On-chain investigator ZachXBT published a detailed thread on X on Monday alleging that Tiffany Milanovich, a U.S.-based individual, has been involved as a “caller” in a series of hardware wallet and centralized exchange support impersonation operations that resulted in at least $5 million in cryptocurrency losses for victims.
According to the investigation posted at approximately 12:03 UTC on August 10, 2026, Milanovich is said to have contacted victims by phone while posing as support staff from exchanges or wallet providers and induced them to grant access to their funds.
ZachXBT stated that she recorded herself taunting victims on those calls after the funds were moved and has publicly displayed luxury purchases, stolen balances, and casino activity on social media and in private groups.
One incident detailed in the thread occurred in June 2026, when a victim allegedly lost $1.2 million in Bitcoin and Ethereum from a Trezor wallet following a spoofed BitcoinIRA email sent under the alias “Patricia Massie.” ZachXBT listed the following addresses in connection with that transfer:
- bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy
- 0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c
He reported that Milanovich and associates later discussed the proceeds in Telegram groups. A separate threat actor using the aliases “bled” and “harm” is described as having supplied phishing-panel infrastructure. The bulk of those funds remained dormant at the time of the post.
The June 2026 incident involved funds taken from a Trezor hardware wallet. In a July 16, 2026 article, ZachXBT stated that “all hardware wallets are complete garbage” and said he does not advise using them for storing significant funds or signing important transactions. He recommended that technically competent users instead consider a dedicated iPhone, citing its Secure Enclave and app sandboxing as stronger protections against the kinds of social-engineering attacks that target hardware-wallet owners.
A second case cited by ZachXBT took place in October 2025, in which approximately $500,000 in Bitcoin was taken from a Coinbase account. The investigator provided these addresses:
- bc1qw3mej5hx7jhtdagqwt7ljls7wzkda2tym3w0d2
- bc1q2r2tjdlcp3s4399g6v0xfamcw40xs5553qx7dx
ZachXBT said Milanovich complained about her share of the proceeds on a recording and shared a withdrawal screenshot.
In February 2026, according to the same thread, Milanovich participated in a Discord call in which participants compared balances. An address linked in that context (0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc) currently holds approximately 631,000 DAI, consistent with the figure stated by ZachXBT. The address was funded through multiple instant-exchange transactions originating from Monero.
Connection to Prior Investigations
ZachXBT also noted a connection to an earlier case he publicized in late January 2026 involving John Daghita (also known as “Lick”), whom he had linked to the theft of roughly $46 million in crypto previously seized by the U.S. government. He got arrested in March 2026. Milanovich is described as having been close to Daghita; she recorded a call with him and shared it, after which Daghita posted her name in a public Telegram channel.
Additional material in the thread includes claims that Milanovich used a victim’s funds to gamble on the crypto casino Shuffle while speaking with the victim and that she shared a screenshot of a Connecticut search-and-seizure warrant whose date precedes several of the listed incidents.
ZachXBT reported the Shuffle account; the platform confirmed it would lock the account after reviewing the evidence he submitted. He further stated that some flex videos appear to have been altered to inflate the apparent size of the thefts.
ZachXBT concluded that Milanovich has left an extensive record of chat logs, call recordings, and on-chain activity and expressed the hope that legal consequences would follow.
Also read: Coinsbuy Wallets Drained For Over $7.9 Million on Ethereum and Tron
