Skip to content
SECURITY UPDATES:

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8M in Crypto


Treasury sanctions and a DOJ seizure warrant hit the Telegram-based marketplace accused of processing more than $24 billion for scam operators, money launderers, and trafficking recruiters.

What happened

On September 9, 2026, the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned Xinbi Guarantee, calling it a Chinese-language platform used extensively by transnational criminal organizations and money laundering networks behind cyber scam operations targeting Americans.[1] Two supporting firms were named alongside it: Cambodia-based Anwen Technology Co. and Singapore-based Safe W Technology.[1]

Treasury sanctions and a DOJ seizure warrant hit the Telegram-based marketplace accused of processing more than $24 billion for scam operators,


The action carried real financial teeth. A day earlier, on September 8, the U.S. Secret Service froze $52.8 million in USDT held across 52 wallets tied to Xinbi Guarantee, using intelligence from blockchain analytics firm Elliptic.[2] Investigators separately seized two cryptocurrency wallets allegedly used by Xinbi to process vendor payments, containing about $12 million, and sought to restrain 47 additional connected wallets.[3] Tether, the issuer of USDT, assisted investigators with the cryptocurrency portion of the operation.[3]

A federal court also moved against the platform's infrastructure. A judge in Washington authorized the seizure of the Telegram channels hosting the marketplace on September 7.[4] U.S. Attorney for the District of Columbia Jeanine Pirro said her office had issued a signed warrant to seize the channels where vendors conducted business and advertised to scammers.[4]

What Xinbi Guarantee actually was

Despite the name, Xinbi wasn't a conventional online storefront. It ran as an escrow system: vendors posted crypto deposits so buyers could trust they'd get what they paid for, from stolen personal data to money-laundering services that turned stolen funds back into cash.[2] Once a scammer purchased a service, Xinbi held the payment until the vendor completed the work — a dispute-resolution layer built for a criminal supply chain.[5]

The scale, as described by Treasury, was substantial. Since its inception around 2022, Xinbi's marketplace had processed the equivalent of over $24 billion in digital assets and fiat currency, primarily facilitating transactions tied to Southeast Asia.[6] According to cyber intelligence firm DarkTower, more than 4,600 crime-as-a-service vendors were active on the platform in the week before the takedown; one report placed its total user base above 650,000.[2][7]

The catalog of services went well beyond simple fraud. DOJ described vendors advertising custom scam investment websites, money-laundering services, and recruitment of trafficking victims to work in Southeast Asian scam compounds.[5] Investigators say they traced American victims' stolen funds directly to Xinbi vendors — funds were traced to vendors that advertised money-laundering services and posted cryptocurrency wallets for payment on Telegram.[4] In one case cited by the Secret Service, a Virginia resident reported losing $800,000 in a scheme routed through the Xinbi network.[7]

Why now: the Huione connection

Xinbi didn't appear in a vacuum. Xinbi grew directly out of Telegram's takedown of Huione Guarantee following international pressure — a predecessor platform that saw an estimated $31 billion in activity before it closed.[2] When that door shut, the same criminal customer base largely migrated rather than disappeared. After the Financial Crimes Enforcement Network identified Huione Pay as a financial institution of primary money-laundering concern, cybercriminals shifted activity to Xinbi Guarantee, which kept serving an overlapping set of customers.[8]

That history matters for reading this takedown correctly. Disrupting one guarantee marketplace has historically pushed its vendor ecosystem toward a successor platform rather than eliminating it — which is likely part of why U.S. officials are treating this as an ongoing campaign rather than a single decisive strike. The U.K. had already acted against Xinbi separately, months earlier: OFAC's action complements the United Kingdom's March 26, 2026 sanctions action against Xinbi.[6]

Scale of the broader crackdown

This action was one entry in a longer-running effort. The Justice Department's Scam Center Strike Force, which coordinated the operation, said the day's restraint action brought its cumulative total to approximately $938 million restrained since the strike force launched in November 2025.[3] Beyond the financial seizures, DOJ personnel were also active on the ground: the department said personnel were deployed to Madagascar to assist with the takedown of 13 Chinese-run scam compounds.[9]

Some reporting also links Xinbi to a wider sanctions history — one account states the platform has reportedly been used by North Korean hackers and several previously sanctioned entities, including Jin Bei Group Co., Ltd.[10] That specific claim comes from a single secondary source reviewed for this article rather than a primary Treasury document, so it should be treated as reported rather than independently confirmed here.

How the operators responded

Xinbi did not go quietly. The marketplace posted a statement condemning the "arbitrary freezing" of its funds and promised to compensate its customers.[7] It also reportedly moved $2.8 million into USDD, a stablecoin that lacks USDT's built-in freeze switch, though its reserves are partly backed by USDT anyway.[7] That's a direct attempt to route around the exact enforcement lever that had just been used against it. By the next day, according to one tracker, Xinbi Guarantee's business address, which had just been activated on September 8, 2026, had already been frozen again.[6]

What this means for potential victims

For most consumers, the practical takeaway isn't really about Xinbi as a brand — few Americans interacted with the platform directly. It's about the schemes downstream of it: fraudulent investment platforms, romance-and-crypto "pig butchering" scams, and fake brokerages, many of which relied on Xinbi-adjacent vendors for laundering and infrastructure. Anyone who has sent cryptocurrency to an investment platform they can't independently verify — especially one introduced through social media or a messaging app — should treat that as a warning sign regardless of what happens to any single marketplace.

Victims of suspected crypto investment fraud can report to the FBI's Internet Crime Complaint Center (IC3.gov) or the U.S. Secret Service.

Security takeaway

Whether this action meaningfully degrades the scam-center ecosystem, or simply pushes vendors toward the next unregulated escrow platform the way Huione's closure pushed them toward Xinbi, will only become clear over the coming months. The pattern so far — sanction, seize, watch the network reconstitute elsewhere — suggests this is a containment strategy rather than a knockout blow, and defenders and consumers alike should expect a successor platform rather than assume the underlying fraud economy has been dismantled.

Sources & References

  • [1] U.S. Department of State — Dismantling Transnational Criminal Organization Xinbi Guarantee — September 9, 2026 — Official press statement
  • [2] The Record — US disrupts Xinbi Guarantee marketplace fueling the cyber scam economyView source
  • [3] Diya TV — DOJ seizes $52 million in crypto scam crackdown — September 9, 2026 — View source
  • [4] Local12 — DOJ takes down Chinese scam network targeting "every American with a retirement account"View source
  • [5] Washington Times — Feds move to shut down Chinese cyberscam factoryView source
  • [6] PJ Media — Chinese Scam Marketplace Moved $24 Billion. The Feds Just Hit It.View source
  • [7] Decrypt — Secret Service Freezes $52.8 Million in Crypto Tied to Telegram Bazaar Behind Global ScamsView source
  • [8] SocialNews.XYZ — US sanctions Chinese-language scam hub — September 9, 2026 — View source
  • [9] Washington Times — Feds move to shut down Chinese cyberscam factory (Madagascar compound takedown) — View source
  • [10] HI India — US sanctions Chinese-language scam hubView source (single secondary source; North Korea/Jin Bei Group link not independently verified against a primary Treasury document)

Disclaimer: This article summarizes publicly reported law-enforcement and Treasury actions as of September 9–10, 2026. Details of ongoing investigations, including specific dollar figures and entity ties, may be revised as official records are unsealed.

NK

Naseem Khan

Cybersecurity Researcher & Technical Editor

Naseem Khan is the author and technical editor behind UnpanicTech, an independent cybersecurity publication covering vulnerability analysis, defensive security, incident response, cloud security, and practical security engineering.

Technical Discussion & Feedback (0)

Leave a Comment (Authenticated Users)