
ZachXBT named Tiffany Milanovich, alleging she helped steal at least $5 million through crypto support-impersonation scams.
Author: Akshat Thakur
August 10th, 2026- On-chain investigator ZachXBT has named Tiffany Milanovich, a US-based woman he ties to at least $5 million in crypto theft. He published the claims in a 10-part thread on X on August 10.
High Signal Summary For A Quick Glance
Defileo🔮
@defileo
@zachxbt Why most of crypto scammers always "flex" and then go to jail 😭😭😭 Is that mentality? We don't know, anyways hope your investigation will help find her.
1/ Meet Tiffany Milanovich, a US based threat actor tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams. She's recorded herself taunting victims on calls after draining their funds. Tiffany openly flaunts luxury purchases, https://t.co/mRMD4yhWiz
12:24 PM·Aug 10, 2026
WenMoon 闻月 💚
@0xWenMoon
@zachxbt Gods work this one is hilarious She taunted her fellow scammer and that was her downfall. These retards fall like dominoes
1/ Meet Tiffany Milanovich, a US based threat actor tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams. She's recorded herself taunting victims on calls after draining their funds. Tiffany openly flaunts luxury purchases, https://t.co/mRMD4yhWiz
12:15 PM·Aug 10, 2026
Deebs DeFi 🛰
@Deebs_DeFi
@zachxbt just watched all the videos its one thing to steal its another level of sick to be proud of it and taunt people
1/ Meet Tiffany Milanovich, a US based threat actor tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams. She's recorded herself taunting victims on calls after draining their funds. Tiffany openly flaunts luxury purchases, https://t.co/mRMD4yhWiz
12:14 PM·Aug 10, 2026
Steady attention without excessive speculation.
According to ZachXBT, Milanovich worked as a caller in support-impersonation scams. She allegedly posed as staff from hardware wallet makers and crypto exchanges. Then she walked victims into handing over access to their funds.
ZachXBT describes Milanovich as the voice on the phone. In his account, she called victims while posing as Trezor or Coinbase support. She then pushed them to reveal seed phrases or approve transactions.
The thread accuses her of at least $5 million in thefts. That figure is a floor, not a full tally. So far, ZachXBT has itemized about $1.7 million across three incidents.
He also alleges she recorded herself taunting victims after each drain. Then she flaunted the proceeds online. According to the thread, she posted luxury purchases and casino gambling.
ZachXBT adds a few stranger details to the file. He says Milanovich altered flex videos to fake wallet ownership. In one clip, she posed as the owner of a Ledger Live wallet receiving about 7,700 JITOSOL.
She also allegedly shared a screenshot of a Connecticut search-and-seizure warrant. Its date predated several of the listed incidents. Still, ZachXBT presents it as part of the wider paper trail.
Milanovich has not publicly responded to the allegations. No law enforcement agency has confirmed her identity or filed charges. As a result, every claim here rests on ZachXBT’s reporting.
Support-impersonation scams follow a simple script. First, the attacker reaches a target by spoofed email or phone. Then they pose as support staff and claim an urgent security problem.
The caller guides the victim toward one fatal step. In many cases, that means entering a seed phrase or approving a transfer. Because private keys control the wallet, a single slip hands over everything.
Hardware wallets like Trezor and Ledger never expose the seed in normal use. So any request to type it into a site or app is a red flag. Once funds move on-chain, there is no reversal.
ZachXBT also names an accomplice behind the tooling. An actor using the aliases “bled” and “harm” allegedly supplied the phishing-panel infrastructure. That setup let the group spoof support pages and capture victim details.
Key milestones in the John Daghita (“Lick”) Exposé
First major theft linked to Daghita — approximately $500K drained from Coinbase accounts.
ZachXBT publicly exposes Daghita for stealing $46M+ from U.S. government-seized crypto. Tiffany records and trolls him; he retaliates by posting her name online.
Daghita flexes gains in a Discord “band 4 band” exchange and moves funds via Exodus wallet.
Daghita is arrested following the January exposure, per subsequent reporting on the case.
An alleged Connecticut search-and-seizure warrant related to Daghita is shared by Tiffany, providing additional legal context to the broader case.
Further theft of ~$1.2M linked to Trezor and BitcoinIRA-related accounts; Daghita flexes proceeds on Telegram.
ZachXBT releases the complete exposé thread, publicly documenting the full timeline of Daghita’s thefts, behavior, and connections.
ZachXBT backed the claims with specific wallet addresses. In October 2025, he says about $500,000 in Bitcoin left a Coinbase account. Around that time, Milanovich allegedly complained about her cut and posted a withdrawal screenshot.
By February 2026, she was flexing again on Discord. ZachXBT says she bragged about a haul and moved roughly $100,000 through Exodus. Later, related funds flowed into an Ethereum address through instant swaps.
That linked Ethereum address held about 631,000 DAI at a recent check. ZachXBT says instant exchanges and Monero funded that wallet. Meanwhile, its Ether balance stayed small.
The largest documented case came in June 2026. According to ZachXBT, roughly $1.2 million in Bitcoin and Ether drained from a Trezor. The victim first received a spoofed BitcoinIRA email under the alias Patricia Massie.
Much of that June haul reportedly sat dormant afterward. The investigator also flagged the Shuffle casino. He says Milanovich gambled stolen funds there while mocking a victim, and Shuffle later locked the account.
The thread connects Milanovich to John Daghita, known online as Lick. ZachXBT exposed Daghita in late January 2026 over an alleged $46 million theft. Those funds came from crypto seized by the US government.
According to ZachXBT, Milanovich recorded and trolled Daghita during that period. In response, he posted her name in a public Telegram channel. That post helped tie the alias to a real identity, the thread claims.
The case is a blunt reminder for anyone holding crypto. Real support teams never ask for your seed phrase. So treat any such request as an attack, whether by phone or by email.
Verify contact through official apps and websites, not inbound calls. Also slow down when someone pushes urgency on you. In most drains, that pressure is the whole point.
The thread spread fast across crypto news within the hour. Aggregators including TechFlow, Odaily, and ChainCatcher summarized ZachXBT’s account. Their write-ups tracked his claims closely, with no conflicting details.
Larger Western outlets stayed quiet at first. Early reaction on X leaned heavily toward ZachXBT, with many calling for prosecution. Still, no one had publicly disputed the identification.
No charges have followed the thread so far. Still, ZachXBT argues the paper trail is hard to ignore. He points to chat logs, recordings, and on-chain data as evidence.
For now, the Tiffany Milanovich allegations rest with ZachXBT and the crypto community. The next move belongs to law enforcement and any victims who step forward.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
ZachXBT Ties Tiffany Milanovich to $5M Crypto Scams
Bybit Sues North Korea and Lazarus Group Over $1.5B Crypto Hack
Coldcard Vulnerability Drains $70M From Bitcoin Wallets
Bybit Disavows “BILLI” Token and BybitBilli Account as Scam
ZachXBT Ties Tiffany Milanovich to $5M Crypto Scams
Bybit Sues North Korea and Lazarus Group Over $1.5B Crypto Hack
Coldcard Vulnerability Drains $70M From Bitcoin Wallets
Bybit Disavows “BILLI” Token and BybitBilli Account as Scam