"Exposed by Braggadocio": ZachXBT Reveals Identity of Scammer Who Stole $5M from Crypto Investors

cryptonews.ru2026-08-12 tarihinde yayınlandı2026-08-12 tarihinde güncellendi

Özet

On-chain investigator ZachXBT has exposed the identity of US citizen Tiffany Milanovich, a member of a group that stole at least $5 million from cryptocurrency investors through an elaborate social engineering scheme. The fraud involved sending fake, alarming emails impersonating crypto services, followed by phone calls where Milanovich, posing as support staff, calmly instructed victims to enter their seed phrases into phishing panels, leading to complete asset drainage. The group's downfall stemmed from their own pride. Milanovich recorded mocking calls with victims, boasted about stolen funds in private Telegram chats, flaunted cash and casino balances, and even gambled victims' funds live. This digital trail, alongside evidence like a leaked search warrant and connections to other criminals like "Lick" (John Daghita), left a comprehensive paper trail. ZachXBT compiled the evidence—including call recordings, chats, and on-chain data—and submitted it to US authorities. The case highlights a major shift in crypto threats from code exploits to psychology, with social engineering now causing the majority of losses. The irreversibility of crypto transactions makes such psychological attacks particularly devastating.

On-chain researcher ZachXBT published investigation results on social network X, revealing the identity of American Tiffany Milanovich. She is linked to an organized group that stole at least $5M from digital asset owners. The entire criminal scheme was not based on virtuoso smart contract hacks or blockchain vulnerabilities. The main weapon was aggressive social engineering, where technical tricks merely served as a backdrop for psychological manipulation.

The deception mechanics were perfected down to the smallest details. The victim received a fake alarming email from a well-known crypto exchange or service, reporting unauthorized access to their account. Immediately after that, a call came to their mobile phone. Milanovich played the role of the person calling the victims, introducing herself as a customer support agent. A calm and confident female voice was meant to alleviate panic. This psychological contrast - the intense stress from the alarming notification and the relaxing conversation on the phone - caused even experienced investors to let their guard down. Dictated by the criminal, they entered their seed phrases into phishing panels themselves, after which the balance was completely drained.

Traces of Boasting in Private Chats

Petty pride became the main reason for the group's downfall. Milanovich recorded mocking pranks on the victims right during the calls, as soon as the withdrawal was confirmed. In private Telegram chats, she posted photos of stacks of cash and flashed screens with hundreds of thousands of dollars in casino balances. She even gambled the stolen funds from the victim at Shuffle casino right during the call. After the researcher's inquiry, the platform confirmed the scammer's account had been blocked. To boost her status in the community's eyes, she edited videos. In one of them, filmed in the Ledger Live interface, she pretended to be the owner of a service hot wallet receiving 7.7K JITOSOL.

  • In June 2026, one of the victims lost $1.2M in Bitcoin and Ethereum. The group emptied a Trezor hardware wallet after sending a fake message from BitcoinIRA in the name of Patricia Massie. Addresses linked to the theft still contain untouched funds. The phishing panel infrastructure for this attack was provided by another member of the group under the nicknames "bled" and "harm".

  • In February 2026, Milanovich participated in a Discord competition "band 4 band," where criminals showcase balances to prove their superiority. She transferred $100,000 to an Exodus wallet. An address linked to her activity currently holds 631K DAI, funded through instant exchanges of the anonymous cryptocurrency Monero.

  • At the end of January 2026, ZachXBT identified John Daghita, known as Lick, for stealing $46M of seized US government cryptocurrency. Milanovich, who closely communicated with him, recorded his conversation and posted it online for trolling. In response, Daghita published her real name in a public Telegram channel.

Paper Trail and Legal Prospects

The illusion of anonymity provided by routing funds through Monero and crypto casinos collapsed due to Milanovich's desire to prove her significance in a narrow circle. The detective collected a digital trail, pieced together recordings of boastful calls, and leaked compromising information online. The group member left behind a complete paper trail of chats, recordings, and on-chain data. She herself posted a screenshot of a search and seizure warrant in Connecticut, dated before a series of described incidents. In a separate audio recording, she mentions a booked flight and claims her funds remain untouched.

The collected evidence base has been handed over to the relevant US authorities. The scale of the digital trail left behind makes legal accountability an inevitable stage in concluding this story. The well-constructed social engineering scheme turned out to be vulnerable to the human factor within the criminal group itself.

AI Opinion

From the perspective of machine data analysis, the Milanovich case is a specific example of a broader 2026 trend: the threat has shifted from code to psychology. Data shows that in 2025, the crypto market lost over $1.8B due to fraud and exploits, with most losses linked specifically to social engineering, not protocol hacks. A similar dynamic has been observed in traditional finance: phone scams against elderly depositors remained more profitable than bank robberies for decades. A technical nuance not covered in the article is that the crypto industry lacks a transaction revocation mechanism, so a psychological attack becomes irreversible the moment the transaction is signed. Food for thought: can call verification ever neutralize a calm human voice as a tool of trust?

end-content

İlgili Sorular

QAccording to the article, what was the primary method used by the criminal group to steal cryptocurrency, and not a key technical vulnerability?

AThe primary method was aggressive social engineering. The scheme was based on manipulative phone calls, not on hacking smart contracts or exploiting blockchain vulnerabilities.

QWhat specific mistake did Tiffany Milanovich make that ultimately led to her exposure according to the on-chain investigator?

AHer downfall was caused by petty pride and a desire to show off. She recorded mocking prank calls of victims, posted videos and screenshots of stolen funds and cash in private Telegram chats, and shared compromising information to boost her status within the criminal community.

QWhat key piece of real-world evidence did Milanovich herself leak online, which is mentioned in the 'Paper Trail and Legal Prospects' section?

AShe herself posted a screenshot of a search and seizure warrant from the state of Connecticut, dated before some of the described incidents.

QBased on the 'AI Opinion' section, what is the broader trend in cryptocurrency losses for 2025 mentioned in the article, and how does it relate to this case?

AThe broader trend is that losses are increasingly due to social engineering rather than protocol hacks. In 2025, over $1.8 billion was lost to fraud and exploits, with most losses linked to social engineering. Milanovich's case is a specific example of this shift from code-based to psychology-based threats.

QWhat action did the cryptocurrency casino 'Shuffle' take after being contacted by the investigator ZachXBT regarding Milanovich's activities?

AThe Shuffle platform confirmed it had blocked the scammer's account after being contacted by the investigator.

İlgili Okumalar

Bitcoin Policy Institute Calls on AI Developers to Provide Crypto Infrastructure Defenders with Access to Advanced Models

The Bitcoin Policy Institute (BPI) has issued an open letter urging leading AI developers to grant trusted access to advanced AI models for defenders of critical crypto infrastructure. Analysts warn that sophisticated AI systems, capable of analyzing large codebases and finding vulnerabilities, could be leveraged by malicious actors before open-source defenders can use them, posing a significant risk to the trillion-dollar digital asset ecosystem. Vulnerable points include wallets, signing devices, cryptographic libraries, node software, exchanges, and payment networks. BPI highlights that developers of key open-source projects like Bitcoin Core currently lack access to the specialized cybersecurity programs and most powerful AI models available to leading AI labs and their partners. This creates a dangerous asymmetry. The institute calls on AI labs to establish or expand permanent trusted access programs, providing qualified developers and researchers with early, supervised access to cutting-edge models, sufficient computing resources for security audits, secure environments for analyzing sensitive code, and direct channels for vulnerability disclosure and coordinated fixes. The goal is to enable defenders to identify and patch security flaws before attackers can exploit them. BPI also urges the crypto industry to assist AI labs in identifying reliable participants for such access programs and coordinating response efforts.

cryptonews.ru8 dk önce

Bitcoin Policy Institute Calls on AI Developers to Provide Crypto Infrastructure Defenders with Access to Advanced Models

cryptonews.ru8 dk önce

Ethena's USDe Captures 43% of Stablecoin Supply on Robinhood Chain for Capital Placement

USDe from Ethena has rapidly become the primary source of dollar liquidity on the Robinhood Chain, surging from about $17 million a month ago to roughly $253 million, accounting for nearly 43% of the network's total stablecoin volume. This synthetic dollar, which maintains its value through crypto assets and offsetting derivatives positions, indicates that incoming capital is seeking more than just a trading venue. It reflects a broader shift where crypto investors are using stablecoins for DeFi, collateral, and yield strategies. Robinhood Chain, an Ethereum L2, is seeing its dollar base shift towards yield-bearing assets. Unlike traditional stablecoins like Paxos's USDG, USDe is a synthetic dollar that does not inherently pay yield; users must stake it to earn rewards via sUSDe within Ethena's delta-neutral framework. Analysts view the rapid inflow as capital being deposited within the network, not just transiting through it, potentially boosting lending and trading activities even without user growth. While transaction activity has spiked—averaging about 11.6 million daily transactions, up 30% weekly—daily active accounts have grown only modestly and remain below July peaks. Currently, memecoins like $CASHCAT dominate over 99% of trading volume, driving speculation rather than the platform's long-term focus on tokenized securities. The key challenge for Robinhood will be converting this initial speculative activity into sustainable, long-term financial transactions aligned with its tokenization strategy.

cryptonews.ru11 dk önce

Ethena's USDe Captures 43% of Stablecoin Supply on Robinhood Chain for Capital Placement

cryptonews.ru11 dk önce

İşlemler

Spot
活动图片