Silence in the slasher was the first warning sign. But here, the silence was in the stolen funds—over $5 million sitting untouched, while the attacker flaunted luxury on social media. The warning sign was not a code exploit; it was a human failure, engineered by design.
Context: The Case of the Fake Support Caller
In early 2025, a woman named Greavys (real name: Milanovich) allegedly orchestrated a series of social engineering attacks targeting crypto holders with significant assets. Posing as customer support from Trezor, Coinbase, and BitcoinIRA, she convinced victims to hand over access to their wallets. The haul: over $5 million in BTC, ETH, and other assets. The funds were then mixed through Monero, converted to DAI via instant exchanges, and parked in an Exodus wallet. Some went to an online casino, Shuffle. The entire operation was exposed by on-chain investigator ZachXBT, who pieced together chat logs, voice recordings, and blockchain traces. The stolen funds, ironically, remained largely untouched—a fact that should have been a red flag from the start.
Core: The Architecture of a Low-Tech Heist
Let me be clear: this is not a zero-day exploit. This is a process failure. The attack vector is as old as telemarketing—impersonation, social engineering, and a script. Milanovich, the 'caller,' would call victims, spoofing official numbers, and use phishing panels provided by an accomplice known as 'bled' or 'harm.' The technical sophistication is minimal. The real sophistication lies in the targeting: victims with large holdings, often using hardware wallets and centralized exchanges, who trust the customer support voice.
From a forensic standpoint, the funding flow is a textbook case of attempted privacy. Monero was used to break the chain. Then, instant exchanges converted it to DAI. The Exodus wallet holding 631,000 DAI became the sink. The casino, Shuffle, became the mixer. But the critical flaw is the exit point. As I noted in my post-mortem of the Ronin bridge hack, the vulnerability is not in the mixing but in the conversion. When Monero enters an instant exchange, the exit address becomes a beacon. ZachXBT tracked that beacon. The proof is in the unverified edge cases: the instant exchange's AML (Anti-Money Laundering) did not flag the transaction. Why? Because the volume was not suspicious in isolation. Complexity is not a shield; it is a trap. The complexity of Monero's privacy is undone by the simplicity of a single DAI address.
Let me dissect the timeline. The stolen funds were sent through multiple Monero transactions, then swapped to DAI. The Exodus wallet appeared. ZachXBT, using OSINT (Open Source Intelligence) and chain analysis, correlated the chat logs where Milanovich boasted about the haul. The chat logs included a voice recording where she mocked a victim. She also edited a video to make it look like she stole more, showing a fake Ledger Live balance of 7.7K JITOSOL. This is not a professional criminal. This is someone who thinks the blockchain is anonymous because of Monero, but forgets that the exit is a window.
When the math holds but the incentives break, the system fails. Here, the incentives broke because the attacker had no discipline. She spent money on luxury goods, gambling, and bragging. The stolen funds were not moved; they were sleeping. That sleeping money became a trap. ZachXBT already had the address monitored. The silence in the slasher—the lack of movement—was the first warning sign for the attacker, but she ignored it. She even complained about the split with her accomplice, John Daghita (known as 'Lick'), who later doxxed her in retaliation. Internal entropy is a feature, not a bug.
Contrarian: The Real Vulnerability Is Not Code, It's Trust
The entire crypto security narrative focuses on smart contract bugs, private key leaks, and MEV attacks. But this case reveals a more fundamental weakness: the trust layer between users and platforms. The infrastructure of customer support—email, phone, chat—is a soft target. Trezor, Coinbase, and BitcoinIRA have robust code, but their customer service channels are easily spoofed. The attack did not break any cryptographic invariant. It broke the invariant of human trust.
Furthermore, the role of 'community investigators' like ZachXBT is a double-edged sword. They are effective, but they are not a scalable solution. In this case, ZachXBT acted as a de facto law enforcement agency, collecting evidence, identifying suspects, and coordinating with platforms like Shuffle to freeze accounts. But this is a single point of failure. What if ZachXBT is wrong? What if he is sued for defamation? The legal system is slow, and the crypto community's trust in a single individual is fragile. The contrarian truth: we are building a security ecosystem that relies on the goodwill and expertise of a few, while the attack surface expands exponentially.
Another blind spot: the instant exchange. These platforms are the new banks. They perform KYC (Know Your Customer) but not real-time chain analysis. The Monero-to-DAI conversion was not flagged because the KYC on the exchange was likely bypassed or the volume was split. The industry needs to rethink AML at the exit ramp. Based on my experience auditing the Curve Stableswap invariant, I know that the edge cases are where the real risks live. Here, the edge case is a single transaction that looks clean but is part of a larger pattern.
Takeaway: The Future of Security Is Process, Not Code
This case is a watershed. It will accelerate regulatory pressure on privacy coins and online casinos. Monero will face increased scrutiny. Shuffle and similar platforms will be forced to implement real-time chain monitoring. But the deeper lesson is for users: no customer support call will ever ask for your seed phrase. The vulnerability is in the process, not the protocol.
When the next caller impersonates, will your platform's verification survive? The answer is not in a new smart contract. It is in a better phone call. The proof is in the unverified edge cases—and they are everywhere.

