Search the site
Press ESC to close
LIVE
Loading...
Updating...

ZachXBT Uncovers $2M Crypto Theft Linked to US Impersonation Scams

Fact-checked
2 min read
371 words
Share

The prominent on-chain investigator known as ZachXBT has identified a United States-based threat actor responsible for the theft of over $2 million in cryptocurrency assets. The individual, identified as Tiffany Milanovich, allegedly orchestrated sophisticated social engineering attacks by impersonating customer service representatives for hardware wallet providers and centralized exchanges. The investigation reveals a pattern of systematic fraud targeting users of major platforms, highlighting the persistent risks of phishing within the digital asset ecosystem.

Tactics Used in the Multi-Million Dollar Heist

The threat actor’s primary method involved deceptive communication aimed at gaining unauthorized access to user funds. In one documented instance, Milanovich posed as BitcoinIRA email support, leading to the illicit transfer of approximately $1.2 million in Bitcoin (BTC) and Ethereum (ETH) from a victim's Trezor hardware wallet. Another recorded incident involved the compromise of Coinbase accounts, resulting in the loss of roughly $80,000 in BTC.

  • Impersonation: Posing as support staff to extract private keys or login credentials.
  • Phishing Panels: Collaborating with other actors to deploy fake interfaces for data harvesting.
  • Money Laundering: Utilizing instant exchange services to obfuscate the trail of stolen digital assets.

Post-Theft Activity and Asset Laundering

According to ZachXBT's findings, the suspect did not maintain a low profile following the successful breaches. Milanovich reportedly boasted about the stolen capital on social media platforms and within Telegram groups. Furthermore, recorded calls suggest the actor actively mocked victims after their funds were drained. The investigation indicates that she worked in tandem with a broader network of cybercriminals to facilitate the laundering of proceeds.

Tiffany was responsible for posing as "customer service support" to trick victims into giving up their funds' access... and collaborated with other threat actors to launder money using phishing panels and instant exchange services.

As of August 2026, the investigation remains a critical point of reference for security analysts. A portion of the stolen funds is still being tracked on-chain, as the detective continues to monitor the movement of assets across different blockchains. This case underscores the necessity for cryptocurrency holders to exercise extreme caution with unsolicited support communications, as legitimate hardware wallet manufacturers and exchanges will never request private recovery phrases or direct access to accounts.

Frequently Asked Questions

Quick answers to the most common questions about this topic.