Loading market data...

ZachXBT Identifies US Woman Behind $5M in Crypto Support Scams

ZachXBT Identifies US Woman Behind $5M in Crypto Support Scams

Blockchain investigator ZachXBT has identified Tiffany Milanovich, a US-based threat actor, as the person behind at least $5 million in crypto thefts using hardware wallet and exchange support impersonation. The scams drained a Trezor wallet and a Coinbase account, with victims losing over $1.7 million combined.

The impersonation playbook

Milanovich worked as a "caller," posing as support staff to trick victims into handing over access. In June 2026, a victim lost $1.2 million in BTC and ETH after a spoofed BitcoinIRA email under the alias "Patricia Massie" led to a drained Trezor wallet. Earlier, in October 2025, another victim lost $500,000 in Bitcoin after a Coinbase account was drained. The method was consistent: fake support contact, social engineering, and a quick exit.

Taunting and flaunting

After draining accounts, Milanovich didn't just disappear. She recorded herself mocking victims, gambled stolen funds at a casino, and flaunted luxury purchases on social media. She even went "band 4 band" with another threat actor on a Discord call, showing balances to prove who held more. But some of that was theater — she altered videos to make it look like she had stolen more than she actually had, including pretending to own a service hot wallet that received 7.7K JITOSOL.

The money trail

Milanovich moved $100,000 to an Exodus wallet, which now holds 631,000 DAI, funded through multiple instant exchanges from Monero. Most of the stolen funds haven't moved and remain dormant. That's a common pattern — the money sits until the heat dies down, or until the actor gets sloppy.

Connections and loose ends

Milanovich is connected to John Daghita (Lick), who allegedly stole $46 million in seized crypto from the US government. She recorded him and shared the recording to troll him. She also shared a screenshot of a search and seizure warrant against her in Connecticut, dated before several of the incidents. Another threat actor using aliases "bled" and "harm" provided the phishing panel infrastructure. ZachXBT reported her account to Shuffle, which reviewed evidence and confirmed the account would be locked. She mentioned a booked flight and said her funds remained untouched in a separate recording.

The investigation is ongoing, and the dormant funds remain a target for recovery efforts. Whether Milanovich faces charges in Connecticut or elsewhere is still an open question.