BTC $64,834.82 -0.21%
ETH $1,906.82 -0.58%
BNB $602.24 -0.33%
XRP $1.02 -0.92%
SOL $76.58 +0.21%
TRX $0.3315 +0.57%
DOGE $0.0697 -0.52%
ADA $0.1963 -0.03%
BCH $215.27 -0.63%
LINK $8.27 -0.24%
HYPE $54.68 +0.76%
AAVE $91.22 +0.10%
SUI $0.6923 +0.11%
XLM $0.1629 -0.06%
ZEC $503.88 -3.59%
BTC $64,834.82 -0.21%
ETH $1,906.82 -0.58%
BNB $602.24 -0.33%
XRP $1.02 -0.92%
SOL $76.58 +0.21%
TRX $0.3315 +0.57%
DOGE $0.0697 -0.52%
ADA $0.1963 -0.03%
BCH $215.27 -0.63%
LINK $8.27 -0.24%
HYPE $54.68 +0.76%
AAVE $91.22 +0.10%
SUI $0.6923 +0.11%
XLM $0.1629 -0.06%
ZEC $503.88 -3.59%

ZachXBT: American female scammer impersonates customer service to steal over 5 million dollars in cryptocurrency assets

2026-08-10 20:17:57

On-chain detective ZachXBT posted that U.S. threat actor Tiffany Milanovich participated in the theft of approximately $5 million in crypto assets by impersonating hardware wallet and centralized exchange customer service.

Her methods included disguising as Bitcoin IRA email support, during one attack transferring about $1.2 million in BTC and ETH from the victim's Trezor wallet, and in another case stealing about $500,000 in BTC from a Coinbase account. Tiffany induced victims to hand over access to their funds under the guise of "customer service calls," later boasting about the stolen money on social media and Telegram groups, mocking victims with recordings, and collaborating with other threat actors to launder money using phishing panels and instant exchange services, with some of the stolen funds still dormant on-chain.

The threat actor codenamed "Tiffany" is suspected of participating in multiple crypto asset thefts, gambling the stolen funds at crypto casinos. The platform Shuffle has frozen related accounts based on evidence submitted by ZachXBT; Tiffany previously shared a search and seizure warrant from Connecticut, dated before some of the incidents involved.

ZachXBT has obtained chat logs, recordings, and on-chain evidence, anticipating that this individual may face further legal consequences. This threat actor is also linked to the John Daghita (Lick) case, who is suspected of stealing over $46 million in crypto assets from a U.S. government-seized wallet.

app_icon
ChainCatcher Building the Web3 world with innovations.