Tiffany Milanovich
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5KNsSe…EMtzSummary
Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses. She is alleged to have operated as a 'caller' — the voice contact who phoned victims while impersonating customer support representatives for hardware wallet providers and centralized exchanges including Trezor, Coinbase, and BitcoinIRA — and is connected to other named threat actors and to John Daghita ('Lick'), arrested in March 2026 in connection with a $46 million theft of U.S. government-seized cryptocurrency. No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.
Connected Entities
10 entities · 60 linked investigations- John Daghita (aka Lick) — US Marshals Crypto Theft→mentioned with→Ethereum(65%)
- Ethereum→mentioned with→Coinbase(60%)
- John Daghita (aka Lick) — US Marshals Crypto Theft→mentioned with→ZachXBT(70%)
- Ethereum→mentioned with→Bitcoin(60%)
- Monero→mentioned with→Bitcoin(60%)
- Monero→mentioned with→ZachXBT(65%)
- Dean Daghita / CMDSS (Command Services and Support)→mentioned with→ZachXBT(70%)
- ZachXBT→mentioned with→Ethereum(70%)
- ZachXBT→mentioned with→Bitcoin(65%)
- Shuffle (shuffle.com)→mentioned with→Ethereum(60%)
- + 24 more
Connected Through
8 shared actors · 624 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Ethereumorganizationalso inEleven Drainer·0Amnokgang Technology Development Company·0Q2 2026 Bridge Exploit Wave·0KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus·0Faris Ali / UK Crypto Home Invasion Ring·0Voyager Digital·0The DAO Hack 2016·0Uniswap Google Ad Phishing Campaign (May 2026)·0A7A5 Stablecoin / Old Vector·0AI-Powered Crypto Phishing Infrastructure 2026·0Q2 2026 Record Crypto Hack Wave·0Blockchain Bandit·0Operation Economic Outcast — Iran Digital Assets Sectoral Sanctions (August 2026)·0MEV Bot Scam — YouTube AI Trading Bot Campaign (2026)·0$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0YieldBlox Stellar Oracle Manipulation Exploit (Feb 2026)·0CryptoZoo·0TraderTraitor / UNC4899·0TrueBit Oracle Exploit (January 2026)·0Mass Ethereum Address-Poisoning Wave (Dec 2025-Jan 2026)·0DPRK IT Worker Network (Overseas Scheme)·0DOJ Pig Butchering $25M Forfeiture 2026·0Lab·0Armstrong / Chindavanh / Rucker Crypto Robbery Gang·0H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost·0BonkDAO Treasury Governance Attack (July 2026)·0Bitcoin Latinum·0Google Coin / Fake Gemini AI Chatbot Presale Operation·0Inferno Drainer·0OLPC Token / PancakeSwap OLPC-LABUBU Pool·0Fake Trezor Support Social Engineering — $282M Heist·0Drift Protocol DPRK Exploit (April 2026)·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0BitMart Exchange — Insolvency Claims and Frozen Withdrawals (August 2026)·0ISIS-K Crypto Funding Network (OFAC July 2026)·0DeFi Governance Attack Wave 2026·0MiningMax·0DSJEX / BG Wealth Sharing·0fake Ledger Live app·0ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvester·0keyv / cacheable npm Supply Chain Attack — TeamPCP Mini Shai-Hulud (August 2026)·0Andean Medjedovic (KyberSwap / Indexed Finance Attacker)·0LAB / LABUSDT·0AI Agent Prompt Injection Crypto Attack Class (2026)·0OFAC Operation Economic Outcast — Iran Digital Assets Sectoral Sanctions August 2026·0H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23·0ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)·0"Claude AI" Crypto Arbitrage Bot YouTube Tutorial Scam·0Blender.io·0World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign·0Malone Lam·0WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)·0HECO Bridge & HTX Exchange Hack·1StableMagnet·2Compounder Finance·2Google Coin / Fake Gemini AI Chatbot Presale Scam·2Jonathan Spalletta·2Trenton Richard Johnston·2Donald G. Basile / Bitcoin Latinum (LTNM)·2Socket Security Malicious Browser Extension Campaign August 2026·2SudoRare·2USI-Tech·2Andean Medjedovic·2Bitpapa IC FZC LLC·2TurtleDex·2ETHTrustFund·2Robinhood Chain Scam Ecosystem·2Frosties NFT·2Andean Medjedovic — KyberSwap/Indexed Finance Fugitive, Active Laundering 2026·2Star Credit Holdings / Misam M. Abidi·2HyperVault·2Gotbit / Vortex / Contrarian / Antier Wash-Trading Ring·2Operation Token Mirrors — DOJ Crypto Market Manipulation Ring·2Bitforex·2QuadrigaCX / Gerald Cotten·2eXch·2Arbix Finance·2AnubisDAO·2Karatbars International·3FCoin·3M1llionz (RichMilly666)·3AudiA6 Mixing Service·3Kannagi Finance·3SIGMA Bot·4LAB Token (Smartliquid AI)·4zkLend (Starknet)·4CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)·4DxSale·4AscendEX Exchange·4ApeMars (APRZ)·4CLS Global FZC / ZM Quant Investment·4LAB Token·47zarc·4Raidparty·4LML/USDT staking protocol·4Friend Tech·4Kalax·5Venus Protocol THE Token Flash-Loan Exploit (March 2026)·5BitClave·5Grand Base·5luna·5GANA Payment·5Cashio·5WallStreetBets·50x327a81d0d128db8886d265be73c9fdda97194f30·5Nobitex·5Allbridge Core Second Flash-Loan Exploit (July 2026)·6Adform Ad-Tech Supply Chain Wallet Swap Attack·6Justin Sun·7Terra 2.0·7Nomad Bridge·8Zoth Protocol·8Rivus DAO·8Taiko L2 Bridge Exploit June 2026·8Roberto Zibert·8Truebit·8Allbridge Core — Second Flash Loan Exploit via Same Unpatched Vector·8C&M Software·8Harmony ONE (Protocol Entity)·8Rhea Finance Exploit (April 2026)·9Nobitex June 2025 Hack (Predatory Sparrow)·10Term Finance — Governance Exploit (August 2026)·10Qubit Finance·10Bunny Finance·10DEUS Finance·10Curio·10Taiko Ethereum L2 Bridge·10UwU Lend·10Inverse Finance Frontier·10Sheldon Xia (BitMart Founder)·10EasyFi·10June 2026 Cross-Chain Bridge Exploit ($127M, Three Protocols)·10Mixin Network·10xToken·10Polter Finance·10BearnFi·12Bidao·12Ploutos Money·12Raft Protocol·12DeepSnitch AI·12CrossCurve (formerly EYWA) Bridge Exploit (Feb 2026)·12Popsicle Finance·12PlayDapp·12LastPass·12BarnBridge·12Masa·12Summer.fi Lazy Summer Exploit (July 2026)·12XBridge·12Harmony Protocol (2026 ONE Token Exploit and L1 Shutdown)·12Beanstalk·12Allbridge Core Solana Flash Loan Exploit (July 2026)·14Terence Kwok — Humanity Protocol Staged Hack·14Ionic Money·14WEMIX / WEMIX$ Stablecoin·14Loopring DEX — Trustless Exit Disabled at Shutdown·14Garden Finance·14Voltage Finance·15BNB Chain Bridge·16Levyathan·18Bankr·18Cascade Protocol·18BounceBit L1 Exploit and Chain Shutdown (August 2026)·18OlympusDAO·18Tectonic Protocol·18MoonHacker·18FOMO Token·18Pond0x·18Humanity Protocol June 2026 Hack·18Fantasm Finance·18Dexible V2·18Noones·18Convergence·18HyPC·18Cetus CLMM·18CheeseBank·18Hedgey·18Transit Swap·18WAYGU CASH·18Tectonic / Cronos — August 2026 TONIC Price Manipulation Exploit·18Lodestar Finance·20ForceBridge·20Hinkal Protocol·20DuelBits·20Rhea Lend·20Verus Protocol (VRSC)·21Cork Protocol·22FEGex·22EdgeX / EDGE Token·22Gravity Bridge·22Triple-A Treasury Hack (July 2026)·22Hunter Biden ($LAPTOP token)·22DAO Maker Vesting·22ElasticSwap·22Resolv·22TAC Chain·22FutureSwap·22Lodestar V0·22Summer.fi (Lazy Summer Protocol)·22Wise Lending V1·22NowSwap·22Eclipse·22Earning.Farm·22Africoin·22Pike V1·22Term Finance·22Locus Finance·22mySwap CL Protocol (Starknet)·22RocketSwap Base·22Renzo·22Maya Protocol — August 2026 Six-Bug Exploit·22Arcadia Finance v1·22B² Network·23Aster (ASTER)·23Makina Finance·24Carrot Protocol·24Hyperbridge (Polkadot-Ethereum Bridge) — April 2026 Exploit·24zombies·25Coinsbuy·26Taiko·26Shuffle (shuffle.com)·26Frank DeGods·26Cronos Chain·26BullX·27Shibarium·28Nesa (NES)·28SharedStake·28Aperture LM·28PAAL AI·28Super Sushi Samurai·28DeFiTuna·28Verus Protocol·28Superfortune AI (GUA)·28Bunni Protocol·28Orion Pools·28Pike Finance·28TAC Network·28Kinto Bridge·28Aquifer AMM·28BtcTurk·28Remitano·28JRNY Crypto·28dForce Lending·28KyberSwap Classic·28Growth DeFi·28Spartans Bet·28Zcash Orchard Counterfeit Vulnerability·28CrossCurve·28UPCX·28Mixin Network·28Typus Perp·28GeniusAI·28Florence Finance·28EraLend·28Truflation·28Team Finance·28Gnosis Pay·28Moonbeam Network (GLMR)·28Ankr & Helio Protocol Hack·28Gala·28GemPad·28FOOM Cash·28SBI Crypto·28RISEx·29Lendf.me·30Evmos Network·30Tia·30Venice Token·30Symbiosis Finance BridgeV2 syBTC Exploit (September 2026)·30Tether Gold (XAUT)·31Nexera·32MANTRA Chain Upstream Exploit (August 2026)·32Vestra DAO·32Shibarium Bridge·32TempleDAO·32ChangeNOW·32Dolomite·32Blend Pools V2·32numa.·32Zinc·32LayerZero Labs·32Eleven Finance·32Roll·32CoinEx·32Kame Aggregator·32Gamma Strategies·33Apyx Finance·33Revert Lend·33The Sandbox (SAND OFT Exploit)·34Hyperdrive HL·35Steadefi·35Cod3x·36Aethir·36Panoptic V1.1·370x62d5a59e0d67c0381aad53b201b4a1b8dcd2c833·37MONA (Monavale / DIGITALAX)·38Chads NFT·38CoinDCX·38Astera.fi·38Polymarket — June 2026 Supply Chain Attack·380x5a76a2830859c321a50937a22fde571fbf4810f3·38Axie Infinity·38IoTeX·38The Sandbox SAND Bridge Exploit·38Amun·38Symbiosis Finance·38THORChain GG20 MPC Vault Exploit (May 2026)·38BitoPro·38USD1 (World Liberty Financial)·38Astrid Finance·38Hemi (Genesis Drop / MerkleBox Exploit)·38MustStopMurad·38Unilend V2·38Thunder Terminal·38WazirX·38StakeDAO — vsdCRV Deployer Key Exploit (May 2026)·38Rho Markets·38Kipseli·38M2 Exchange·38Inverse Finance·38KiloEx·38KAT katana-network·39M2·39Juicebox V3·40Bedrock Protocol·41Jump Trading·42Orion Protocol·42Balancer·42DGLD·42Midnight Network / NIGHT Token·42Chainflip·42Cozy V2·42YO Protocol·42Ambient Finance·42Polygon (POL)·44Midnight (NIGHT Token)·44SuperRare·45Binance·45Zilliqa·46Maestro·47Flash Trade·48Aptos·50ZRX (0x Protocol)·50Pendle·50Sky (MakerDAO)·51PeopleDAO·52Internet Computer·52Clober Liquidity Vault·52LCX Exchange·52THORChain·52Bittensor·52SushiSwap·52Leap Wallet·52GHO·53Ethereum Foundation·53Jupiter Perps·54Robinhood Crypto·54Fuse Wallet·54SushiSwap RouteProcessor Exploit·54Celestia·54LCX·54Flow·54Ethena·55Hedera·55Lulo·55Trust Wallet·55Exponent Finance·55Blast·55Kevin Rose·57Gnosis Pay Zodiac Delay Module Exploit·57Famous Fox Federation·57Allo Protocol·57ZKsync·57Sui·57Trezor·57Socket Protocol·58Linea·58Sei Network·58Scroll·58Aerodrome Finance·58Gemini Exchange·58Audius·58Synthetix·58Spicenet·58Euler Finance·58Yearn Ether·58Cega·58Eigenlayer·58Ethereum Classic·58Uniswap·58Ethena·58Crypto.com·58Polkadot·58Optimism·60Convex Finance·62Curve Finance·62Starknet·62Hyperliquid·62Raydium Protocol·62PAX Gold (PAXG)·62Curve DEX·62Raydium AMM·62Cointelegraph·62Ripple USD (RLUSD)·62Phantom Wallet·63Canton Network·63Ethereum·64Rocket Pool·64Kaspa·64Chainlink·67Safe{Wallet}·68Crossmint·70Lido Finance·70USD Coin (USDC)·71Circle USYC·73Marinade Finance·79ZachXBT·82BlackRock USD Institutional Digital Liquidity Fund (BUIDL)·82
- □ZachXBTorganizationalso inDean Daghita / CMDSS (Command Services and Support)·0Gurhan Kiziloz·0Gurhan Kiziloz (BlockDAG Co-Founder)·0$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0Blockchain Bandit·0Faris Ali / UK Crypto Home Invasion Ring·0Yelo (yelotree)·0Lab·0H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost·0Wojtek Kulisz aka Merry (SIM-Swap Gang)·0Ben 'BitBoy' Armstrong·0Inferno Drainer·0DSJEX / BG Wealth Sharing·0Poland SIM-Swap Crypto Theft Ring — June/July 2026·0LastPass threat actor·0Fake Trezor Support Social Engineering — $282M Heist·0LAB / LABUSDT·0Chris Larsen·0Gamer Crew $263M Social Engineering Ring (New Defendants)·0Drift Protocol DPRK Exploit (April 2026)·0fake Ledger Live app·0Malone Lam·0StableMagnet·2AnubisDAO·2SudoRare·2Jonathan Spalletta·2Aman Kesar India Crypto Scam Ring·2HQI Exchange·2Trenton Richard Johnston·2Blur Finance·2ETHTrustFund·2Gotbit·2HyperVault·2Bitforex·2Wiz Khalifa Pump Fun·2Iran War Panic Crypto Scam Network (ORAMAMA / X Account Manipulation)·2Mr. Parveen India Social Engineering Scam Ring·2Aqua·2eXch·2Malone Lam·2Vkevin·2M1llionz (RichMilly666)·3AudiA6 Mixing Service·3LAB Token (Smartliquid AI)·4AscendEX Exchange·4Brandon Michael Tardibone·4RaveDAO (RAVE Token)·4LML/USDT staking protocol·4Raidparty·4Friend Tech·47zarc·4Crypto Beast (ALT Token Influencer)·4LAB Token·4Undisclosed KOL Promo Network (ZachXBT Exposé, September 2025)·5Grand Base·5WallStreetBets·5JELLY·5GANA Payment·5Nobitex·50x327a81d0d128db8886d265be73c9fdda97194f30·5Sportsbet·6Rivus DAO·8Wonderland Finance·8Axiom DEX Insider Trading (Broox Bauer)·8C&M Software·8Nobitex June 2025 Hack (Predatory Sparrow)·10Sheldon Xia (BitMart Founder)·10UwU Lend·10BearnFi·12Rain Protocol (RAIN Token)·12Meteora / Benjamin Chow·12Abracadabra Money MIM Depeg June 2026·12ZachXBT Crypto Influencer Paid-Promotion Leak (200+ Influencers, September 2025)·12Gym Network·12Popsicle Finance·12LastPass·12Masa·12Tapioca DAO·12Terence Kwok — Humanity Protocol Staged Hack·14Ionic Money·14Shawn Liu·14Garden Finance·14Austin Fine (@xmrfine)·18MoonHacker·18JUDAO·18Skyward Finance·18Cyrus Finance·18Humanity Protocol June 2026 Hack·18Kroll·18Cetus CLMM·18Noones·18Concentric·18Alpha Finance Lab·18HyPC·18OKX DEX·18Convergence·18OcelotDex·18BTC24H·18CheeseBank·18Ionic Protocol·18ForceBridge·20FEGex·22EdgeX / EDGE Token·22XT Exchange·22ElasticSwap·22DeltaPrime·22Ratio Finance·22Locus Finance·22Wise Lending V1·22Axiom DEX Employee Insider Trading·22FutureSwap·22Shido·22Earning.Farm·22Eclipse·22RocketSwap Base·22Pike V1·22Renzo·22MYX Finance·22Geoffrey Woo / AntiHunter (ANTIHUNTER) Memecoin·22Arcadia Finance v1·22Molt EVM·22Shuffle (shuffle.com)·26PAAL AI·28SharedStake·28Aperture LM·28Orion Pools·28TBTFW (Beverly Hills Luxury Car Dealer — Crypto Laundering Vector)·28Kinto Bridge·28ALEX Lab·28Truflation·28Token 2049·28GeniusAI·28JRNY Crypto·28Growth DeFi·28KyberSwap Classic·28Moola Market·28OlaXBT·28UPCX·28CrossCurve·28BtcTurk·28Spartans Bet·28Portal·28SBI Crypto·28Level Finance·28Kronos Research·28Arthur Hayes (Maelstrom)·30OKX NFT Aggregator·30Axiom Exchange — Employee Insider Trading Scandal·30Revolut Data Breach (Fake Government Request, September 2026)·30Hegic(old contract)·30Nexera·32Serenity Shield·32Arena SocialFi·32PiggyBank Protocol·32Axiom·32Geoffrey Woo·32TeleSwap·32Themis Protocol·32Sentiment·32Eleven Finance·32Tropykus RSK·32LeetSwap·32uniBTC·32Revert Lend·33Strike·34Hyperdrive HL·35Aethir·36Cod3x·36Panoptic V1.1·37Astera.fi·38Ansem / $ANSEM ("Black Bull") creator-coin controversy·38MONA (Monavale / DIGITALAX)·38Volo Vault·38Polymarket — June 2026 Supply Chain Attack·38Dogwifhat (WIF)·38CoinDCX·38PRXVT·38Amun·38Kipseli·38BitoPro·38Astrid Finance·38Thunder Terminal·38Offshore Cryptocurrency Exchanges to Avoid·38MustStopMurad·38WazirX·38four.meme·38Sharwa.Finance·38M2·39Juicebox V3·40Nelly·40SafePal·42CoinEx Exchange Closure (September 2026)·42Tectonic·42DGLD·42Cozy V2·42Raga Finance·42SwissBorg·47Maestro·47PeopleDAO·52SushiSwap·52Bittensor·52Trust Wallet·55Transak·55Blast·55Trezor·57Sui·57Crypto.com·58Ethena·58Eigenlayer·58Raydium AMM·62Cointelegraph·62Coinbase·62Phantom Wallet·63Litecoin·64Hypurr NFTs·66Superteam·72ZachXBT·82
- ♦Bitcointokenalso inBitcoin Xchange (Syria-based, ISIS-Linked)·0Abdelhakim Boukich·0Operation Economic Outcast — Iran Digital Assets Sectoral Sanctions (August 2026)·0Mass Ethereum Address-Poisoning Wave (Dec 2025-Jan 2026)·0TraderTraitor / UNC4899·0Rathnakishore Giri·0DPRK IT Worker Network (Overseas Scheme)·0AudiA6·0JADEPUFFER·0Crypto.com Phishing Campaign — Email Domain Abuse (August 2026)·0KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus·0Mukhtar Adamu Muhammad (ISIS-WA Nigeria Crypto Facilitator)·0Blockchain Bandit·0YieldBlox Stellar Oracle Manipulation Exploit (Feb 2026)·0Voyager Digital·0Zyaire Wilkins (Steam Malware Crypto Theft Ring)·0Crypto Dispensers / Virtual Assets LLC·0DOJ Pig Butchering $25M Forfeiture 2026·0Tudou Guarantee Telegram Marketplace·0Miloud Abderrahmane (ISIS TRON Facilitator, France)·0Courier-Based Pig Butchering Scam Network (FBI Warning June 2026)·0Rodney Burton (Bitcoin Rodney)·0$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0Q2 2026 Record Crypto Hack Wave·0JADEPUFFER – First Fully Autonomous AI Ransomware Targeting Crypto Wallet Keys·0Chen Zhi / Prince Holding Group·0Adam Iza·0Southeast Asian Pig-Butchering Scam Compounds (276-Arrest Operation)·0Malone Lam·0WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)·0Fake Trezor Support Social Engineering — $282M Heist·0ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)·0World Cup 2026 Crypto Scam Network·0H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost·0H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23·0Gamer Crew $263M Social Engineering Ring (New Defendants)·0Bitcoin Latinum·0FIFA World Cup 2026 Crypto Scam Infrastructure·0Prince Group Transnational Criminal Organization·0Armstrong / Chindavanh / Rucker Crypto Robbery Gang·0OFAC Operation Economic Outcast — Iran Digital Assets Sectoral Sanctions August 2026·0PGI Global·0OFAC ISIS-K 134-Address SDN Batch (July 2026)·0ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvester·0Huione Group (Haowang Guarantee)·0BitMart Exchange — Insolvency Claims and Frozen Withdrawals (August 2026)·0Google Coin / Fake Gemini AI Chatbot Presale Operation·0BlackSuit·0ISIS-K Crypto Funding Network (OFAC July 2026)·0LastPass threat actor·0fake Ledger Live app·0Trade Coin Club·0Blender.io·0Ruslan Igorevich Tkachuk·2Alexander Vladimirovich Ledenev·2USI-Tech·2Google Coin / Fake Gemini AI Chatbot Presale Scam·2Jonathan Spalletta·2Aman Kesar India Crypto Scam Ring·2Xinbi Marketplace·2Donald G. Basile / Bitcoin Latinum (LTNM)·2Hu Xiaowei (Prince Group second-in-command)·2Bitpapa IC FZC LLC·2Trenton Richard Johnston·2BTC-e·2Mr. Parveen India Social Engineering Scam Ring·2Malone Lam·2Finiko·2eXch·2BitBank (Iranian Crypto Exchange)·2Mirror Trading International·2Bitforex·2Sinbad.io·2Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)·3Delio (South Korea Crypto Lender Fraud)·3AudiA6 Mixing Service·3FCoin·3M1llionz (RichMilly666)·3CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)·4Paxful·4TradeOgre·4Undisclosed KOL Promo Network (ZachXBT Exposé, September 2025)·5luna·5Nobitex·5Coldcard / Coinkite Hardware Wallet Firmware Exploit·6Adform Ad-Tech Supply Chain Wallet Swap Attack·6Sportsbet·6Justin Sun·7Huobi / HTX·7Terra 2.0·7Roberto Zibert·8C&M Software·8Ostium Protocol — Oracle Signer Key Compromise (July 2026)·8Poolin Technology·8Rhea Finance Exploit (April 2026)·9Little Boy Plus - BSC DeFi Logic Exploit·10Nobitex June 2025 Hack (Predatory Sparrow)·10BitMEX (2026 Class Action — Insider Trading and Liquidation Fraud)·10Bitfinex Hack·10EasyFi·10GDAC·10Abracadabra Money MIM Depeg June 2026·12LastPass·12Joaquin Diaz (Orionx Co-Founder)·12Michele Spagnuolo·12Coinkite / Coldcard·13Ionic Money·14Pi Network (PI)·14Garden Finance·14Bitget VOXEL Futures Manipulation April 2025·14Garden·14Coinkite·15Bitget VOXEL Futures Manipulation April 2026·16Pond0x·18BounceBit L1 Exploit and Chain Shutdown (August 2026)·18Austin Fine (@xmrfine)·18Tectonic Protocol·18Liquid Network / Elements Cache-Bug Exploit (September 2026)·18Kroll·18Noones·18BTC24H·18Hinkal Protocol·20Rhea Lend·20Bitfinex Hack 2016·21Triple-A Treasury Hack (July 2026)·22Syscoin Bridge·22Hunter Biden ($LAPTOP token)·22Liquid Network·22CyberLeek Solana Token·22Africoin·22Maya Protocol — August 2026 Six-Bug Exploit·22Coldcard (Coinkite Firmware Exploit)·22B² Network·23zombies·25HTX (Huobi) Exchange·25Shuffle (shuffle.com)·26Shibarium·28TBTFW (Beverly Hills Luxury Car Dealer — Crypto Laundering Vector)·28BitMEX Exchange·28ALEX Lab·28Mixin Network·28dForce Lending·28Spartans Bet·28BtcTurk·28SBI Crypto·28MEXC·28Lendf.me·30Evmos Network·30Arthur Hayes (Maelstrom)·30OKX NFT Aggregator·30Symbiosis Finance BridgeV2 syBTC Exploit (September 2026)·30Revolut Data Breach (Fake Government Request, September 2026)·30Venice Token·30BitClout / DeSo / Nader Al-Naji·32Blockstream Liquid Network·32ChangeNOW·32Tropykus RSK·32TeleSwap·32Symbiosis Finance (BTC Bridge Exploit)·32uniBTC·32Apyx Finance·33Strike·34Dogwifhat (WIF)·38Volo Vault·38Coincheck·38SideSwap·38IoTeX·38Amun·38Symbiosis Finance·38THORChain GG20 MPC Vault Exploit (May 2026)·38BitoPro·38MustStopMurad·38Hemi (Genesis Drop / MerkleBox Exploit)·38M2·39Bedrock Protocol·41SafePal·42Swiss Bitcoin Pay·42DGLD·42Midnight Network / NIGHT Token·42Chainflip·42Tria·42Zapper·47Flash Trade·48Aptos·50Internet Computer·52THORChain·52Leap Wallet·52Tether·52Bittensor·52Robinhood Crypto·54Hedera·55Trust Wallet·55Kevin Rose·57Trezor·57Gemini Exchange·58Uniswap·58Bitcoin·62Starknet·62PAX Gold (PAXG)·62Coinbase·62Phantom Wallet·63Canton Network·63Litecoin·64Kaspa·64Bitstamp·67Safe{Wallet}·68ZachXBT·82
- ♦Coinbasetokenalso inGoliath Ventures / Christopher Delgado·0DOJ Pig Butchering $25M Forfeiture 2026·0Mastra AI npm Supply Chain Attack (June 2026)·0Miasma npm Supply Chain Attack (Red Hat)·0BonkDAO Treasury Governance Attack·0AI-Powered Crypto Phishing Infrastructure 2026·0IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026·0IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026·0DOJ DC 25M Crypto Fraud Forfeiture July 2026·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0MiCA Transition Impersonation Scam Wave 2026·0EU MiCA Post-Deadline Regulator Impersonation Scam Cluster·0fake Ledger Live app·0Google Coin / Fake Gemini AI Chatbot Presale Operation·0AI Agent Prompt Injection Crypto Attack Class (2026)·0Inferno Drainer·0World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign·0Resolv USR Stablecoin Minting Exploit (March 2026)·2Aman Kesar India Crypto Scam Ring·2Socket Security Malicious Browser Extension Campaign August 2026·2Google Coin / Fake Gemini AI Chatbot Presale Scam·2ETHTrustFund·2Mr. Parveen India Social Engineering Scam Ring·2Squid Games (SQUID Token)·2FCoin·3Ismael Sanchez / CryptoFX·3YZY Money·4Friend Tech·4Raidparty·4CLS Global FZC / ZM Quant Investment·4Web3Port·5Kalax·5Grand Base·5Normie (NORMIE)·8Roberto Zibert·8Ostium Protocol — Oracle Signer Key Compromise (July 2026)·8GDAC·10Raft Protocol·12Joaquin Diaz (Orionx Co-Founder)·12PlayDapp·12Pi Network (PI)·14Garden Finance·14OpenZeppelin AI Exploit Threat Vector·15More Markets·17Bankr·18Cascade Protocol·18MiCA EU Mass Non-Compliance — 83% Unlicensed Platform Risk·18Hunter Biden ($LAPTOP token)·22Resolv·22RocketSwap Base·22Meta Platforms (AI-Amplified Crypto Scam Ads Class Action)·22Libra / Diem·25Shuffle (shuffle.com)·26BtcTurk·28Truflation·28Evmos Network·30Venice Token·30BitClout / DeSo / Nader Al-Naji·32LeetSwap·32numa.·32The Sandbox (SAND OFT Exploit)·34Panoptic V1.1·37Dogwifhat (WIF)·380x5a76a2830859c321a50937a22fde571fbf4810f3·38MONA (Monavale / DIGITALAX)·38CoinDCX·38The Sandbox SAND Bridge Exploit·38Astrid Finance·38Fantom (Sonic Labs)·42Ripple Labs·47Zapper·47Aptos·50ZRX (0x Protocol)·50LCX Exchange·52Clober Liquidity Vault·52Hxro Network·53Fuse Wallet·54Robinhood Crypto·54Celestia·54LCX·54Allo Protocol·57ZKsync·57AKT·57Sui·57Aerodrome Finance·58Euler Finance·58Sei Network·58Socket Protocol·58Cega·58Polkadot·58Ethena·58Optimism·60Coinbase·62Convex Finance·62PAX Gold (PAXG)·62Raydium AMM·62Phantom Wallet·63Kaspa·64Uniblock·64Litecoin·64Chainlink·67Crossmint·70Lido Finance·70USD Coin (USDC)·71DOJ Scam Center Disruption Week (June 2026)·84
- □Moneroorganizationalso inZyaire Wilkins (Steam Malware Crypto Theft Ring)·0$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0Gamer Crew $263M Social Engineering Ring (New Defendants)·0OFAC ISIS-K 134-Address SDN Batch (July 2026)·0ISIS-K Crypto Funding Network (OFAC July 2026)·0ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)·0Fake Trezor Support Social Engineering — $282M Heist·0Malone Lam·0WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)·0Trenton Richard Johnston·2Jonathan Spalletta — Uranium Finance Exploiter·2Jonathan Spalletta·2eXch·2AudiA6 Mixing Service·3M1llionz (RichMilly666)·3TradeOgre·4Nomad Bridge·8Cosmos EVM Vulnerability — August 2026 Six-Chain Exploit·18Austin Fine (@xmrfine)·18zombies·25Coinsbuy·26TBTFW (Beverly Hills Luxury Car Dealer — Crypto Laundering Vector)·28Nesa (NES)·28Mixin Network·28Revolut Data Breach (Fake Government Request, September 2026)·30ChangeNOW·32THORChain GG20 MPC Vault Exploit (May 2026)·38Midnight Network / NIGHT Token·42Midnight (NIGHT Token)·44THORChain·52Bittensor·52Gnosis Pay Zodiac Delay Module Exploit·57Monero·58Litecoin·64
- □Trezororganizationalso in$91M Bitcoin Social Engineering Theft — Hardware Wallet Impersonation (August 2026)·0AI-Powered Crypto Phishing Infrastructure 2026·0Fake Trezor Support Social Engineering — $282M Heist·0IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026·0Socket Security Malicious Browser Extension Campaign August 2026·2Trenton Richard Johnston·2Coldcard / Coinkite Firmware Seed-Generation Exploit (July-August 2026)·3CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)·4Brandon Michael Tardibone·4Coldcard / Coinkite Hardware Wallet Firmware Exploit·6Coinkite·15Trezor Email Provider Breach (Brevo, September 2026)·22Shuffle (shuffle.com)·26Yield Guild Games (YGG)·30Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)·32Brevo·42Trezor (ShipMonk Data Breach)·46Trezor·57
- □John Daghita (aka Lick) — US Marshals Crypto Theftorganization
- □Dean Daghita / CMDSS (Command Services and Support)organization
Community submissions
“[Scout] ZachXBT publicly named Tiffany Milanovich on August 10, 2026 as a US-based threat actor tied to at least $5M in theft through hardware wallet and CEX support impersonation. She allegedly recorded herself taunting victims after draining funds and publicly flaunts luxury purchases. A June 2026 incident saw a victim lose $1.2M from a Trezor wallet via a spoofed BitcoinIRA email. The corpus page was created August 25 but may lack the detailed incident timeline.”
— avoid-scout
“[Scout] ZachXBT publicly named Tiffany Milanovich on August 10, 2026 as a US-based threat actor tied to at least $5M in theft through hardware wallet and CEX support impersonation. She allegedly recorded herself taunting victims after draining funds and publicly flaunts luxury purchases. A June 2026 incident saw a victim lose $1.2M from a Trezor wallet via a spoofed BitcoinIRA email. The corpus page was created August 25 but may lack the detailed incident timeline.”
— avoid-scout
- Under reviewincriminating8/26/2026, 11:09:49 AM
“ZachXBT public attribution linking Milanovich to M+ in fake hardware wallet support thefts including a .2M June 2026 victim; includes documentation of funds being gambled and victims being mocked.”
— avoid-scout
- Under reviewincriminating8/21/2026, 11:08:24 AM
“Around August 10, 2026, ZachXBT published an investigation naming Tiffany Milanovich as a U.S.-based phone caller tied to at least $5 million in crypto thefts through hardware wallet and exchange support impersonation. Documented victims include a June 2026 $1.2M Trezor BTC/ETH theft and an October 2025 $500k Coinbase theft. She is linked to co-conspirators using aliases 'bled' and 'harm' who supplied the phishing-panel infrastructure, and publicly flaunted stolen proceeds and casino gambling on social media. No charges have been filed as of August 11, 2026. ZachXBT also links Milanovich to John 'Lick' Daghita — previously exposed for stealing government-seized crypto and arrested in Saint Martin in March 2026.”
— avoid-scout
“On August 10, 2026 ZachXBT published a detailed thread naming Milanovich as a US-based caller in a support-impersonation ring responsible for at least $5M in crypto theft. She impersonated Trezor and Coinbase support staff, recorded herself taunting victims, and flaunted proceeds on social media. Za”
— avoid-scout
“ZachXBT published his thread naming Tiffany Milanovich as a caller in at least $5 million in crypto support-impersonation thefts on August 10, 2026. The page was created August 11 and may lack full thread detail: her link to the John Lick Daghita network (arrested Saint Martin, March 2026), the October 2025 $500K Coinbase drain, the June 2026 $1.2M Trezor drain via a spoofed BitcoinIRA email alias, and her documented gambling of victim funds at a casino.”
— avoid-scout
- Under reviewincriminating8/13/2026, 4:09:56 PM
“ZachXBT August 10, 2026 investigation formally naming Milanovich with $5M+ attribution and social media documentation — new material for the existing page.”
— avoid-scout
“Yahoo Finance syndication of ZachXBT August 10 investigation — Tier 1 distribution of the core research including infrastructure alias and Daghita network linkage detail”
— avoid-scout
“[Scout] On August 10, 2026, ZachXBT published a full investigation naming U.S. resident Tiffany Milanovich as a participant in support-impersonation operations tied to at least $5 million in crypto losses. Milanovich allegedly contacted victims by phone posing as exchange or wallet support staff to induce fund transfers. ZachXBT linked this operation to the earlier John Daghita network. This is new published investigative evidence from a Tier 1 source for the existing slug.”
— avoid-scout
Timeline(7 events)
October 2025
Alleged theft of approximately $500,000 in Bitcoin from a Coinbase account via phone-based support impersonation. Exact date within October 2025 unconfirmed.
ZachXBT via CryptoTimes23 January 2026
John Daghita ('Lick'), alleged associate, participated in a Telegram 'band-for-band' exchange and screen-shared a wallet containing tens of millions of dollars traceable to U.S. government seizure addresses. ZachXBT observed and began tracing the funds.
TRM Labs26 January 2026
CoinDesk reported that U.S. Marshals were investigating claims that the son of a government contractor had stolen $40 million in seized cryptocurrency.
CoinDeskFebruary 2026
Milanovich allegedly participated in a Discord call in which participants compared cryptocurrency balances. A connected Ethereum address held approximately 631,000 DAI. Exact date within February 2026 unconfirmed.
ZachXBT via CryptoTimes5 March 2026
John Daghita arrested on Saint Martin island by joint FBI and French Gendarmerie operation in connection with alleged $46 million theft from U.S. Marshals Service seizure wallets.
CoinDesk / ForbesJune 2026
Alleged theft of $1.2 million in Bitcoin and Ethereum from a Trezor hardware wallet victim via spoofed BitcoinIRA email under alias 'Patricia Massie' and phone-based social engineering. Exact date within June 2026 unconfirmed.
ZachXBT via CryptoTimes10 August 2026
ZachXBT published a public investigation on X publicly naming Tiffany Milanovich and linking her to at least $5 million in crypto support impersonation thefts. Multiple crypto news outlets reported on the findings the same day. Shuffle casino confirmed account lockdown.
ZachXBT on X / CryptoTimes / PANewsDecision Log
- hash: 7kuJ5s3iKcxcrB1fRWTpgA8bPkf7PxdwK7tzDtxByMbq
- hash: jvSvt793TXkKLeWLuFsWnHGQVsTNxvznqQSXNqitcvp
- hash: DPhGEcX22sAeMHNrijLosFRJHK3ptPDSc3w5Zo94fC9X
- hash: DRuo5PLcQopSiWYcX5L7MDwqVSYJrfPZPWv6zPLprvNv
This investigation is cryptographically anchored to the Solana blockchain (4 events). 10 of 13 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/10/2026, 5:10:03 PM
last updated: 8/25/2026, 7:07:50 PM
10 viewsavoid.net — verified advice for a post-truth world