Contrary to the narrative that hardware wallets are impenetrable fortresses, the $5M theft from Trezor and Coinbase users wasn't caused by a zero-day exploit. It was a phone call. That's the uncomfortable truth buried under ZachXBT's latest investigation—a case that exposes the structural vulnerability of an entire ecosystem that has convinced itself code is the only risk.
Context
Between October 2025 and August 2026, a loosely organized ring targeted high-net-worth cryptocurrency holders. The method: impersonate customer support from Trezor, Coinbase, and BitcoinIRA. The caller, Tiffany Milanovich, contacted victims directly, claiming to assist with account issues. The infrastructure behind her—phishing panels provided by pseudonymous actors "bled" and "harm"—enabled credential harvesting and cloned websites. The result: at least $5M in BTC and ETH stolen, with the majority still sitting dormant on-chain, waiting to be cleaned.
ZachXBT, the independent on-chain investigator, connected the dots. He linked Milanovich to John "Lick" Daghita—a man already indicted for stealing $37M from the U.S. Marshals Service. The connection came from an internal feud: a disgruntled associate leaked logs. The FBI later confirmed the investigation, with Director Kash Patel personally tweeting about the case. Chainalysis data shows such impersonation scams surged 1,400% in 2025, with over 80,000 complaints filed to the FBI, totaling $2.9B in losses.
Core Insight: The Attack Is Not Technical—It's Structural
Let's dissect the attack vector. The protocol doesn't have a bug. Trezor's firmware is secure. Coinbase's 2FA is intact. The vulnerability is the human operating the hardware wallet. The attacker exploited trust, not code.
- Target Acquisition: The ring likely purchased customer data from compromised exchanges or wallet vendors. They knew who held significant BTC and ETH, and which devices they used. This is not a guess—it's a data-driven selection process.
- Impersonation Workflow: Milanovich called the victim, claiming to be from Coinbase or Trezor support. She used a spoofed number and a script that referenced real account details. The victim, already primed to trust official-sounding calls, engaged. The goal: convince the victim to reveal their seed phrase, approve a malicious contract, or install remote desktop software.
- Infrastructure Ready: The phishing panels provided by "bled" and "harm" were not custom-built. They were likely purchased from a Phishing-as-a-Service (PhaaS) marketplace. These panels include templates for major platforms, auto-logging, and admin dashboards. The cost to enter the crime business: a few hundred dollars.
- Exit Strategy: The stolen funds remain mostly dormant. This is not incompetence—it's patience. The ring is waiting for the heat to subside before moving through mixers, cross-chain bridges, or OTC desks. The dormancy itself is a risk management strategy.
Hype is just volatility wearing a suit and tie. The crypto industry celebrates decentralization, but it ignores that the most expensive attacks are not on smart contracts—they are on phone lines. The 1,400% surge in impersonation scams is not a bug; it's a feature of a system that outsources trust to customer support hotlines.
Contrarian Angle: What the Bulls Got Right
The optimists will argue that this attack proves the value of self-custody and hardware wallets. They are partially correct. The victims who lost funds had their assets in Trezor wallets and Coinbase accounts—both custodial or semi-custodial setups. A pure self-custody approach, with no interaction with customer support, would have prevented this. But the bulls ignore the middle ground: most users will always need some form of help. The moment a user interacts with a support system, they re-introduce a trusted third party. The attack does not invalidate the security model; it highlights an unsealed interface.
Another angle: the FBI's involvement shows that authorities are getting better at tracking these rings. Daghita's arrest in France within months of ZachXBT's report suggests that the surveillance state is catching up. The bulls might say this is a net positive for institutional adoption—cleaner markets. But I'd argue that the risk is not a number, it's a structural flaw. The flaw is that the industry relies on users to distinguish between a real support call and a fake one. That's not a solvable problem with education alone. It requires protocol-level changes: for example, in-app verification that a support request is genuine, or disallowing phone-based account recovery entirely.
Trust is a variable we must eliminate, not manage. The litigation risk for exchanges like Coinbase is real. If a victim sues, a court will ask: "Why did your system allow a phone call to override hardware security?" The answer cannot be "because the user was tricked." That is a liability, not a defense.
Takeaway
The next evolution of this attack will not be a phone call—it will be a deepfake voice clone of a known support agent, delivered via a hacked customer database. The industry must prepare for that by eliminating the phone as a trust vector. Until then, the $5M theft is not an anomaly. It's a template. Every protocol that offers customer support should read this report and ask: "What is our structural flaw?" The answer is not a number. It's the phone.