BitcoinIRA and iTrustCapital breaches linked to threat actor Tiffany Milanovich
In brief
- ZachXBT linked $5 million in crypto thefts to threat actor Tiffany Milanovich via spoofed emails
- One victim lost $1.2 million in Bitcoin and Ethereum after receiving a spoofed BitcoinIRA email
- Neither BitcoinIRA nor iTrustCapital publicly confirmed breaches as of mid-August
- Tech-support impersonation scams surged 1,400% in recent years, per Chainalysis
- FBI logged 80,000 tech-support impersonation complaints in 2025, totaling $2.9 billion in losses
The Breach and Attribution
ZachXBT's on-chain analysis connected unauthorized access to both platforms with fraudulent activity targeting their customers. According to ZachXBT's investigation, Milanovich gained unauthorized access to customer databases at both BitcoinIRA and iTrustCapital. The damage was precise and severe.
One victim alone lost $1.2 million in Bitcoin and Ethereum after receiving a spoofed email that appeared to come from BitcoinIRA. According to ZachXBT's analysis, Milanovich allegedly impersonated customer support representatives and sent fraudulent emails designed to look like official platform communications. The emails prompted victims to provide sensitive account information, enabling the thefts.
This attack vector is far from isolated. Chainalysis has tracked a 1,400% increase in tech-support impersonation scams over recent years. The FBI logged 80,000 complaints related to tech-support impersonation in 2025, with losses totaling $2.9 billion.
The Disclosure Gap
As of mid-August, neither BitcoinIRA nor iTrustCapital had issued a public statement confirming the breaches. It is unclear when the breach was discovered or when ZachXBT published findings, making it difficult to assess the exact timeline. It is also unclear whether the platforms are coordinating with law enforcement, which may delay public disclosure.
Most US data breach notification laws require companies to inform affected individuals within a reasonable timeframe. The SEC and state regulators have been tightening expectations around cybersecurity disclosures for financial services firms operating in the digital asset space. Silence from both platforms raises questions about compliance with these obligations.
Protecting Your Keys
"No legitimate customer support representative will ever ask for your private keys or seed phrase."
Vigilance matters. Verifying any communication by independently navigating to the platform's website or calling their published support number is basic hygiene that becomes critical in an environment where attackers already have your personal details. If you hold assets on either platform, treat unsolicited emails with extreme skepticism—especially those requesting credentials or seed phrases.


