveals Identity of Scammer Who Stole $5M from Crypto Investors

cryptonews.ruPublished on 2026-08-12Last updated on 2026-08-12

Abstract

On-chain investigator ZachXBT has exposed the identity of US citizen Tiffany Milanovich, a member of a group that stole at least $5 million from cryptocurrency investors through an elaborate social engineering scheme. The fraud involved sending fake, alarming emails impersonating crypto services, followed by phone calls where Milanovich, posing as support staff, calmly instructed victims to enter their seed phrases into phishing panels, leading to complete asset drainage. The group's downfall stemmed from their own pride. Milanovich recorded mocking calls with victims, boasted about stolen funds in private Telegram chats, flaunted cash and casino balances, and even gambled victims' funds live. This digital trail, alongside evidence like a leaked search warrant and connections to other criminals like "Lick" (John Daghita), left a comprehensive paper trail. ZachXBT compiled the evidence—including call recordings, chats, and on-chain data—and submitted it to US authorities. The case highlights a major shift in crypto threats from code exploits to psychology, with social engineering now causing the majority of losses. The irreversibility of crypto transactions makes such psychological attacks particularly devastating.

On-chain researcher ZachXBT published investigation results on social network X, revealing the identity of American Tiffany Milanovich. She is linked to an organized group that stole at least $5M from digital asset owners. The entire criminal scheme was not based on virtuoso smart contract hacks or blockchain vulnerabilities. The main weapon was aggressive social engineering, where technical tricks merely served as a backdrop for psychological manipulation.

The deception mechanics were perfected down to the smallest details. The victim received a fake alarming email from a well-known crypto exchange or service, reporting unauthorized access to their account. Immediately after that, a call came to their mobile phone. Milanovich played the role of the person calling the victims, introducing herself as a customer support agent. A calm and confident female voice was meant to alleviate panic. This psychological contrast - the intense stress from the alarming notification and the relaxing conversation on the phone - caused even experienced investors to let their guard down. Dictated by the criminal, they entered their seed phrases into phishing panels themselves, after which the balance was completely drained.

Traces of Boasting in Private Chats

Petty pride became the main reason for the group's downfall. Milanovich recorded mocking pranks on the victims right during the calls, as soon as the withdrawal was confirmed. In private Telegram chats, she posted photos of stacks of cash and flashed screens with hundreds of thousands of dollars in casino balances. She even gambled the stolen funds from the victim at Shuffle casino right during the call. After the researcher's inquiry, the platform confirmed the scammer's account had been blocked. To boost her status in the community's eyes, she edited videos. In one of them, filmed in the Ledger Live interface, she pretended to be the owner of a service hot wallet receiving 7.7K JITOSOL.

  • In June 2026, one of the victims lost $1.2M in Bitcoin and Ethereum. The group emptied a Trezor hardware wallet after sending a fake message from BitcoinIRA in the name of Patricia Massie. Addresses linked to the theft still contain untouched funds. The phishing panel infrastructure for this attack was provided by another member of the group under the nicknames "bled" and "harm".

  • In February 2026, Milanovich participated in a Discord competition "band 4 band," where criminals showcase balances to prove their superiority. She transferred $100,000 to an Exodus wallet. An address linked to her activity currently holds 631K DAI, funded through instant exchanges of the anonymous cryptocurrency Monero.

  • At the end of January 2026, ZachXBT identified John Daghita, known as Lick, for stealing $46M of seized US government cryptocurrency. Milanovich, who closely communicated with him, recorded his conversation and posted it online for trolling. In response, Daghita published her real name in a public Telegram channel.

Paper Trail and Legal Prospects

The illusion of anonymity provided by routing funds through Monero and crypto casinos collapsed due to Milanovich's desire to prove her significance in a narrow circle. The detective collected a digital trail, pieced together recordings of boastful calls, and leaked compromising information online. The group member left behind a complete paper trail of chats, recordings, and on-chain data. She herself posted a screenshot of a search and seizure warrant in Connecticut, dated before a series of described incidents. In a separate audio recording, she mentions a booked flight and claims her funds remain untouched.

The collected evidence base has been handed over to the relevant US authorities. The scale of the digital trail left behind makes legal accountability an inevitable stage in concluding this story. The well-constructed social engineering scheme turned out to be vulnerable to the human factor within the criminal group itself.

AI Opinion

From the perspective of machine data analysis, the Milanovich case is a specific example of a broader 2026 trend: the threat has shifted from code to psychology. Data shows that in 2025, the crypto market lost over $1.8B due to fraud and exploits, with most losses linked specifically to social engineering, not protocol hacks. A similar dynamic has been observed in traditional finance: phone scams against elderly depositors remained more profitable than bank robberies for decades. A technical nuance not covered in the article is that the crypto industry lacks a transaction revocation mechanism, so a psychological attack becomes irreversible the moment the transaction is signed. Food for thought: can call verification ever neutralize a calm human voice as a tool of trust?

end-content

Related Questions

QAccording to the article, what was the primary method used by the criminal group to steal cryptocurrency, and not a key technical vulnerability?

AThe primary method was aggressive social engineering. The scheme was based on manipulative phone calls, not on hacking smart contracts or exploiting blockchain vulnerabilities.

QWhat specific mistake did Tiffany Milanovich make that ultimately led to her exposure according to the on-chain investigator?

AHer downfall was caused by petty pride and a desire to show off. She recorded mocking prank calls of victims, posted videos and screenshots of stolen funds and cash in private Telegram chats, and shared compromising information to boost her status within the criminal community.

QWhat key piece of real-world evidence did Milanovich herself leak online, which is mentioned in the 'Paper Trail and Legal Prospects' section?

AShe herself posted a screenshot of a search and seizure warrant from the state of Connecticut, dated before some of the described incidents.

QBased on the 'AI Opinion' section, what is the broader trend in cryptocurrency losses for 2025 mentioned in the article, and how does it relate to this case?

AThe broader trend is that losses are increasingly due to social engineering rather than protocol hacks. In 2025, over $1.8 billion was lost to fraud and exploits, with most losses linked to social engineering. Milanovich's case is a specific example of this shift from code-based to psychology-based threats.

QWhat action did the cryptocurrency casino 'Shuffle' take after being contacted by the investigator ZachXBT regarding Milanovich's activities?

AThe Shuffle platform confirmed it had blocked the scammer's account after being contacted by the investigator.

Related Reads

Supply Skyrockets by 3 Trillion, Veteran Blockchain Harmony Dealt Another Fatal Blow

**Title: Supply Surges by 3 Trillion, Dealing Another Blow to Veteran Blockchain Harmony** A significant security breach has struck the Harmony blockchain, involving the illegal minting of approximately 3 trillion ONE tokens (valued around $23.4 billion), which constitutes about 26% of its total supply. The attack exploited critical logic errors in Harmony's cross-shard receipt verification and signature validation systems, allowing the attacker to forge receipts and bypass security checks. Initial reports indicated around 4 billion tokens were minted, but this figure was later revised drastically upwards as more data became available. A substantial portion of the newly minted tokens was quickly transferred to cryptocurrency exchanges, leading to a sharp price drop of nearly 38% for ONE. Harmony's official response included identifying related wallet addresses, urging exchanges to freeze associated funds, releasing a software patch (v2026.1.1) to prevent further minting, and temporarily halting its cross-chain bridge service. The team is also evaluating the option of a network rollback. This incident marks the third major security or technical issue directly affecting Harmony's token supply in recent years, following a $100 million bridge hack in 2022 and a staking bug in late 2023. Once a notable Layer 1 chain, Harmony's market capitalization has dwindled to around $12 million, with its Total Value Locked (TVL) collapsing from a peak over $1.4 billion to under $170,000. The event underscores the persistent security vulnerabilities faced by smaller blockchain protocols and highlights the importance of scrutinizing a project's security history and on-chain activity.

marsbit1h ago

Supply Skyrockets by 3 Trillion, Veteran Blockchain Harmony Dealt Another Fatal Blow

marsbit1h ago

ENS Has Quietly Completed a 'Self-Revolution'

On August 11th, the ENS DAO officially voted into effect the "Next Era of ENS DAO" proposal. This move by the crucial Ethereum domain name protocol establishes a legal entity, the ENS Foundation, to represent it in the real world—a long-missing piece after nearly a decade of operation. The proposal, initially introduced in June, sparked significant community debate. Critics feared it amounted to the DAO dissolving itself and handing over its treasury. The final version, however, represents a compromise, carefully balancing control. The DAO retains governance over its substantial ENS token holdings and its operational wallet. A $65 million endowment is delegated to the Foundation's Board but protected by a 9-day timelock and a Security Council veto. The DAO also holds ultimate power to appoint and remove Board members. The Foundation's role is to handle tasks the DAO is ill-suited for, such as legal representation, trademark enforcement, and engagement with traditional internet governance bodies like ICANN. This allows ENS Labs, the core development company, to focus on engineering, like the upcoming ENSv2. The five-member Foundation Board includes independent directors with provisions to manage conflicts of interest, particularly regarding funding to ENS Labs. This governance restructuring aims to create a clearer separation of duties: the DAO safeguards protocol neutrality, the Foundation handles real-world operations and diplomacy, and ENS Labs focuses on development. It acknowledges the limitations of pure token voting for day-to-day operations, seeking efficiency through a professionally managed entity with built-in accountability mechanisms. The ENS experiment—aiming to be both credibly neutral and effectively represented in traditional forums—will be closely watched as a potential model for the broader DAO ecosystem.

marsbit1h ago

ENS Has Quietly Completed a 'Self-Revolution'

marsbit1h ago

Trading

Spot
活动图片