On August 10, 2026, on-chain investigator ZachXBT published a thread naming Tiffany Milanovich, a US-based individual he alleges worked as the "caller" in a series of support-impersonation thefts totalling at least $5 million. The allegations are his — as of August 11, 2026, no law enforcement agency has publicly confirmed her identity, and no charges have been announced.
The name is trending. The more useful question is the one the coverage keeps skipping: this was not a hack. Nobody broke Trezor's firmware or cracked Coinbase's servers. A person picked up a phone, sounded credible for eleven minutes, and the victim moved the funds themselves. That is a defence problem, not a cryptography problem, and it is the part worth reading.
According to the thread posted at roughly 12:03 UTC on August 10, 2026, Milanovich's role in the crew was the voice. She allegedly phoned targets while posing as support staff from a hardware wallet vendor or a centralized exchange, walked them through a "security" procedure, and induced them to hand over access to their own funds.
ZachXBT lists two anchor incidents. In June 2026, a victim allegedly lost $1.2 million in BTC and ETH from a Trezor wallet after a spoofed BitcoinIRA email sent under the alias "Patricia Massie." In October 2025, roughly $500,000 in BTC was taken from a Coinbase account. He states that a separate actor operating as "bled" and "harm" supplied the phishing-panel infrastructure behind the campaigns, and that proceeds were discussed afterwards in Telegram groups.

Two details in the thread do more work than the dollar figures. First, he says she recorded herself taunting victims on those calls — meaning the crew kept audio of its own crimes. Second, he notes that some of the "flex" videos appear to have been edited to inflate the apparent size of the hauls, which is a caution against treating scammer self-reporting as data.
| Date | Target | Entry point | Reported loss | On-chain reference cited |
|---|---|---|---|---|
| Oct 2025 | Coinbase account | Support impersonation call | ~$500,000 in BTC | bc1qw3mej5hx7jhtdagqwt7ljls7wzkda2tym3w0d2; bc1q2r2tjdlcp3s4399g6v0xfamcw40xs5553qx7dx |
| Feb 2026 | — | Discord call comparing balances | Balance display, not a theft | 0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc (~631,000 DAI) |
| Jun 2026 | Trezor hardware wallet | Spoofed BitcoinIRA email, alias "Patricia Massie" | ~$1.2M in BTC and ETH | bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy; 0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c |
All figures and addresses as reported by ZachXBT on August 10, 2026. The bulk of the June proceeds were still dormant at the time of his post — a detail that matters, because dormant funds are recoverable funds if a seizure ever lands.
The DAI address is the most instructive line in the table. ZachXBT reports it was funded through multiple instant-exchange transactions originating from Monero. That is the modern laundering shape: take the traceable coin, push it through a privacy chain, come back out into a stablecoin on Ethereum where it sits liquid and spendable. The Monero leg is where conventional chain analysis loses the thread, which is precisely why the case was built on chat logs and call recordings rather than on transaction graphs alone.
Phishing panels are commodity infrastructure. Anyone with a few hundred dollars can rent one. Spoofed sender domains are trivial. The scarce input in this business is a person who can hold a stressed, suspicious victim on the line for ten minutes and sound like an employee.
That is the uncomfortable operational reality behind this case. FatMan, commenting on the thread, made the point bluntly: a caller who reads as a woman from a support desk clears the victim's threat model in a way a generic male voice often does not. Victims are trained by years of security advice to expect a scam to feel like a scam. A calm, apologetic, procedurally competent caller feels like the opposite.
The practical implication for anyone holding meaningful crypto: your instinct about whether a caller "sounds legitimate" carries no information. It is the single input the attacker optimizes hardest.
Reconstructed from the incidents ZachXBT describes, the sequence is consistent:
Step 5 is why hardware wallets did not help here. A Trezor faithfully signs whatever its owner approves. It has no opinion about why.
| Behaviour | Legitimate support | The impersonation call |
|---|---|---|
| Initiates contact | Rarely; usually responds to your ticket | Always calls you first |
| Asks for your recovery phrase | Never, under any circumstance | Frames it as "verification" |
| Asks you to move funds | Never | The core ask, dressed as a rescue |
| Creates time pressure | No | "Your funds will be drained in minutes" |
| Objects to a callback | No — encourages it | Discourages hanging up, stays on the line |
The single rule that defeats this entire class of attack: hang up and call back through a number or channel you found yourself. Every one of these operations dies at that step, which is why the caller works so hard to keep you from taking it.
None of these are exotic. All of them are boring, and boring is the point.
| Layer | Control | What it stops |
|---|---|---|
| Account | Withdrawal address whitelist with a cooling-off period | The panicked transfer to an attacker address |
| Account | 2FA via authenticator app, not SMS | Credential reuse and SIM-swap follow-ons |
| Wallet | Recovery phrase never typed into anything, ever | Seed extraction over a call |
| Process | Callback rule on every inbound "support" contact | The entire pretext |
| Process | A second signer or a 24-hour delay on large moves | Sole-decision-maker failure |
Withdrawal whitelisting is the one most people skip and the one that matters most in this scenario, because it converts an instant loss into a delay the victim can wake up from. WEEX's own account security guide walks through enabling it alongside 2FA and session monitoring, and the broader account security and risk management guide covers the settings side. Exchange support desks, including WEEX's, will never ask for your password or seed phrase by phone, email, or social media.
The frequent takeaway from cases like this is "use a hardware wallet." That advice is now partly contested. On July 16, 2026, ZachXBT argued that hardware wallets are not the answer he once considered them and said he does not recommend them for storing significant funds, suggesting technically capable users consider a dedicated iPhone instead, citing the Secure Enclave and app sandboxing.
Reasonable people disagree with that, and it is a strong claim about a broad product category. But the underlying observation holds: in the June 2026 case the hardware wallet worked exactly as designed and the money left anyway. Device security and human security are different problems, and only one of them was under attack.
The second thing traders miss is the recovery window. Dormant stolen funds — like the June proceeds ZachXBT describes — are the cases where reporting fast actually changes the outcome. Exchanges can freeze; casinos can lock accounts, as Shuffle reportedly agreed to do after ZachXBT submitted evidence. The first hour after realising you have been drained is worth more than the next six months of forensics.
Not publicly, as of August 11, 2026. ZachXBT's thread includes a screenshot of a Connecticut search-and-seizure warrant he says predates several of the listed incidents, and he notes a connection to John Daghita, known online as "Lick," whom he previously linked to the theft of roughly $46 million in crypto that had been seized by the US government and who was arrested in March 2026. Milanovich is described as close to Daghita.
That is context, not a charging document. Everything in this article about Milanovich is an allegation by a private investigator, and the appropriate posture until a prosecutor files something is exactly that. WEEX's news desk covered the initial report on August 10, 2026.
1. Who is Tiffany Milanovich?
A US-based individual named by on-chain investigator ZachXBT on August 10, 2026 as an alleged participant in crypto support-impersonation thefts totalling at least $5 million. She has not been charged publicly, and the allegations have not been confirmed by law enforcement.
2. How much crypto is she alleged to have helped steal?
At least $5 million across multiple incidents, per ZachXBT. The two largest cited are roughly $1.2 million in BTC and ETH from a Trezor wallet in June 2026 and about $500,000 in BTC from a Coinbase account in October 2025.
3. Was Trezor or Coinbase hacked?
No. Both incidents as described are social engineering. The victims were persuaded to authorize transfers or surrender access themselves. No vendor exploit is alleged.
4. How do I tell a fake support call from a real one?
You cannot, reliably, from the call itself. Hang up and re-initiate contact through a number or in-app channel you look up yourself. Real support has no problem with that; an impersonator will try to keep you on the line.
5. What should I do in the first hour after being drained?
Contact the exchange or custodian immediately with the transaction hashes, file with your local law enforcement, and report the addresses publicly or to a chain-analytics contact. Stolen funds that sit dormant are the ones that occasionally get frozen or recovered.
6. Can stolen crypto that went through Monero be traced?
Generally not through the privacy leg itself. Investigators typically rebuild those cases from the edges — exchange deposits, instant-swap records, chat logs, and operational mistakes — rather than from the chain alone, which is what ZachXBT appears to have done here.
Crypto assets are volatile and self-custody is unforgiving; a transfer you authorize cannot be reversed, and partial or total loss of funds is possible. Social-engineering losses of the kind described here are almost never covered by any insurance or platform guarantee, because the transaction is technically legitimate — you signed it. Treat every unsolicited call, email, or message claiming to be exchange or wallet support as hostile until you have verified it through a channel you initiated. Never share a recovery phrase, private key, password, or 2FA code with anyone, including anyone identifying themselves as support staff. Details in this article reflect allegations published by ZachXBT on August 10, 2026 and reporting current as of August 11, 2026; no charges have been publicly confirmed, and the situation may change.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























