← Radar

Incident case file

Sign in to watch

Tiffany Milanovich — Crypto Support Impersonation Fraud Network

Incident date 2026-08-09Last updated Aug 20, 2026

3 views

ActiveBitcoinEthereumCoinbaseSocial engineering — Support impersonation phone fraud networkCluster: TFM-PHI-2026-08

Estimated loss

$5M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

Tiffany Milanovich (US-based, real name published by ZachXBT with on-chain evidence on Aug 10, 2026). Alias: Patricia Massie (used in BitcoinIRA phishing). Telegram handles: @tiffany (member of fraud marketplace t.me/edge). Known associates: @disappear (Telegram co-caller), John Daghita ('Lick', arrested March 2026). Network infrastructure: t.me/trezor666 (17,031 subscribers — caller recruitment channel). Known Bitcoin theft wallets: bc1qw3mej5hx7jhtdagqwt7ljls7wzkda2tym3w0d2 | bc1q2r2tjdlcp3s

Funds moved to

Multi-chain: stolen Bitcoin (Oct 2025: ~$500K) retained in bc1qw3mej... and bc1q2r2t... wallets. Stolen Ethereum-based assets (Feb 2026: ~$100K) converted to DAI; 631K DAI sits in 0x0b8cf7c3... (funded via Monero to break trail). Bitcoin IRA drain (June 2026: ~$1.2M) — destination wallets partially identified by ZachXBT but not all publicly disclosed. Casino: Shuffle account locked after ZachXBT report (funds transferred in before lock). Monero used extensively to break traceability.

Linked

Fraud marketplace: t.me/edge (admins: @cool, @kingpin; proxy fee 10%; Tiffany listed as member alongside @flesh, @cybercriminal, @pistol, @philosopher, @antihero, @promethazine). Recruitment channel: t.me/trezor666 (17,031 subscribers; offering 'mail callers' for Dubai+UK, panel + mailer, 900 per % CC only). Known victim types: Bitcoin IRA customers (June 2026 — alias Patricia Massie, Ticket #196653), Coinbase users (Oct 2025), crypto holders via Trezor support impersonation. ZachXBT investiga

Chronology

7 beats
  1. August 10, 2026 — ZachXBT published a detailed investigative thread naming Tiffany Milanovich as the operator of a multi-victim crypto support impersonation fraud network responsible for more than $5M in cumulative thefts.

  2. October 2025: Tiffany and her network drained ~$500K in Bitcoin from a victim's Coinbase account via phone-based social engineering — impersonating Coinbase customer support. Bitcoin proceeds sent to wallets bc1qw3mej... and bc1q2r2t...

  3. February 2026: Tiffany participates in a 'band 4 band' flex on a Discord call, showing balances to prove holdings. ~$100K in an Exodus wallet. Ethereum address 0x0b8cf7c3... now holds 631K DAI, funded through Monero via instant exchanges.

  4. June 2026: BitcoinIRA phishing operation. Tiffany operates under alias 'Patricia Massie' and sends spoofed BitcoinIRA support emails (ticket #196653, dated 06/19/2026) to victims, directing them to fake verification portals to harvest credentials. ~$1.2M drained.

  5. June 2026: Tiffany is recorded on a phone call gambling a victim's stolen funds on a casino (Shuffle) while mocking the victim. Video evidence shared within her network.

  6. August 10, 2026, ~12:03 UTC: ZachXBT publishes full investigation thread (tweet 2086785502750138684) with on-chain evidence, wallet addresses, audio/video recordings, and network mapping. August 10: Shuffle casino confirms account will be locked after reviewing ZachXBT's evidence. John Daghita ('Lick'), a known associate, had been arrested in March 2026.

  7. As of August 20, 2026: No formal charges against Tiffany Milanovich confirmed publicly. FBI warrant reportedly pre-existing per community sources. Investigation ongoing. Stolen funds not recovered.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)