On March 13, 2025, a single Exodus wallet held 631,000 DAI. The funds traced back to a series of Monero instant exchanges. The source? Stolen from at least two victims, totaling over $5 million. This is the Greavys case—a textbook example of low-tech attack, high-value loss, and the power of on-chain forensics.
Context: The Attack Vector The attackers operated with a simple but effective playbook. They impersonated customer support representatives from Trezor, Coinbase, and BitcoinIRA. The primary caller, identified as Greavys (real name Milanovich), would cold-call victims, spoofing official numbers and using background noise to simulate a call center. Another actor, known as "bled" or "harm," provided the phishing infrastructure—fake websites and email templates. A forged email from "Patricia Massie" at BitcoinIRA was used to gain trust. The victims were not small retail holders; they held significant assets—one had a Trezor wallet with approximately $1.2 million in BTC and ETH, another had a Coinbase account with $500,000 in BTC. The attack relied entirely on social engineering, not on any cryptographic exploit.
Core: The On-Chain Evidence Chain Follow the metadata, not the mood. ZachXBT, the independent on-chain investigator, pieced together the flow using a combination of chat logs, recorded phone calls, and blockchain data. The stolen funds were initially moved to a series of intermediate wallets. Then, the attackers converted the assets to Monero—a privacy coin designed to obscure transaction history. This step was intentional: to break the chain. But the exit was the bottleneck. The Monero was subsequently exchanged back to DAI via instant exchange services. One such exchange led to a single Exodus wallet that, at the time of the investigation, held 631,000 DAI. The wallet was not yet drained because ZachXBT had already flagged it. The forensic trail did not stop there. A portion of the funds was sent to Shuffle, an online casino. After ZachXBT provided evidence, Shuffle locked the associated account. The casino's cooperation was a rare bright spot in an otherwise slow institutional response.
Data doesn’t care about your timeline. The internal conflicts within the criminal group accelerated the case. John Daghita—another threat actor previously exposed by ZachXBT—publicly doxxed Milanovich in retaliation for a dispute over the stolen funds. The chat logs revealed arguments over splits, with Milanovich complaining about not receiving her share. This off-chain evidence, combined with the on-chain trail, formed a complete loop. The attackers also made critical errors: they posted videos showing off luxury goods, modified screenshots to inflate the stolen amount, and even recorded themselves mocking the victims. The arrogance was self-destructive.
Contrarian: The Real Weakness Is Not Technology The common narrative is that crypto is insecure because of smart contract bugs or private key leaks. This case proves otherwise. The attack did not exploit any vulnerability in Trezor hardware, Coinbase’s infrastructure, or the Bitcoin network. It exploited a human process: the trust in a phone call. The attackers simply identified high-net-worth individuals and called them, pretending to be support. The platforms themselves—Trezor, Coinbase, BitcoinIRA—had no mechanism to verify that their official support channels were not being impersonated. The phishing panels were generic; the social engineering scripts were not sophisticated. Yet the attack succeeded because the victims were not conditioned to question the authenticity of a phone call from a known brand.
Another blind spot: Monero privacy is not absolute. The attackers assumed that converting to Monero would make the funds untraceable. But the instant exchange exit created a new transaction on a transparent chain. Once the destination address was identified, all subsequent activity was visible. This is a fundamental limitation of using privacy coins in a broader crypto ecosystem that still relies on public blockchains for settlement. The exit is always the weakest link.
Takeaway: Next-Week Signal The Greavys case is not an anomaly. It is a signal that the next wave of attacks will target the human layer, not the code layer. The average crypto user does not expect a phone call from their wallet provider. The platforms must add authentication layers—such as out-of-band verification codes or in-app notifications—before any support request is processed. The on-chain forensic methodology demonstrated here—OSINT plus blockchain data—is becoming the standard for law enforcement. The Connecticut search warrant, dated earlier than some of the events described in the public thread, suggests that collaboration between investigators and law enforcement is already underway. The question is not whether the industry will adopt these practices, but how quickly the weakest links will be reinforced.
Follow the metadata, not the mood. The evidence is clear: the attack was avoidable, the trace was possible, and the accountability is now in the hands of the courts. The data doesn’t care about your timeline—it only waits to be read.