Fact-check findings
What an automated fact-checker found when it re-read Tiffany Milanovich against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
2 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #10[disputed][awaiting moderator]in section: Modus Operandi: Phishing Infrastructure and Money Laundering
“Two additional threat actors identified only by the handles 'bled' and 'harm' are alleged to have supplied phishing panels used to capture victim credentials.”
reviewerTwo additional threat actors identified only by the handles 'bled' and 'harm' supplied phishing panels used to capture victim credentials.Multiple secondary reports of ZachXBT's own thread (CryptoPotato and others) describe 'bled' and 'harm' as two aliases used by a single additional threat actor who supplied phishing infrastructure, not two separate people as the page states. This inflates the number of named accomplices.Proposed correction (not yet applied)An additional threat actor identified only by the handles 'bled' and 'harm' is alleged to have supplied phishing panels used to capture victim credentials. - #17[disputed][awaiting moderator]in section: Connection to John Daghita ('Lick') and the $46M U.S. Marshals Theft
“Daghita was publicly identified by ZachXBT after appearing in a Telegram 'band-for-band' exchange in January 2025 in which he screen-shared a wallet holding tens of millions of dollars in cryptocurrency traceable to government seizure addresses.”
reviewerDaghita was publicly identified by ZachXBT after appearing in a Telegram 'band-for-band' exchange in January 2025 in which he screen-shared a wallet holding tens of millions of dollars traceable to government seizure addresses.The page's own cited source (TRM Labs) says 'January 2025,' but this is contradicted by ZachXBT's own tweets in the same investigation thread ('In late January 2026, I exposed John Daghita...'), by crypto.news citing the tweet's January 25, 2026 timestamp, and by CoinDesk's January 26, 2026 article describing the exposure as having happened 'last Friday.' The band-for-band exchange and Daghita's public exposure occurred in January 2026, not January 2025 — a one-year error, likely inherited from a typo in the TRM Labs source. Note the page's own timeline entry for this event (timeline[1].date = 2026-01-23) already has the correct year; only this section's prose has the error.Proposed correction (not yet applied)Daghita was publicly identified by ZachXBT after appearing in a Telegram 'band-for-band' exchange in January 2026 in which he screen-shared a wallet holding tens of millions of dollars in cryptocurrency traceable to government seizure addresses.
partially supported
3 claimsThe cited evidence supports part of the claim but not all of it.
- #1[partially supported][awaiting moderator]in the summary
“Tiffany Milanovich is a U.S.-based individual whom on-chain investigator ZachXBT publicly identified on August 10, 2026 as a participant in a crypto support impersonation operation alleged to have caused at least $5 million in verified victim losses.”
reviewerZachXBT publicly identified Milanovich on August 10, 2026 as a participant in a crypto support impersonation operation causing at least $5 million in victim losses.The $5M figure, date, and role are well corroborated across ZachXBT's own tweet and secondary reporting. However none of the sources describe the losses as 'verified' — they are consistently framed as allegations documented by a single on-chain investigator, not confirmed by a court, exchange, or law-enforcement audit. 'Verified' overstates the evidentiary status against the page's own hedging elsewhere ('alleged'). - #3[partially supported][awaiting moderator]in section: Identity and Role
“WEEX reporting characterizes her role as being the primary voice contact responsible for inducing fund handovers.”
reviewerWEEX reporting characterizes Milanovich's role as being the primary voice contact responsible for inducing fund handovers.The underlying characterization (she was the phone-based social engineer) is accurate, but the page attributes specific phrasing to WEEX that the article does not contain — a mischaracterization of the source's exact language. - #20[partially supported][awaiting moderator]in section: On-Chain Evidence and Attributed Addresses
“Lookonchain summarized the investigation corroborating ZachXBT's on-chain attributions.”
reviewerLookonchain summarized the investigation, corroborating ZachXBT's on-chain attributions.The page implies Lookonchain independently corroborated the specific address attributions; in fact Lookonchain's post is a narrative summary of ZachXBT's findings without its own address-level analysis. The dollar figures match, but 'corroborating on-chain attributions' overstates what the source does.
confirmed
20 claimsThe cited evidence supports the claim as written.
- #2[confirmed][no action needed]in the summary
“No criminal charges against Milanovich had been publicly confirmed as of the date of this report, though ZachXBT stated that a search and seizure warrant in Connecticut predated some of the later incidents he documented.”
reviewerNo criminal charges against Milanovich had been publicly confirmed, though ZachXBT stated a Connecticut search and seizure warrant predated some of the later incidents.A follow-up search for any Milanovich arrest, charge, or indictment as of September 2026 (over a month after the report) found nothing, so the no-charges claim remains current, not stale. - #4[confirmed][no action needed]in section: June 2026: Trezor Wallet Attack ($1.2 Million)
“In June 2026, a victim lost approximately $1.2 million in Bitcoin and Ethereum after Milanovich and her associates allegedly drained a Trezor hardware wallet.”
reviewerIn June 2026, a victim lost approximately $1.2 million in Bitcoin and Ethereum after a Trezor hardware wallet was drained.Consistent across two independent secondary reports of ZachXBT's findings. - #5[confirmed][no action needed]in section: June 2026: Trezor Wallet Attack ($1.2 Million)
“According to ZachXBT's investigation, the attack was initiated via a spoofed BitcoinIRA email sent under the alias 'Patricia Massie.'”
reviewerThe June 2026 Trezor attack was initiated via a spoofed BitcoinIRA email sent under the alias 'Patricia Massie.'Matches the cited source directly. - #6[confirmed][no action needed]in section: June 2026: Trezor Wallet Attack ($1.2 Million)
“ZachXBT identified two blockchain addresses associated with this incident: Bitcoin address bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy and Ethereum address 0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c.”
reviewerTwo blockchain addresses are associated with the June 2026 Trezor incident: bc1ql2t0mwtf6unkr8vnlg9hy7njuv7vcvn9nxvlzy (BTC) and 0x491333e8ea6f4fc2a2475db01b649e1e4602ec3c (ETH).Went beyond the cited article and independently confirmed the Bitcoin address exists on-chain with real transaction volume consistent with the alleged theft. - #7[confirmed][no action needed]in section: October 2025: Coinbase Account Attack (~$500,000)
“In October 2025, a separate victim allegedly lost approximately $500,000 in Bitcoin from a Coinbase account.”
reviewerIn October 2025, a victim lost approximately $500,000 in Bitcoin from a Coinbase account.Confirmed by two secondary reports and independently corroborated on-chain: the two cited Bitcoin addresses together hold/moved a combined amount consistent with the alleged $500,000 theft. - #8[confirmed][no action needed]in section: October 2025: Coinbase Account Attack (~$500,000)
“Blockwisely reporting indicates ZachXBT also shared recordings from this incident in which Milanovich allegedly complained about her share of the proceeds, providing additional audio evidence connecting her to the operation.”
reviewerBlockwisely reported ZachXBT shared recordings of Milanovich complaining about her share of the Coinbase-incident proceeds.Direct match to the cited source. - #9[confirmed][no action needed]in section: February 2026: Discord Call and DAI Holdings
“One connected Ethereum address, 0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc, reportedly held approximately 631,000 DAI at the relevant time.”
reviewerAn Ethereum address linked to a February 2026 Discord call, 0x0b8cf7c3c66aa9478b101e203dc31b4e7200dfbc, reportedly held approximately 631,000 DAI.Went beyond the cited article and independently verified the address is real and currently holds a DAI balance consistent with the reported figure. - #11[confirmed][no action needed]in section: Modus Operandi: Phishing Infrastructure and Money Laundering
“Stolen funds were laundered through instant exchange services that did not enforce rigorous Know Your Customer requirements, with some transactions originating from Monero, consistent with techniques used to obscure fund provenance.”
reviewerStolen funds were laundered through instant exchange services lacking rigorous KYC, with some transactions originating from Monero.Corroborated across multiple secondary reports of the ZachXBT investigation. - #12[confirmed][no action needed]in section: Modus Operandi: Phishing Infrastructure and Money Laundering
“Blockwisely reported that some stolen funds remained inactive on-chain as of the report date.”
reviewerBlockwisely reported that some stolen funds remained inactive on-chain as of the report date.Confirmed, though the page's generic phrasing slightly broadens Blockwisely's more specific statement (which was about the June 2026 Trezor funds specifically). - #13[confirmed][no action needed]in section: Post-Theft Behavior: Taunting and Public Display of Proceeds
“ZachXBT presented evidence that Milanovich recorded herself taunting victims on phone calls after their funds had been drained, and that these recordings were distributed in private Telegram groups.”
reviewerMilanovich recorded herself taunting victims on phone calls after their funds had been drained, and these recordings were distributed in private Telegram groups.Matches ZachXBT's own primary-source language. - #14[confirmed][no action needed]in section: Post-Theft Behavior: Taunting and Public Display of Proceeds
“Shuffle reportedly reviewed the evidence provided by ZachXBT and confirmed that her account would be locked.”
reviewerShuffle casino reviewed the evidence ZachXBT provided and confirmed Milanovich's account would be locked.Confirmed by two independent secondary reports. - #15[confirmed][no action needed]in section: Connection to John Daghita ('Lick') and the $46M U.S. Marshals Theft
“Daghita is alleged to have stolen more than $46 million in cryptocurrency from wallets managed by Command Services & Support (CMDSS), a Virginia contractor with U.S. Marshals Service contracts for seized crypto custody.”
reviewerDaghita is alleged to have stolen more than $46 million in cryptocurrency from wallets managed by CMDSS, a Virginia contractor with U.S. Marshals Service contracts for seized crypto custody.Confirmed by tier-1 sources (Forbes, CoinDesk) and TRM Labs. - #16[confirmed][no action needed]in section: Connection to John Daghita ('Lick') and the $46M U.S. Marshals Theft
“Daghita is the son of CMDSS president Dean Daghita.”
reviewerDaghita is the son of CMDSS president Dean Daghita.Confirmed by two tier-1 sources. - #18[confirmed][no action needed]in section: Connection to John Daghita ('Lick') and the $46M U.S. Marshals Theft
“French Gendarmerie officers reportedly found Daghita at a villa on Saint Martin with $239,348 in cash, a Rolex GMT Master, and multiple hardware wallets containing stolen cryptocurrency.”
reviewerFrench Gendarmerie officers found Daghita at a villa on Saint Martin with $239,348 in cash, a Rolex GMT Master, and multiple hardware wallets containing stolen cryptocurrency.Precise figures corroborated by an independent secondary account, though sourced through social-media summaries rather than a primary court or law-enforcement document. - #19[confirmed][no action needed]in section: Legal Status and Law Enforcement Activity
“WEEX reporting stated that Milanovich 'is expected to face legal consequences,' though this reflects editorial assessment rather than confirmed legal action.”
reviewerWEEX reporting stated Milanovich 'is expected to face legal consequences,' reflecting editorial assessment rather than confirmed legal action.Direct quote match, and the page's hedging is accurate. - #21[confirmed][no action needed]in the timeline
“Alleged theft of approximately $500,000 in Bitcoin from a Coinbase account via phone-based support impersonation. Exact date within October 2025 unconfirmed.”
reviewerOctober 2025: alleged theft of approximately $500,000 in Bitcoin from a Coinbase account via phone-based support impersonation.Consistent with the corresponding section and on-chain address activity. - #22[confirmed][no action needed]in the timeline
“John Daghita ('Lick'), alleged associate, participated in a Telegram 'band-for-band' exchange and screen-shared a wallet containing tens of millions of dollars traceable to U.S. government seizure addresses. ZachXBT observed and began tracing the funds.”
reviewerDaghita participated in a Telegram 'band-for-band' exchange and screen-shared a wallet traceable to U.S. government seizure addresses, dated 2026-01-23, after which ZachXBT began tracing the funds.Unlike the corresponding prose in sections[6].content (which incorrectly says 'January 2025'), this timeline entry's date field (2026-01-23) is correct per ZachXBT's own tweets and contemporaneous CoinDesk reporting. The event content/date value itself needs no correction; only the prose in sections[6] does. - #23[confirmed][no action needed]in the timeline
“CoinDesk reported that U.S. Marshals were investigating claims that the son of a government contractor had stolen $40 million in seized cryptocurrency.”
reviewerCoinDesk reported that U.S. Marshals were investigating claims that the son of a government contractor had stolen $40 million in seized cryptocurrency, dated 2026-01-26.Date and figure both check out against the article as published. - #24[confirmed][no action needed]in the timeline
“John Daghita arrested on Saint Martin island by joint FBI and French Gendarmerie operation in connection with alleged $46 million theft from U.S. Marshals Service seizure wallets.”
reviewerJohn Daghita was arrested on Saint Martin island on 2026-03-05 by a joint FBI/French Gendarmerie operation over the alleged $46 million theft.Core facts (location, agencies, $46M figure, March 2026) are solidly confirmed by tier-1 sources. There is a minor, unresolved one-day ambiguity (March 4 vs March 5) in the underlying reporting itself that is not clearly attributable to a page error, so no correction is proposed. - #25[confirmed][no action needed]in the timeline
“ZachXBT published a public investigation on X publicly naming Tiffany Milanovich and linking her to at least $5 million in crypto support impersonation thefts. Multiple crypto news outlets reported on the findings the same day. Shuffle casino confirmed account lockdown.”
reviewerZachXBT published a public investigation on X on 2026-08-10 naming Tiffany Milanovich; Shuffle casino confirmed account lockdown.Confirmed.