
Onchain investigator ZachXBT has identified a US-based threat actor, Tiffany Milanovich, who is tied to at least $5 million in cryptocurrency thefts through fake support calls. According to his latest findings, Milanovich worked as a 'caller,' phoning victims while posing as support staff and talking them into surrendering access to their funds. The investigator reported that she recorded herself taunting victims after draining them of their assets. As reported by ZachXBT, Milanovich worked as part of a group where a separate actor using aliases 'bled' and 'harm' supplied the phishing-panel infrastructure. The claims remain allegations unless confirmed by law enforcement or court records, with ZachXBT noting that the evidence trail includes blockchain transactions, chat logs, call recordings, Telegram activity, and social media posts. No law enforcement agency has confirmed her identity or filed charges, and Milanovich has not publicly responded to the allegations. ZachXBT has published blockchain addresses connected to the movement of the stolen cryptocurrency, providing concrete evidence of the theft operations.
The scheme involved impersonating hardware wallet and centralized exchange support services, with Milanovich serving as the primary caller. In June 2026, a victim lost $1.2 million in Bitcoin (BTC) and Ethereum (ETH) after the group drained the victim's Trezor wallet following a spoofed BitcoinIRA email sent under the alias 'Patricia Massie'. According to ZachXBT's report, some 'flex' videos appear to have been altered to inflate the apparent size of the thefts, as the crypto sleuth noted. Fake support scams work by creating urgency, with attackers claiming account risks and pushing victims to act quickly. The report emphasizes that real support teams do not need your seed phrase or ask you to move funds to a 'safe' wallet. Support-impersonation scams follow a simple script where attackers reach targets by spoofed email or phone, pose as support staff, and claim urgent security problems, guiding victims toward entering seed phrases or approving transfers. The caller would allegedly guide the victim through a series of steps involving their wallet or exchange account, by the time the victim realised something was wrong, the funds had already been moved.
According to ZachXBT's report, an earlier theft in October 2025 cost a victim $500,000 in Bitcoin after the group drained a Coinbase account. The investigator noted that Milanovich complained about her cut and posted a screenshot of the withdrawal herself. A February 2026 incident added context when Milanovich joined a Discord call with another threat actor and flexed wallet balances. One address linked to the activity reportedly held a large DAI balance funded through exchange activity involving Monero. The bulk of the stolen funds remain dormant onchain, indicating the scale of these ongoing operations in the cryptocurrency sector. ZachXBT has itemized about $1.7 million across three documented incidents, with the $5 million figure representing a floor rather than a complete tally. The alleged bragging, recordings, and online activity may have made the trail considerably easier to follow.
As reported by ZachXBT, Milanovich openly displayed stolen proceeds, luxury purchases, and casino gambling on social media. The investigator alleged that she allegedly gambled a victim's funds at a crypto casino. After ZachXBT submitted evidence, the platform Shuffle reportedly reviewed the account and moved to lock it. The thread connects Milanovich to John Daghita, known online as Lick, whom ZachXBT exposed in January for allegedly stealing crypto seized by the US government. According to the new report, Milanovich recorded a call with Daghita and shared it to mock him, with Daghita then allegedly posting her name in a Telegram channel. Additional details include Milanovich allegedly sharing a screenshot of a Connecticut search-and-seizure warrant whose date predated several listed incidents. Shortly after the theft, Tiffany began flexing it in Telegram groups.
According to FBI data reported by ZachXBT, FBI data logged more than 80,000 tech-support and government-impersonation complaints in 2025, with losses above $2.9 billion. Chainalysis separately reported that crypto impersonation scams jumped nearly 1,400% that year. The investigator noted that the bulk of the stolen funds remain dormant onchain, indicating the scale of these ongoing operations in the cryptocurrency sector. Crypto users should treat this case as a reminder to tighten security habits, never sharing seed phrases, recovery phrases, private keys, or two-factor codes. Hardware wallet and exchange users targeted by fake support calls and spoofed emails, who face irreversible loss if they share a seed phrase. The same blockchain records that can be exploited to move stolen money can also help investigators follow it, as demonstrated in this case where the alleged bragging, recordings, and online activity made the trail considerably easier to follow.