ZachXBT Exposes US Caller in $5M Crypto Support Impersonation Scams
On‑chain investigator ZachXBT has publicly linked a United States‑based individual, Tiffany Milanovich, to at least $5 million in stolen cryptocurrency. Working as a “caller” inside a broader fraud group, Milanovich would phone victims while posing as customer support for hardware wallets and centralised exchanges, persuading them to hand over access to their funds.
One of the most severe losses occurred in June 2026, when a victim lost $1.2 million in Bitcoin and Ethereum after the group drained a Trezor wallet. The attack started with a spoofed email purporting to come from BitcoinIRA, using the alias “Patricia Massie”. ZachXBT noted that the bulk of the stolen funds remains stationary on‑chain. An earlier raid in October 2025 drained $500,000 in Bitcoin from a Coinbase account. According to the investigator, Milanovich complained about her own cut and even posted a screenshot of the withdrawal.
Milanovich openly flaunted the proceeds of the thefts on social media, showing off luxury purchases and casino visits. ZachXBT added that some “flex” videos may have been edited to exaggerate the true scale of the hauls. The report also ties Milanovich to John “Lick” Daghita, whom ZachXBT had previously exposed for alleged theft of government‑seized crypto; Daghita was arrested in Saint Martin in March.
Inside the Operation: From Phishing Panels to Casino Splurges
The Caller’s Playbook: Impersonating Trezor and Coinbase Support
Milanovich’s role was to initiate direct contact with victims, posing as legitimate customer support for well‑known wallet and exchange brands. She would convince them to share credentials, seed phrases, or remote access, enabling the group to drain their accounts. Working alongside her, an individual using the aliases “bled” and “harm” supplied the phishing panels that mimicked genuine service interfaces, creating a seamless deception pipeline from fake email to fake support call.
On‑Chain Evidence and Social Media Bragging
ZachXBT’s tracing shows that most of the stolen crypto remains unmoved, sitting in identifiable addresses. This inactivity provides law enforcement a clear trail. Paradoxically, Milanovich herself left a digital footprint by posting screenshots of transactions and sharing recordings of calls, some of which revealed her mocking victims. The investigator pointed out that some social media videos flaunting wealth were manipulated to inflate the perceived scale of the thefts, but the core evidence tying her to specific wallets is on‑chain.
The Connection to John “Lick” Daghita
Milanovich’s circle included John Daghita, a figure already known to the crypto‑crime community. According to ZachXBT, Milanovich recorded a call with Daghita and shared the recording to embarrass him; Daghita retaliated by posting her name in a public Telegram channel. This personal feud helped investigators cross‑reference identities. Daghita’s own arrest in March added credibility to the broader group’s criminal profile.
Impersonation Scams Surge Industry‑Wide
The Milanovich case fits into a major trend. FBI data recorded over 80,000 complaints of tech support and government impersonation fraud in 2025, with losses exceeding $2.9 billion. Separately, Chainalysis reported that crypto‑specific impersonation scams jumped by nearly 1,400% that year, underscoring the scale of the threat that investigators like ZachXBT are now exposing.
How Crypto Users Can Protect Themselves from Impersonation Attacks
For individual crypto holders, the case highlights specific security gaps that thieves exploit. While the investigation is ongoing, users can immediately apply lessons from the reported methods:
- Verify support contacts independently. The group impersonated Trezor, Coinbase, and BitcoinIRA support. Never use phone numbers or links from an unsolicited message; always navigate directly to the official website or app to get genuine contact details.
- Never share seed phrases or login credentials over the phone. Legitimate support will never ask for a recovery phrase or password. The Trezor drain in the report began after the victim was tricked into handing over access, a reminder that full wallet control must never be given away.
- Scrutinize emails that claim to be from crypto services. The attack that cost one victim $1.2 million started with a spoofed BitcoinIRA email. Check sender addresses carefully and treat any unexpected request for immediate action with suspicion.
- Monitor on‑chain activity if you suspect a breach. Because the stolen funds in this case remain largely static, victims and exchanges may still have an opportunity to flag addresses and potentially pursue recovery through law enforcement.
Comments 0