ZachXBT Exposes Alleged $5M Crypto Scam
ZachXBT traces an alleged $5M crypto theft network using fake support calls, social engineering, wallet drains & onchain evidence.
Join Our Internship Program
Apply Now →On-chain investigator ZachXBT has published a new investigation linking U.S.-based Tiffany Milanovich to at least $5 million in alleged cryptocurrency thefts involving hardware wallet & centralized exchange support impersonation scams.
According to ZachXBT, Milanovich allegedly operated as a “caller” within a wider threat group, contacting victims while pretending to represent crypto platforms or wallet providers & convincing them to hand over access to their funds. The investigation spans incidents between October 2025 & June 2026 and includes wallet addresses, phone recordings, Telegram messages, Discord activity, screenshots & on-chain transaction trails.
How the Alleged $5M Support Scam Operated
Milanovich allegedly acted as the person who directly contacted victims, posing as customer support from hardware wallet companies, exchanges or other crypto services. The objective was not necessarily to break wallet encryption or compromise blockchain infrastructure. Instead, the attacker allegedly persuaded victims to surrender credentials, approve actions or otherwise provide access to their holdings.
A similar weakness was visible during an Ethereum phishing attack that drained $585K in 11 hours, where malicious approvals rather than a flaw in Ethereum enabled attackers to access user assets.
The pattern extends across the ecosystem. EtherWorld recently reported that hundreds of wallets were drained across multiple EVM chains, with potential attack vectors including spoofed interfaces, malicious approvals, blind signing & social engineering.
ZachXBT's latest investigation alleges that Milanovich went even further by recording interactions with victims, sharing material from the thefts & openly displaying luxury spending and cryptocurrency balances online. He claims this behaviour ultimately contributed to a significant digital evidence trail.
From a $1.2M Trezor Theft to a $500K Coinbase Drain
One of the largest incidents identified by ZachXBT allegedly occurred in June 2026, when a victim lost approximately $1.2 million in Bitcoin & Ethereum. According to the investigation, attackers used a spoofed BitcoinIRA email while operating under the alias “Patricia Massie.” The victim's Trezor wallet was subsequently drained.
He further claimed that Milanovich began displaying the proceeds in Telegram groups shortly afterwards. Another threat actor using the aliases “bled” & “harm” allegedly provided phishing-panel infrastructure used during the operation.
The case is another reminder that even hardware wallets cannot protect users if attackers successfully manipulate the wallet owner. EtherWorld recently examined this distinction after the COLDCARD exploit exposed weaknesses around hardware wallet security. That incident involved a different attack vector, but both cases challenge the assumption that self-custody automatically eliminates security risk.
ZachXBT also highlighted an earlier incident from October 2025, when Milanovich & associates allegedly drained approximately $500,000 in Bitcoin from a Coinbase account. He claimed Milanovich was later recorded complaining about her share of the stolen funds & posted evidence of a withdrawal herself.
Support impersonation involving centralized exchanges has become particularly dangerous because attackers can use information about account balances, transaction history or user identities to make fraudulent calls sound credible. Following Coinbase's previous security incident, EtherWorld reported how exposed customer information was allegedly used for social engineering scams impersonating Coinbase representatives.
1/ Meet Tiffany Milanovich, a US based threat actor tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams.
— ZachXBT (@zachxbt) August 10, 2026
She's recorded herself taunting victims on calls after draining their funds.
Tiffany openly flaunts luxury purchases,… pic.twitter.com/mRMD4yhWiz
Wallet Trails, Gambling & the John Daghita Connection
Another episode documented by ZachXBT allegedly occurred in February 2026 during a Discord call between Milanovich & another threat actor. According to the investigation, participants were doing “band 4 band,” comparing crypto balances to prove who controlled more assets. Milanovich allegedly transferred approximately $100,000 into an Exodus wallet during the call.
He stated that the address later held roughly 631,000 DAI & had been funded through multiple instant exchanges involving Monero. Independent investigators have increasingly become part of crypto's security infrastructure. ZachXBT, for example, received support during the Ethereum Security QF round, which closed with a 637 ETH matching pool, reflecting ecosystem demand for public threat intelligence & investigative work.
The latest investigation also overlaps with ZachXBT's earlier work involving John Daghita, known online as “Lick.” ZachXBT previously alleged that Daghita was connected to approximately $46 million in cryptocurrency stolen from assets seized by the U.S. government.
According to the new thread, Milanovich had a relationship with Daghita & allegedly recorded one of their calls before circulating it. Daghita later shared her name through his public Telegram channel.
ZachXBT also alleges Milanovich gambled with funds belonging to a victim on crypto casino Shuffle while communicating with that victim. He stated that he reported the activity to Shuffle & that the platform reviewed the evidence before confirming the account would be locked.
Milanovich also allegedly shared what appeared to be a Connecticut search-and-seizure warrant against herself. ZachXBT said the document was dated before several of the incidents covered in his thread.
Why Social Engineering Is Becoming Crypto's Biggest Security Problem
In April, EtherWorld reported that more than $635 million was lost across DeFi exploits during the month. Importantly, not all losses came from protocol vulnerabilities. Social engineering & user-targeted attacks were emerging as major attack surfaces.
The Lazarus Group's latest Mac-focused crypto malware campaigns have combined malware with fake meetings, search manipulation & social engineering. Meanwhile, MetaMask has warned users about malware targeting crypto wallets, reinforcing how asset security increasingly depends on devices, applications & user behaviour as much as the blockchain itself.
Even older tools remain relevant. Services such as Revoke.cash allow users to identify & revoke dangerous token approvals, although no tool can recover assets once a user voluntarily shares a seed phrase or private key with an attacker.
Governments are also beginning to pay greater attention to these attack models. EtherWorld previously covered a U.S. Senate proposal for a federal task force focused specifically on cryptocurrency scams, reflecting growing recognition that crypto fraud requires specialised coordination between platforms, investigators & law enforcement.
Social engineering can allow criminals to bypass sophisticated security systems without breaking the underlying blockchain. But once funds move onchain, transactions can create a permanent record that investigators can combine with offchain evidence.
ZachXBT said Milanovich had left behind extensive chat logs, recordings & on-chain data, arguing that the evidence could eventually result in legal consequences.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- What the COLDCARD Exploit Means for Crypto?
- New QR Code Scam Drains Hardware Wallet Funds
- Ethereum Phishing Attack Drains $585K in 11 Hours
- Hundreds of Wallets Drained Across EVM Chains, ZachXBT Warns
- Legacy Ethereum Wallets Exploited as $800K Gets Drained
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.