CryptocurrencyNews

How a “Calm Voice” Stole $5 Million

Join our Trading Community on Telegram

On-chain investigator ZachXBT published on X the results of an investigation that identified American woman Tiffany Milanovich, who has been linked to an organized group accused of stealing at least $5 million from digital-asset holders.

What makes this story particularly notable is that the criminals did not exploit some extraordinary blockchain vulnerability, hack sophisticated smart contracts, or rely on an exclusive technical exploit. Their main weapon was a much older and, as practice shows, extremely effective technology — social engineering.

The attackers did not so much hack wallets as persuade the owners themselves to open the door. The technical infrastructure was merely a tool: phishing websites imitated the interfaces of well-known services, fake emails created a sense of emergency, and phone calls turned the victim’s initial panic into a scenario controlled by the scammers.

The scheme relied on a fairly simple psychological trick. First, a potential victim received an alarming message supposedly from a well-known crypto exchange, investment service, or another familiar brand. The message warned of suspicious activity, an unauthorized login, or an attempted withdrawal. The person was urged to take immediate action to protect the account.

Almost immediately afterward, a phone call would arrive. According to the investigation, Milanovich acted as an operator, posing as a customer-support representative. And this was where the most important part of the attack began.

After receiving a frightening notification, the victim expected another source of stress. Instead, they encountered a calm, confident, and friendly voice.

The psychological contrast worked in the scammers’ favor: first, the victim was convinced that their assets were under threat, and then they were offered “help” in saving them.

As a result, even an experienced cryptocurrency user could stop viewing the situation as a potential attack and begin following the instructions of someone who supposedly wanted to protect them.

The victim was then directed to a fake page or phishing panel. In some cases, the attackers persuaded the wallet owner to enter their seed phrase — a sequence of words that effectively serves as the master key to their crypto assets.

This is a crucial point: the criminals did not need to guess a password, hack a hardware wallet, or find a vulnerability in the blockchain. The owner handed them the key to their own vault, believing they were carrying out a security procedure.

Once the seed phrase was obtained, the attackers could gain full control of the assets and transfer the funds to addresses they controlled.

In the cryptocurrency world, such an operation is particularly dangerous: once a transaction has been confirmed, it generally cannot be reversed through a bank or customer support.

The blockchain does not ask whether a transfer was made voluntarily, under threat, or after a conversation with a very convincing woman. If the transaction is signed and broadcast to the network, it cannot be reversed through standard means.

Milanovich Was Not Brought Down by Technology, but by Her Own Bragging

One of the key elements of the investigation was material that the alleged group member herself left behind in private chats and on social media.

Rather than trying to hide her tracks as thoroughly as possible, Milanovich, judging from the material collected by ZachXBT, showed people around her the results of her activities.

She recorded mocking prank calls with victims while the phone conversations were taking place, including after the withdrawal of stolen funds had already been confirmed.

Private Telegram chats contained videos showing stacks of cash, screens displaying large balances, and demonstrations of an expensive lifestyle. In some cases, according to the investigation, she even used stolen funds to place bets at the Shuffle crypto casino while speaking to the victim on the phone.

After the researcher contacted the platform, it confirmed that the account associated with the alleged scammer had been blocked. By that point, however, the digital trail had already extended far beyond a single account.

The desire to demonstrate status within the criminal community pushed participants to leave behind more and more evidence.

There is a peculiar form of internal competition in such groups: it is not enough to make money — you also have to prove to everyone around you exactly how much you made.

And that need for recognition often becomes one of the criminals’ weakest points.

In one case, Milanovich allegedly edited video footage to create the impression of higher status and demonstrate supposed access to significant cryptocurrency assets. In particular, in a video recorded in the Ledger Live interface, she portrayed herself as the owner of a service hot wallet receiving 7.7K JITOSOL.

Posts that were seemingly intended to demonstrate success within a closed circle ultimately became part of the evidence.

The $1.2 Million Theft and the Attack on Trezor

One of the most serious incidents occurred in June 2026. According to the investigation, one victim lost approximately $1.2 million in Bitcoin and Ethereum.

The scenario once again began with a fake message designed to create the impression of an official communication.

This time, the attackers used the name BitcoinIRA and presented themselves as company employees, including by using the name Patricia Massie.

After establishing contact, the victim was persuaded to perform actions that ultimately allowed the attackers to gain control of a Trezor hardware wallet. The funds were subsequently withdrawn from the wallet.

Particularly significant is the fact that addresses linked to the theft, according to the investigation, still contain some of the funds that have not been moved further. This gives researchers an opportunity to track the movement of the assets directly on the blockchain.

At the same time, the infrastructure behind the phishing panels used in the attack has been linked to another member of the group operating under the pseudonyms “bled” and “harm.”

This suggests that we are not dealing with a lone scammer improvising during a phone call, but with a distributed structure in which different participants handle different stages: creating phishing infrastructure, communicating with victims, obtaining seed phrases, moving funds, and subsequently laundering or spending the cryptocurrency.

Crypto Casinos, Monero, and the Illusion of Anonymity

Another episode that attracted ZachXBT’s attention involved a February Discord competition called “band 4 band.”

Such events effectively become competitions in displaying wealth: participants show each other their wallet balances and attempt to prove who controls the most money.

To an ordinary person, it may look like pointless bragging. To an on-chain investigator, it can be a potential source of extremely valuable information.

According to the investigation, as part of such a competition, Milanovich transferred $100,000 to an Exodus wallet. The address that the researcher associates with her activities later held approximately 631K DAI.

The funds were allegedly replenished through instant swaps using Monero — a cryptocurrency designed to provide enhanced transaction privacy.

The participants presumably expected that combining Monero, crypto casinos, numerous wallets, and intermediary swaps would make it significantly harder to trace the origin of the funds.

But this is where the scheme ran into its biggest problem: the blockchain itself may be relatively difficult to analyze, but human behavior remains predictable.

If someone first displays a large balance, then publishes material about their earnings, uses particular wallets, and simultaneously leaves recordings of conversations, an investigator can begin connecting individual fragments into a single chain.

Cryptocurrency anonymity does not mean anonymity for a person who constantly tells everyone around them how much money they have.

Connection to the $46 Million Theft from the U.S. Government

Milanovich’s story also intersects with another high-profile ZachXBT investigation.

In late January 2026, the researcher identified John Daghita, known by the pseudonym Lick, in connection with the theft of approximately $46 million in cryptocurrency assets that were under the control of the U.S. government.

According to the investigation, Milanovich maintained close communication with Daghita. At one point, she recorded one of his conversations and published the recording online, effectively using it to troll him.

But the attempt to publicly humiliate another participant in the crypto-criminal environment ultimately backfired.

In response, Daghita published her real name in a public Telegram channel.

Thus, one participant inadvertently helped identify another, while public conflicts within the criminal community began creating even more connections between people, accounts, wallets, and phone numbers.

What was perceived as entertainment inside the closed circle ultimately became additional material for the investigation.

How the Digital Puzzle Was Assembled

In investigations like these, there is almost never a single “magic” piece of evidence.

The result usually comes from combining dozens of seemingly unrelated elements: blockchain addresses, transaction histories, social media posts, phone-call recordings, screenshots, photographs, usernames, messages from private chats, cryptocurrency-service data, and information from public sources.

In Milanovich’s case, human mistakes played a particularly important role.

She herself displayed financial results, recorded conversations, published material in private communities, and sought to prove to those around her that she was involved in major operations.

At a certain point, these scattered pieces of data began forming a single picture.

The illusion of anonymity was further undermined by moving funds between different services.

Monero does provide a significantly higher level of privacy than transparent blockchains such as Bitcoin or Ethereum, but using a privacy-focused cryptocurrency does not erase every other trace.

If the same person is simultaneously connected to certain accounts, devices, social-media profiles, phone conversations, and other cryptocurrency addresses, the movement of funds becomes just one part of a much larger digital puzzle.

The Strangest Evidence — Documents from the System Itself

Of particular interest is information that Milanovich herself allegedly published in the form of a screenshot of a document related to a search and seizure in the state of Connecticut.

The document was dated to a period preceding some of the incidents described in the investigation.

In addition, in a separate audio recording, she allegedly mentioned a booked flight and stated that her funds remained untouched.

For investigators and independent researchers, such material is especially valuable because it is created directly by the subject and allows their statements to be compared with objective blockchain data and other digital evidence.

The evidence collected by ZachXBT was passed on to relevant U.S. authorities.

However, it is important to distinguish the findings of an independent on-chain investigation from legally established guilt.

Identifying a person, linking them to particular addresses, and publishing evidence online do not in themselves constitute a court conviction.

The final legal assessment must be made by the competent authorities and the courts.

Social Engineering Is Becoming the Main Weapon of Crypto Scammers

The Milanovich case demonstrates a much broader trend that extends well beyond a single group.

For years, the cryptocurrency industry focused primarily on technical threats: smart-contract hacks, protocol vulnerabilities, server compromises, coding errors, and attacks on exchange infrastructure.

But as technical security becomes more sophisticated, criminals are increasingly attacking not the code, but the person.

The logic is simple.

Breaking into a well-protected hardware wallet is extremely difficult. Convincing its owner to voluntarily reveal their seed phrase is much easier.

There is no need to bypass multiple layers of protection if you can convince someone that they must disable that protection themselves in order to save their money.

This is where social engineering exploits one of the most fundamental human reactions — the fear of loss.

A message saying, “Someone is trying to steal your money” automatically puts a person into emergency-response mode.

At that moment, critical thinking can give way to the desire to solve the problem as quickly as possible.

The scammer only needs to offer a solution — and present themselves as the person capable of helping.

That is why the combination of “alarming email + phone call + confident support representative” is so effective.

Each element reinforces the next.

The email creates the problem, the phone call creates trust, the phishing page creates the illusion of an official procedure, and the victim performs the critical action themselves.

Why Cryptocurrency Is Particularly Vulnerable

The cryptocurrency industry has a fundamental characteristic that makes such attacks especially dangerous.

Many traditional financial systems have mechanisms for cancelling or disputing suspicious transactions. A bank may freeze a transfer, reverse a transaction, or investigate fraud.

The blockchain has no universal equivalent.

If a wallet owner personally signs a transaction and sends the assets to another address, the network does not distinguish between the legitimate owner and the scammer.

To the blockchain, it is simply a valid transaction carrying a correct cryptographic signature.

That is why the moment a victim reveals a seed phrase or signs a malicious transaction can effectively become the point of no return.

After that, technical specialists can track the funds, blockchain analysts can build transaction graphs, exchanges can freeze associated accounts, and law enforcement can investigate — but there is no simple “undo transfer” button.

The Broader Trend in 2026

The Milanovich case can be viewed as one example of a much broader shift in the structure of cryptocurrency crime.

In 2025, the crypto market lost more than $1.8 billion to fraud and various exploits, with a significant share of the damage linked not to classic blockchain-protocol hacks, but to attacks involving deception, phishing, impersonation, and social engineering.

This reflects a broader trend in financial fraud.

Phone scammers have been exploiting trust, fear, and authority for decades instead of relying on weapons or sophisticated technical tools.

The difference is that in cryptocurrency, the potential target can be sitting in a single wallet and be worth millions of dollars, while the transfer of funds can happen almost instantly.

This creates a paradoxical situation: the more money moves into the digital environment, the less sophisticated technology scammers sometimes need.

The weakest link turns out to be the person holding the key to the money.

The Main Takeaway

The story of Tiffany Milanovich is not so much about criminals learning how to hack cryptocurrency wallets as it is about criminals learning how to make wallet owners dismantle their own security.

The most dangerous weapon in this scheme is neither malicious code nor a blockchain vulnerability.

It is the convincing voice of someone saying:

“Don’t worry, I’m from security. We’re going to protect your money now.”

That is why technical literacy alone is no longer enough.

A user may understand Bitcoin perfectly well, use a hardware wallet, store their seed phrase separately, and avoid suspicious websites — and still lose their money if, at a critical moment, they trust the person on the other end of the phone.

Perhaps the next major security technology for cryptocurrency users will not be even more sophisticated cryptography, but a reliable system for verifying the identity of people who attempt to contact them.

But that raises a difficult question: can technology ever completely neutralize the human factor?

After all, a scammer does not necessarily have to fool a computer.

They only have to convince a person that the individual standing on the other side of the conversation is someone they can trust.

And that is the main lesson of the ZachXBT investigation: in cryptocurrency, you can build virtually impenetrable technical security, but if a person opens the door themselves, no blockchain can save them.

0
0
Disclaimer

All content provided on this website (https://wildinwest.com/) -including attachments, links, or referenced materials — is for informative and entertainment purposes only and should not be considered as financial advice. Third-party materials remain the property of their respective owners.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related posts
Disruptive technologyNews

Is Anthropic Quietly Watermarking AI-Generated Text?

The entire X is currently discussing reports that Anthropic has begun introducing invisible…
Read more
Disruptive technologyForex brokersNewsStock brokersStock research & analytics

The Gravity of the Financial Market — or Why the Darlings Went Into a Tailspin

The space euphoria in the stock market has given way to harsh reality. Riding the wave of excitement…
Read more
Disruptive technologyNewsStock research & analytics

Is Apple Preparing a Global Price Increase?

Apple may soon revise prices across the iPhone 17 lineup. According to insider reports, the company…
Read more
Telegram
Subscribe to our Telegram channel

To stay up-to-date with the latest news from the financial world

Subscribe now!