Stealing millions of dollars in cryptocurrency required no blockchain vulnerability, no hardware wallet exploit, and no cryptographic attack. The method was considerably simpler – and considerably more effective. A victim would first receive a message warning of unauthorized access to their account. Shortly afterward, a caller posing as a support representative would contact them directly and persuade them to surrender their wallet recovery data. Independent blockchain investigator ZachXBT has linked an American woman named Tiffany Milanovic to a group he estimates stole no less than $5 million through this scheme. Law enforcement has not publicly confirmed charges against Milanovic, and the published findings remain the product of a private investigation.
The Social Engineering Playbook: Panic, Then the Reassuring Voice
The group staged each attack with methodical precision. A victim would receive a spoofed email appearing to originate from a cryptocurrency exchange, a hardware wallet manufacturer, or another familiar service – warning of suspicious activity on their account. Within minutes, Milanovic would call, introduce herself as a member of the support team, and urge the victim to act immediately to protect their funds.
The sequence was deliberate: first, provoke alarm; then, moments later, provide a calm and seemingly knowledgeable voice to resolve it. During the call, the victim was directed to a phishing page and persuaded to enter their seed phrase.
A seed phrase – also known as a recovery phrase – is a sequence of words that can be used to restore access to a cryptocurrency wallet on any compatible device. Trezor explicitly states that a wallet’s backup contains everything necessary to recover full access. Disclosing that sequence to a third party is functionally equivalent to handing over the wallet itself: the recipient can restore it on a separate device and transfer any associated funds at will.
Why Hardware Protection Cannot Stop This Attack
In this scenario, the hardware wallet’s protections are rendered entirely irrelevant. The attackers did not need to extract private keys from a Trezor device, circumvent its firmware protections, or identify any flaw in the underlying blockchain. They simply needed the recovery phrase from the owner directly. Once obtained, the assets could be swept to an attacker-controlled address – a transaction that, once confirmed on-chain, cannot be reversed through any support channel.
The $1.2 Million June 2026 Episode
One of the largest documented incidents occurred in June 2026. A Trezor owner lost approximately $1.2 million in Bitcoin and Ethereum. Before the phone call, the group had dispatched a spoofed message purportedly from BitcoinIRA, using the name Patricia Massey. ZachXBT identified an accomplice operating under the aliases “bled” and “harm” as having provided the phishing page infrastructure. A substantial portion of the stolen funds remained stationary on associated addresses in the aftermath.
Taunting Victims and Broadcasting the Spoils
Following successful thefts, Milanovic allegedly generated considerable incriminating evidence of her own making. She recorded phone conversations with victims she had already defrauded, mocked them after withdrawing their funds, and distributed those recordings through Telegram. Private channels featured video messages displaying stacks of cash and casino screens showing hundreds of thousands of dollars. During one call, a portion of the funds stolen from a victim mid-conversation was dispatched to the crypto casino Shuffle. After ZachXBT’s inquiry, the platform reviewed the materials and disabled the associated account.
Not all of the conspicuous displays reflected accurate figures. ZachXBT asserts that Milanovic edited certain clips to claim control over larger holdings than she actually possessed. In one recording featuring the Ledger Live interface, the presentation implied she had access to an operational hot wallet that had received approximately 7,700 JitoSOL. Hot wallets are internet-connected cryptocurrency wallets designed for fast, frequent transactions.
Discord Competitions, Monero Layering, and a Public Feud
In February 2026, Milanovic participated in a Discord “band 4 band” competition – a format in which participants display their wallet and account balances to establish who controls the most funds. During one session, she transferred $100,000 to an Exodus wallet. An address linked to her activity later held 631,000 DAI, which had arrived through several instant exchange services following transactions involving Monero.
DAI is a stablecoin – a cryptocurrency designed to maintain a value pegged to a reference asset, in this case the U.S. dollar. Monero operates on an altogether different principle: its developers built the protocol around transaction privacy, making it a frequent choice for those seeking to obscure the movement of funds. For the group described here, routing assets through Monero introduced an additional layer of separation between stolen cryptocurrency and subsequent addresses.
The web of connections around Milanovic’s circle was partially unraveled through a personal dispute. In January 2026, ZachXBT had linked a man named John Dagita – known online as “Lick” – to the theft of approximately $46 million in cryptocurrency previously seized by U.S. authorities. Milanovic had communicated with Dagita, recorded one of their conversations, and distributed the recording. Dagita retaliated by publishing her real name in a public Telegram channel. The ensuing quarrel publicly associated her online aliases with her actual identity.
Self-Published Evidence and the Limits of Obfuscation
Attempts to obscure the movement of funds through Monero, exchange services, and casinos proved far less effective than the group had anticipated. Phone recordings, chat messages, videos displaying account balances, posts about expenditures, and blockchain transaction data together allowed individual episodes to be corroborated and connected.
Among the materials that surfaced was a photograph of a search and seizure warrant issued in Connecticut, predating several of the thefts described in the investigation. In a separate audio recording, Milanovic referenced a flight she had booked and maintained that her funds remained untouched. ZachXBT stated that he had transmitted the collected materials to U.S. law enforcement.
The Real Lesson: Social Engineering Defeats Hardware Security
This case illustrates, with unusual clarity, the fundamental boundary of hardware-based cryptocurrency protection. A Trezor device keeps private keys offline and away from a conventional computer – but it cannot prevent its owner from voluntarily disclosing the recovery phrase to a convincing fraudster. The manufacturer itself warns that the backup word sequence grants full wallet access to whoever possesses it. Once an attacker has that phrase, the hardware device becomes immaterial.
In an investigation involving estimated losses of at least $5 million, the decisive evidence was not found in exploited code or compromised infrastructure. It resided in call recordings, chat logs, publicly displayed balances, and blockchain data – much of it placed in the open by the group’s own members.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.