ZachXBT dug out an outrageously arrogant crypto female scammer.

Written by: Nicky, Foresight News

A phone call rings. The caller claims to be from an exchange’s security team, speaking in a professional yet urgent tone to tell you that abnormal activity has appeared on your account. They say you must immediately verify your identity and transfer assets to safeguard the funds. Meanwhile, on the other end of the line, someone is already starting to record—preparing to turn this harvesting operation into material for their next bragging post.

On the evening of August 10, on-chain investigator ZachXBT published a detailed investigative thread exposing how a fraudster in the United States operating under the alias Tiffany Milanovich managed to amass at least $5 million in cryptocurrency assets by impersonating exchange and hardware-wallet customer support. The thread also describes how, during phone calls, the scammer mocked the victims and publicly bragged about the stolen funds on social media. ZachXBT confirmed that she was a minor, and some media outlets cited reports that she was about 17 years old.

ZachXBT’s investigation shows that Tiffany Milanovich played the role of a “caller” in a诈骗诈骗 ring, directly calling victims and impersonating exchange or wallet customer support. She used scripts about account abnormalities, security verification, and the like to trick victims into handing over account access or their seed phrases, after which the assets were transferred.

This past June, a victim was led to a phone number impersonating customer support after receiving a forged BitcoinIRA phishing email. Ultimately, $1.2 million worth of Bitcoin and Ethereum in a Trezor wallet was transferred to two addresses involved in the case, and most of the funds remain dormant to this day. In October of last year, another victim’s $500,000 worth of Bitcoin from a Coinbase account was stolen using the same method. Afterward, Tiffany not only complained that her cut was too small, but also posted withdrawal screenshots herself.

What sets her apart from other scammers is that after successfully stealing money, she publicly bragged about it and mocked the victims. ZachXBT has disclosed an audio recording in which her call with a victim can be clearly heard. This February, she competed with other scammers on Discord by showing a balance of about $100,000 in an Exodus wallet. The related addresses still currently hold about 631,000 DAI. The funds came from repeated conversions of Monero through instant exchanges. She also used victims’ money to gamble at a Shuffle crypto casino, while simultaneously mocking the victim during the call. ZachXBT reported the relevant accounts to the platform and confirmed that they were locked. In addition, she is suspected to have edited multiple bragging videos to exaggerate the amount stolen.

Despite her high-profile behavior, Tiffany Milanovich did not operate public social media accounts under her real name. Her bragging and mocking behavior mainly took place in private channels such as Telegram groups and Discord calls, rather than public platforms like X or Instagram. Accounts on X with the same name or similar spelling either had extremely limited activity or had no association with this incident. Public records also show no evidence that she had previously been formally arrested, prosecuted, or convicted, and her education and work history appear to be blank. However, she did share screenshots of a Connecticut search and seizure warrant on her own, dated earlier than some of the alleged incidents involved in this case—suggesting that law enforcement may have been investigating her before, though the specific reasons and outcomes were not disclosed.

Links between her and other scammers in the industry also emerged in this investigation. In January, ZachXBT exposed that John Daghita was allegedly stealing $46 million in crypto assets from wallets seized by the U.S. government. Tiffany had close ties to Daghita; she recorded calls to mock him, while Daghita publicly revealed her name in a Telegram channel as retaliation. Daghita was arrested jointly by the FBI and French police on the island of Saint Martin in March of this year.

This kind of social-engineering scam involving impersonating customer support is not an isolated case in the crypto industry. In May of this year, ZachXBT previously disclosed that within a single week, Coinbase users lost about $45 million due to similar schemes. Several waves of customer-support impersonation from the end of 2024 to the beginning of 2025 led to more than $65 million being stolen. A 23-year-old man from New York, Ronald Spektor, was previously indicted for impersonating Coinbase’s elite customer support. He used stolen customer data to call victims, cumulatively defrauding nearly $16 million and involving about 100 victims.

In the earlier Chirag Tomar case, the perpetrator created a spoofed exchange website and guided victims to take actions by phone. The total theft exceeded $20 million. After pleading guilty in 2024, he was sentenced to 5 years in prison. Hardware-wallet users are also a key target. This year, there were even physical-mail scams in which fake Ledger and Trezor official letters were sent to users’ home addresses, with QR codes attached to诱导 people into entering seed phrases, as well as an incident where about $9.5 million was stolen shortly after a fake Ledger Live app was uploaded to Apple’s App Store—about two weeks later.

According to reports by organizations such as Chainalysis, in 2025 crypto impersonation scams increased by more than 1,400% year over year, and technical support/customer service impersonation complaints received by the FBI have resulted in annual losses in the hundreds of millions to billions of dollars. The root cause of these scams repeatedly occurring is that attackers exploit the trust users place in exchange and wallet brands, targeting users with weak security awareness or individuals holding large amounts of assets with precise attacks. And once crypto assets are transferred out, the transaction is irreversible. For ordinary users, the most basic line of defense is to always remember that exchanges and wallets will never proactively call to request seed phrases or ask you to transfer assets to so-called “safe addresses.” If you receive similar calls, hang up first and verify through official channels.