← Tiffany Milanovich1 decision on this page
Audit log
Every state-changing event for Tiffany Milanovich: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-10 17:10:20ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
DRuo5PLcQopS…zPLprvNvsha256 → base58
verifying row…canonical bytes (20645 B) ▸
{"actor":"system:backfill","investigation_id":"3456ece0-b6b3-4b34-917f-faee271d0a77","kind":"publish","page_slug":"tiffany-milanovich","published_at":"2026-08-10T17:10:20.005Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Tiffany Milanovich","sections":[{"content":"Tiffany Milanovich is identified by ZachXBT as a U.S. resident who served as a 'caller' within an organized crypto theft ring. In this role, she allegedly phoned victims directly while impersonating customer support staff for hardware wallet manufacturers and centralized cryptocurrency exchanges, including Trezor, Coinbase, and BitcoinIRA. ZachXBT's August 10, 2026 report describes her as responsible for the social engineering component of attacks — persuading victims over the phone to surrender account access, approve transactions, or reveal sensitive credentials. WEEX reporting characterizes her role as being the primary voice contact responsible for inducing fund handovers. No formal law enforcement confirmation of her identity or charges had been publicly announced as of August 10, 2026.","heading":"Identity and Role","severity":"critical","sources":[{"credibility":2,"name":"ZachXBT on X — primary investigation thread","type":"social_media","url":"https://x.com/zachxbt/status/2086785482487456201"},{"credibility":2,"name":"ZachXBT on X — caller role description","type":"social_media","url":"https://x.com/zachxbt/status/2086785485331182047"},{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"American Hacker Impersonates Customer Service to Steal Over $5 Million in Cryptocurrency — WEEX","type":"news_article","url":"https://www.weex.com/news/detail/american-hacker-impersonates-customer-service-to-steal-over-5-million-in-cryptocurrency-ftk5m0syaihrmkg8vliumjki"}]},{"content":"In June 2026, a victim lost approximately $1.2 million in Bitcoin and Ethereum after Milanovich and her associates allegedly drained a Trezor hardware wallet. According to ZachXBT's investigation, the attack was initiated via a spoofed BitcoinIRA email sent under the alias 'Patricia Massie.' The victim was contacted by phone — allegedly by Milanovich in her caller role — and induced to grant access to their wallet. ZachXBT identified two blockchain addresses associated with this incident: Bitcoin address bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy and Ethereum address 0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c. Proceeds from this attack were alleged to have been discussed in Telegram groups among participants in the ring.","heading":"June 2026: Trezor Wallet Attack ($1.2 Million)","severity":"critical","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"ZachXBT: U.S. Female Scammer Impersonates Customer Service to Steal Over $5 Million in Crypto Assets — PANews","type":"news_article","url":"https://panews.io/articles/019feb9b-186d-73be-b932-39b30d25f514"},{"credibility":2,"name":"ZachXBT on X — primary investigation thread","type":"social_media","url":"https://x.com/zachxbt/status/2086785482487456201"}]},{"content":"In October 2025, a separate victim allegedly lost approximately $500,000 in Bitcoin from a Coinbase account. ZachXBT's investigation linked this incident to Milanovich and identified two associated Bitcoin addresses: bc1qw3mej5hx7jhtdagqwt7ljls7wzkda2tym3w0d2 and bc1q2r2tjdlcp3s4399g6v0xfamcw40xs5553qx7dx. Blockwisely reporting indicates ZachXBT also shared recordings from this incident in which Milanovich allegedly complained about her share of the proceeds, providing additional audio evidence connecting her to the operation. The attack method followed the same pattern of phone-based social engineering with impersonation of official exchange support.","heading":"October 2025: Coinbase Account Attack (~$500,000)","severity":"critical","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"ZachXBT Tiffany Milanovich Report: $5M Crypto Theft Claims — Blockwisely","type":"news_article","url":"https://blockwisely.com/news/zachxbt-tiffany-milanovich-crypto-theft-claims/"}]},{"content":"ZachXBT's investigation documents an additional incident from February 2026 in which Milanovich allegedly participated in a Discord call in which participants compared cryptocurrency balances. One connected Ethereum address, 0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc, reportedly held approximately 631,000 DAI at the relevant time. This incident was cited by CryptoTimes in its summary of the ZachXBT report as part of the evidentiary chain connecting Milanovich to the broader operation.","heading":"February 2026: Discord Call and DAI Holdings","severity":"high","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"}]},{"content":"ZachXBT's investigation describes a multi-actor operation in which Milanovich served as the caller while other members provided supporting infrastructure. Two additional threat actors identified only by the handles 'bled' and 'harm' are alleged to have supplied phishing panels used to capture victim credentials. Stolen funds were laundered through instant exchange services that did not enforce rigorous Know Your Customer requirements, with some transactions originating from Monero, consistent with techniques used to obscure fund provenance. On-chain analysis confirmed portions of stolen funds were tracked, though some amounts remain unaccounted for. Blockwisely reported that some stolen funds remained inactive on-chain as of the report date.","heading":"Modus Operandi: Phishing Infrastructure and Money Laundering","severity":"high","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"ZachXBT: U.S. Female Scammer Impersonates Customer Service to Steal Over $5 Million in Crypto Assets — PANews","type":"news_article","url":"https://panews.io/articles/019feb9b-186d-73be-b932-39b30d25f514"},{"credibility":2,"name":"ZachXBT Tiffany Milanovich Report: $5M Crypto Theft Claims — Blockwisely","type":"news_article","url":"https://blockwisely.com/news/zachxbt-tiffany-milanovich-crypto-theft-claims/"}]},{"content":"ZachXBT presented evidence that Milanovich recorded herself taunting victims on phone calls after their funds had been drained, and that these recordings were distributed in private Telegram groups. She is alleged to have openly displayed luxury purchases, casino activity, and stolen balances on social media platforms. In one documented instance, she allegedly gambled a victim's stolen funds on Shuffle, a crypto casino, while simultaneously mocking that victim by phone. Shuffle reportedly reviewed the evidence provided by ZachXBT and confirmed that her account would be locked. This behavior is consistent with patterns documented in other U.S.-based crypto theft rings in 2025 and 2026.","heading":"Post-Theft Behavior: Taunting and Public Display of Proceeds","severity":"high","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"ZachXBT on X — caller role description","type":"social_media","url":"https://x.com/zachxbt/status/2086785485331182047"},{"credibility":2,"name":"ZachXBT: U.S. Female Scammer Impersonates Customer Service to Steal Over $5 Million in Crypto Assets — PANews","type":"news_article","url":"https://panews.io/articles/019feb9b-186d-73be-b932-39b30d25f514"}]},{"content":"ZachXBT noted a connection between Milanovich's operation and John Daghita, known by the alias 'Lick,' who was arrested in March 2026 on Saint Martin island in a joint FBI and French Gendarmerie operation. Daghita is alleged to have stolen more than $46 million in cryptocurrency from wallets managed by Command Services & Support (CMDSS), a Virginia contractor with U.S. Marshals Service contracts for seized crypto custody. Daghita is the son of CMDSS president Dean Daghita. Daghita was publicly identified by ZachXBT after appearing in a Telegram 'band-for-band' exchange in January 2025 in which he screen-shared a wallet holding tens of millions of dollars in cryptocurrency traceable to government seizure addresses. French Gendarmerie officers reportedly found Daghita at a villa on Saint Martin with $239,348 in cash, a Rolex GMT Master, and multiple hardware wallets containing stolen cryptocurrency. The nature and scope of the alleged connection between Milanovich and Daghita beyond ZachXBT's report has not been independently confirmed by law enforcement.","heading":"Connection to John Daghita ('Lick') and the $46M U.S. Marshals Theft","severity":"high","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":1,"name":"Son of contractor managing seized crypto for U.S. Marshals arrested in France over alleged $46m theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/03/05/son-of-u-s-government-contractor-accused-of-stealing-millions-in-seized-crypto-arrested-in-france"},{"credibility":2,"name":"John Daghita aka 'John/Lick' Arrested in Alleged Cryptocurrency Theft Tied to US Marshals Service — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/john-daghita-aka-john-lick-arrested-in-alleged-cryptocurrency-theft-tied-to-us-marshals-service"},{"credibility":1,"name":"FBI Arrests U.S. Contractor's Son In $46 Million Crypto Theft — Forbes","type":"news_article","url":"https://www.forbes.com/sites/digital-assets/2026/03/05/fbi-arrests-us-contractors-son-in-46-million-crypto-theft/"}]},{"content":"As of August 10, 2026, no public criminal charges against Tiffany Milanovich had been confirmed by law enforcement. However, ZachXBT stated in his report that a search and seizure warrant in Connecticut predated some of the later incidents he documented, suggesting active law enforcement engagement prior to the public disclosure. WEEX reporting stated that Milanovich 'is expected to face legal consequences,' though this reflects editorial assessment rather than confirmed legal action. The Connecticut warrant reference is sourced from ZachXBT's report and has not been independently verified through court records as of this writing.","heading":"Legal Status and Law Enforcement Activity","severity":"medium","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"American Hacker Impersonates Customer Service to Steal Over $5 Million in Cryptocurrency — WEEX","type":"news_article","url":"https://www.weex.com/news/detail/american-hacker-impersonates-customer-service-to-steal-over-5-million-in-cryptocurrency-ftk5m0syaihrmkg8vliumjki"}]},{"content":"ZachXBT's report includes blockchain transaction data, chat logs, and call recordings as evidence. The following addresses are attributed to the operation in various secondary reports citing ZachXBT's findings: Bitcoin address bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy (June 2026 Trezor incident); Ethereum address 0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c (June 2026 Trezor incident); Bitcoin addresses bc1qw3mej5hx7jhtdagqwt7ljls7wzkda2tym3w0d2 and bc1q2r2tjdlcp3s4399g6v0xfamcw40xs5553qx7dx (October 2025 Coinbase incident); Ethereum address 0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc (February 2026, reported to hold approximately 631,000 DAI). These addresses have not been independently verified through court filings or regulatory records as of the publication of this report. Lookonchain summarized the investigation corroborating ZachXBT's on-chain attributions.","heading":"On-Chain Evidence and Attributed Addresses","severity":"high","sources":[{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"ZachXBT: U.S. attackers impersonate wallet customer support to scam, stealing at least $5 million in crypto assets — Lookonchain","type":"on_chain","url":"https://www.lookonchain.com/feeds/67717"}]}],"sources_used":[{"credibility":2,"name":"ZachXBT on X — primary investigation thread","type":"social_media","url":"https://x.com/zachxbt/status/2086785482487456201"},{"credibility":2,"name":"ZachXBT on X — caller role description","type":"social_media","url":"https://x.com/zachxbt/status/2086785485331182047"},{"credibility":2,"name":"ZachXBT Links U.S. Resident to Alleged $5M in Crypto Support Impersonation Thefts — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"credibility":2,"name":"ZachXBT: U.S. Female Scammer Impersonates Customer Service to Steal Over $5 Million in Crypto Assets — PANews","type":"news_article","url":"https://panews.io/articles/019feb9b-186d-73be-b932-39b30d25f514"},{"credibility":2,"name":"American Hacker Impersonates Customer Service to Steal Over $5 Million in Cryptocurrency — WEEX","type":"news_article","url":"https://www.weex.com/news/detail/american-hacker-impersonates-customer-service-to-steal-over-5-million-in-cryptocurrency-ftk5m0syaihrmkg8vliumjki"},{"credibility":2,"name":"ZachXBT Tiffany Milanovich Report: $5M Crypto Theft Claims — Blockwisely","type":"news_article","url":"https://blockwisely.com/news/zachxbt-tiffany-milanovich-crypto-theft-claims/"},{"credibility":2,"name":"ZachXBT Unmasks Fraudster Linked to $5 Million Crypto Phishing Scams — Cryptovka","type":"news_article","url":"https://cryptovka.com/news/zachxbt-unmasks-fraudster-linked-to-5-million-crypto-phishing-scams"},{"credibility":2,"name":"ZachXBT: U.S. attackers impersonate wallet customer support to scam, stealing at least $5 million in crypto assets — Lookonchain","type":"on_chain","url":"https://www.lookonchain.com/feeds/67717"},{"credibility":1,"name":"Son of contractor managing seized crypto for U.S. Marshals arrested in France over alleged $46m theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/03/05/son-of-u-s-government-contractor-accused-of-stealing-millions-in-seized-crypto-arrested-in-france"},{"credibility":1,"name":"FBI Arrests U.S. Contractor's Son In $46 Million Crypto Theft — Forbes","type":"news_article","url":"https://www.forbes.com/sites/digital-assets/2026/03/05/fbi-arrests-us-contractors-son-in-46-million-crypto-theft/"},{"credibility":2,"name":"John Daghita aka 'John/Lick' Arrested in Alleged Cryptocurrency Theft Tied to US Marshals Service — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/john-daghita-aka-john-lick-arrested-in-alleged-cryptocurrency-theft-tied-to-us-marshals-service"},{"credibility":1,"name":"U.S. marshals investigate claim of $40 million crypto theft by son of federal crypto custodian — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/01/26/u-s-marshals-investigate-claims-that-son-of-government-contractor-stole-usd40-million-of-seized-crypto"},{"credibility":3,"name":"International Cyber Digest on X — corroborating identification","type":"social_media","url":"https://x.com/IntCyberDigest/status/2086808469764452795"}],"summary":"Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses. She is alleged to have operated as a 'caller' — the voice contact who phoned victims while impersonating customer support representatives for hardware wallet providers and centralized exchanges including Trezor, Coinbase, and BitcoinIRA — and is connected to other named threat actors and to John Daghita ('Lick'), arrested in March 2026 in connection with a $46 million theft of U.S. government-seized cryptocurrency. No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.","timeline":[{"date":"2025-10-01","event":"Alleged theft of approximately $500,000 in Bitcoin from a Coinbase account via phone-based support impersonation. Exact date within October 2025 unconfirmed.","source":"ZachXBT via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"date":"2026-01-23","event":"John Daghita ('Lick'), alleged associate, participated in a Telegram 'band-for-band' exchange and screen-shared a wallet containing tens of millions of dollars traceable to U.S. government seizure addresses. ZachXBT observed and began tracing the funds.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/john-daghita-aka-john-lick-arrested-in-alleged-cryptocurrency-theft-tied-to-us-marshals-service"},{"date":"2026-01-26","event":"CoinDesk reported that U.S. Marshals were investigating claims that the son of a government contractor had stolen $40 million in seized cryptocurrency.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/01/26/u-s-marshals-investigate-claims-that-son-of-government-contractor-stole-usd40-million-of-seized-crypto"},{"date":"2026-02-01","event":"Milanovich allegedly participated in a Discord call in which participants compared cryptocurrency balances. A connected Ethereum address held approximately 631,000 DAI. Exact date within February 2026 unconfirmed.","source":"ZachXBT via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"date":"2026-03-05","event":"John Daghita arrested on Saint Martin island by joint FBI and French Gendarmerie operation in connection with alleged $46 million theft from U.S. Marshals Service seizure wallets.","source":"CoinDesk / Forbes","source_url":"https://www.coindesk.com/business/2026/03/05/son-of-u-s-government-contractor-accused-of-stealing-millions-in-seized-crypto-arrested-in-france"},{"date":"2026-06-01","event":"Alleged theft of $1.2 million in Bitcoin and Ethereum from a Trezor hardware wallet victim via spoofed BitcoinIRA email under alias 'Patricia Massie' and phone-based social engineering. Exact date within June 2026 unconfirmed.","source":"ZachXBT via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/10/zachxbt-links-u-s-resident-to-alleged-5m-in-crypto-support-impersonation-thefts/"},{"date":"2026-08-10","event":"ZachXBT published a public investigation on X publicly naming Tiffany Milanovich and linking her to at least $5 million in crypto support impersonation thefts. Multiple crypto news outlets reported on the findings the same day. Shuffle casino confirmed account lockdown.","source":"ZachXBT on X / CryptoTimes / PANews","source_url":"https://x.com/zachxbt/status/2086785482487456201"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 16b6da8f-53f0-4e03-9c9a-73690c063ae3
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.