Skip to main content
AVOID.NET

Tiffany Milanovich

avoid.net/tiffany-milanovich→0/100·78% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5KNsSe…EMtz

Summary

Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses. She is alleged to have operated as a 'caller' — the voice contact who phoned victims while impersonating customer support representatives for hardware wallet providers and centralized exchanges including Trezor, Coinbase, and BitcoinIRA — and is connected to other named threat actors and to John Daghita ('Lick'), arrested in March 2026 in connection with a $46 million theft of U.S. government-seized cryptocurrency. No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.

Connected Entities

10 entities · 60 linked investigations
Organizations
□Ethereum64□John Daghita (aka Lick) — US Marshals Crypto Theft□Shuffle (shuffle.com)□Tiffany Milanovich□Trezor□Dean Daghita / CMDSS (Command Services and Support)□ZachXBT□Monero
Tokens
♦Coinbase♦Bitcoin
Relationships
  • John Daghita (aka Lick) — US Marshals Crypto Theft→mentioned with→Ethereum(65%)
  • Ethereum→mentioned with→Coinbase(60%)
  • John Daghita (aka Lick) — US Marshals Crypto Theft→mentioned with→ZachXBT(70%)
  • Ethereum→mentioned with→Bitcoin(60%)
  • Monero→mentioned with→Bitcoin(60%)
  • Monero→mentioned with→ZachXBT(65%)
  • Dean Daghita / CMDSS (Command Services and Support)→mentioned with→ZachXBT(70%)
  • ZachXBT→mentioned with→Ethereum(70%)
  • ZachXBT→mentioned with→Bitcoin(65%)
  • Shuffle (shuffle.com)→mentioned with→Ethereum(60%)
  • + 24 more

Connected Through

8 shared actors · 624 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Tiffany Milanovich?
0
Accepted
9
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminating[WAYBACK]8/29/2026, 4:09:58 PM

    “[Scout] ZachXBT publicly named Tiffany Milanovich on August 10, 2026 as a US-based threat actor tied to at least $5M in theft through hardware wallet and CEX support impersonation. She allegedly recorded herself taunting victims after draining funds and publicly flaunts luxury purchases. A June 2026 incident saw a victim lose $1.2M from a Trezor wallet via a spoofed BitcoinIRA email. The corpus page was created August 25 but may lack the detailed incident timeline.”

    — avoid-scout

  • Under reviewincriminating[WAYBACK]8/29/2026, 4:09:58 PM

    “[Scout] ZachXBT publicly named Tiffany Milanovich on August 10, 2026 as a US-based threat actor tied to at least $5M in theft through hardware wallet and CEX support impersonation. She allegedly recorded herself taunting victims after draining funds and publicly flaunts luxury purchases. A June 2026 incident saw a victim lose $1.2M from a Trezor wallet via a spoofed BitcoinIRA email. The corpus page was created August 25 but may lack the detailed incident timeline.”

    — avoid-scout

  • Under reviewincriminating8/26/2026, 11:09:49 AM

    “ZachXBT public attribution linking Milanovich to M+ in fake hardware wallet support thefts including a .2M June 2026 victim; includes documentation of funds being gambled and victims being mocked.”

    — avoid-scout

  • Under reviewincriminating8/21/2026, 11:08:24 AM

    “Around August 10, 2026, ZachXBT published an investigation naming Tiffany Milanovich as a U.S.-based phone caller tied to at least $5 million in crypto thefts through hardware wallet and exchange support impersonation. Documented victims include a June 2026 $1.2M Trezor BTC/ETH theft and an October 2025 $500k Coinbase theft. She is linked to co-conspirators using aliases 'bled' and 'harm' who supplied the phishing-panel infrastructure, and publicly flaunted stolen proceeds and casino gambling on social media. No charges have been filed as of August 11, 2026. ZachXBT also links Milanovich to John 'Lick' Daghita — previously exposed for stealing government-seized crypto and arrested in Saint Martin in March 2026.”

    — avoid-scout

  • Under reviewincriminating[WAYBACK]8/19/2026, 11:13:24 AM

    “On August 10, 2026 ZachXBT published a detailed thread naming Milanovich as a US-based caller in a support-impersonation ring responsible for at least $5M in crypto theft. She impersonated Trezor and Coinbase support staff, recorded herself taunting victims, and flaunted proceeds on social media. Za”

    — avoid-scout

  • Under reviewincriminating[WAYBACK]8/15/2026, 4:11:55 PM

    “ZachXBT published his thread naming Tiffany Milanovich as a caller in at least $5 million in crypto support-impersonation thefts on August 10, 2026. The page was created August 11 and may lack full thread detail: her link to the John Lick Daghita network (arrested Saint Martin, March 2026), the October 2025 $500K Coinbase drain, the June 2026 $1.2M Trezor drain via a spoofed BitcoinIRA email alias, and her documented gambling of victim funds at a casino.”

    — avoid-scout

  • Under reviewincriminating8/13/2026, 4:09:56 PM

    “ZachXBT August 10, 2026 investigation formally naming Milanovich with $5M+ attribution and social media documentation — new material for the existing page.”

    — avoid-scout

  • Under reviewincriminating[WAYBACK]8/12/2026, 4:09:38 PM

    “Yahoo Finance syndication of ZachXBT August 10 investigation — Tier 1 distribution of the core research including infrastructure alias and Daghita network linkage detail”

    — avoid-scout

  • Under reviewincriminating[WAYBACK]8/12/2026, 11:10:29 AM

    “[Scout] On August 10, 2026, ZachXBT published a full investigation naming U.S. resident Tiffany Milanovich as a participant in support-impersonation operations tied to at least $5 million in crypto losses. Milanovich allegedly contacted victims by phone posing as exchange or wallet support staff to induce fund transfers. ZachXBT linked this operation to the earlier John Daghita network. This is new published investigative evidence from a Tier 1 source for the existing slug.”

    — avoid-scout

Timeline(7 events)

October 2025

Alleged theft of approximately $500,000 in Bitcoin from a Coinbase account via phone-based support impersonation. Exact date within October 2025 unconfirmed.

ZachXBT via CryptoTimes

23 January 2026

John Daghita ('Lick'), alleged associate, participated in a Telegram 'band-for-band' exchange and screen-shared a wallet containing tens of millions of dollars traceable to U.S. government seizure addresses. ZachXBT observed and began tracing the funds.

TRM Labs

26 January 2026

CoinDesk reported that U.S. Marshals were investigating claims that the son of a government contractor had stolen $40 million in seized cryptocurrency.

CoinDesk

February 2026

Milanovich allegedly participated in a Discord call in which participants compared cryptocurrency balances. A connected Ethereum address held approximately 631,000 DAI. Exact date within February 2026 unconfirmed.

ZachXBT via CryptoTimes

5 March 2026

John Daghita arrested on Saint Martin island by joint FBI and French Gendarmerie operation in connection with alleged $46 million theft from U.S. Marshals Service seizure wallets.

CoinDesk / Forbes

June 2026

Alleged theft of $1.2 million in Bitcoin and Ethereum from a Trezor hardware wallet victim via spoofed BitcoinIRA email under alias 'Patricia Massie' and phone-based social engineering. Exact date within June 2026 unconfirmed.

ZachXBT via CryptoTimes

10 August 2026

ZachXBT published a public investigation on X publicly naming Tiffany Milanovich and linking her to at least $5 million in crypto support impersonation thefts. Multiple crypto news outlets reported on the findings the same day. Shuffle casino confirmed account lockdown.

ZachXBT on X / CryptoTimes / PANews
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 10 of 13 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-2325 claims checked2 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/10/2026, 5:10:03 PM

last updated: 8/25/2026, 7:07:50 PM

10 views

avoid.net — verified advice for a post-truth world