TL;DR: π Blockchain investigator ZachXBT ties U.S.-based operator Tiffany Milanovich to $5M+ in thefts involving hardware-wallet and exchange-support impersonation scams...then documents her allegedly flexing the stolen funds on Telegram, gambling with victim money mid-call, and even sharing a search-and-seizure warrant against herself.
The blockchain didn't forget any of it.
π¨ Crypto Scammers Are Getting Smarter
Then one of them goes and posts a screenshot of the withdrawal.
That's the story blockchain investigator ZachXBT just laid out in a new investigation naming Tiffany Milanovich, a U.S.-based operator he ties to at least $5 million in hardware-wallet and exchange-support impersonation scams.
Her alleged role: the "caller."
The person who phones the victim, poses as crypto support, and talks them into handing over access to their funds.
What separates this case from the usual scam writeup isn't just the theft.
It's the trail she allegedly left behind.
π¬ Chat logs
ποΈ Phone recordings
π± Telegram posts
π» Discord calls
πΈ Screenshots
π Wallet addresses
βοΈ On-chain transactions
Even social posts allegedly flexing the proceeds.
The blockchain didn't forget any of it.
π° The $1.2 Million Trezor Job
The biggest single hit allegedly happened in June 2026.
A victim lost roughly $1.2 million in BTC and ETH after attackers spoofed a BitcoinIRA email under the alias "Patricia Massie" and drained a Trezor wallet.
ZachXBT identified the theft addresses:
βΏ BTC
bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy
Ξ ETH
0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c
Then, allegedly, Milanovich started showing off the funds in Telegram groups almost immediately.
Another actor operating under the aliases "bled" and "harm" appears to have supplied the phishing infrastructure behind the operation.
According to ZachXBT, most of the stolen funds had not moved and remained dormant.
Worth remembering:
β οΈ A dormant wallet isn't a safe wallet.
Every transaction that funded it is still sitting there, permanently visible.
π΅ $500K Off a Coinbase Account
A separate incident from October 2025 allegedly saw Milanovich and associates drain about $500,000 in BTC from a Coinbase account.
ZachXBT says she was recorded complaining about her cut of the theft, and later posted a screenshot of the withdrawal herself.
Addresses tied to that theft:
bc1qw3mej5hx7jhtdagqwt7ljls7wzkda2tym3w0d2
bc1q2r2tjdlcp3s4399g6v0xfamcw40xs5553qx7dx
This is the pattern that makes on-chain sleuthing so effective:
The ledger shows where the money went.
But the social-engineering trail of calls, screenshots, messages and recordings can help investigators connect that activity to a real person.
π€ "Band 4 Band" With Stolen Crypto
The strangest chapter may have happened in February 2026.
Milanovich allegedly participated in a Discord call with another threat actor in a crypto version of "band 4 band" comparing balances to prove who was holding more money.
ZachXBT says she allegedly moved approximately $100,000 through an Exodus wallet:
0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc
ZachXBT traced that wallet forward and says it now holds approximately 631,000 DAI, funded through multiple instant exchanges involving Monero.
π΅οΈ Privacy-preserving assets and services can complicate the trail.
They don't necessarily erase the surrounding activity.
The more pieces an investigator can connect, wallets, timestamps, exchanges, communications and counterparties, the more complete the picture becomes.
π The Daghita Connection
This case also overlaps with another ZachXBT investigation.
In late January 2026, ZachXBT exposed John Daghita, known online as "Lick," alleging that he stole approximately $46 million in cryptocurrency seized by U.S. authorities.
Milanovich was reportedly close to Daghita.
According to ZachXBT, she recorded one of their calls and shared it to troll him.
Daghita subsequently posted her name in his public Telegram channel.
Crypto crime investigations rarely stay confined to one wallet.
Often, it's the social graph,Β who knows whom, who trusts whom, and who eventually turns on whom, that helps crack a case open.
π° Casino Money, Mocking Calls
One of the uglier allegations is that Milanovich gambled with a victim's stolen funds while simultaneously calling and mocking the victim.
ZachXBT says he reported the account to Shuffle, which reviewed the evidence and confirmed that the account would be locked.
He also claims some of Milanovich's "flex" content was staged.
One example involves a Ledger Live clip allegedly showing the receipt of approximately 7,700 JitoSOL while appearing to impersonate the owner of a service hot wallet.
In other words, even the bragging may not have been entirely real.
That detail is almost as revealing as the alleged thefts themselves.
The apparent desire wasn't simply to steal money.
It was to look rich while doing it.
π The Warrant She Posted Herself
Maybe the wildest detail is this:
Milanovich allegedly shared a search-and-seizure warrant against herself.
According to ZachXBT, the warrant was issued in Connecticut and predates several of the incidents discussed in the investigation.
Separately, he references a recording in which she discusses a booked flight while claiming her funds remain untouched.
Individually, any one piece of evidence has limitations.
Stack them together with timestamps, wallet transactions, Telegram messages, Discord recordings, social posts and recordings, and you can begin constructing a timeline.
And timelines are what make blockchain investigations so powerful.
π§ The Real Takeaway
Crypto isn't anonymous.
It's pseudonymous.
Nobody necessarily knows who controls an address when they first see it.
But once investigators establish that connection, the historical activity associated with that address can become extremely valuable evidence.
That's the toolkit investigators like ZachXBT are running:
π§© On-chain analysis
π± Social-media activity
π¬ Telegram and Discord logs
ποΈ Recorded calls
πΈ Screenshots
π΅οΈ Identity and relationship mapping
βοΈ Cross-chain tracing
Stack enough of those pieces together and the trail can become extraordinarily difficult to explain away.
π‘οΈ The Blockchain Keeps Receipts
None of this happened because ZachXBT broke Bitcoin or cracked a Trezor.
It happened because someone allegedly opened the doorΒ to a spoofed email, a fake support call, a manufactured emergency.
No legitimate crypto support representative needs your seed phrase, your hardware wallet recovery phrase, or remote access to your computer.
If someone's creating urgency around your holdings, that's the tell.
Stop. Verify. Then act.
These attacks don't need to break Bitcoin.Β They don't need to crack Ethereum.Β They don't need to hack your Trezor.Β
They just need to convinceΒ you to open the door.
The other irony is that the alleged operator didn't just steal millions, but she allegedly documented much of it herself.
πΈ The screenshots.
ποΈ The calls.
π± The Telegram posts.
π» The Discord conversations.
π€ The flexing.
π° The bragging.
π The alleged taunting of victims.
All of it potentially becomes evidence.
You can delete a post, change a username, move funds between chains, and hide behind an alias.
But you can't rewrite yesterday's blockchain.
It doesn't care who you are.
It just keeps the receipts.
π Original investigation by ZachXBT:
https://x.com/zachxbt/status/2086785482487456201
β οΈ Disclaimer
This article summarizes allegations and investigative claims published by blockchain investigator ZachXBT. It is not a finding of criminal guilt, and the allegations described above should not be treated as a judicial determination.
Not financial advice.