U.S. Disrupts Xinbi Guarantee, Freezing $52.8 Million Tied to Global Scam Networks
Malware

Illustrative image generated with AI

U.S. Disrupts Xinbi Guarantee, Freezing $52.8 Million Tied to Global Scam Networks

U.S. authorities seize Telegram channels and crypto wallets, freeze $52.8M in USDT, and sanction Xinbi Guarantee, a marketplace enabling pig-butchering scams.

Text generated by artificial intelligence, published without human review. AI transparency

Telegram channels and cryptocurrency wallets taken offline

U.S. authorities announced coordinated action on Wednesday against Xinbi Guarantee, a Chinese-language marketplace that supplied infrastructure and financial services to cyber-enabled fraud operations.

The Department of Justice seized the Telegram channels and usernames hosting the marketplace after receiving authorization from a district court on the preceding Monday. Xinbi’s main channel was no longer reachable by Wednesday.

Investigators also seized two cryptocurrency wallets containing approximately $12 million. In a broader financial operation, the U.S. Secret Service worked with blockchain analytics company Elliptic and stablecoin issuer Tether to freeze $52.8 million across 52 wallets associated with Xinbi and its merchant network.

The Justice Department said roughly $52 million in suspected scam-laundering funds was restrained in a single day. That brought the total amount restrained by the Scam Center Strike Force to approximately $938 million.

The Treasury Department’s Office of Foreign Assets Control sanctioned Xinbi and two companies accused of supporting its operations. The Record identified the businesses as Anwen Technology and SafeW Technology Co.

Anwen Technology, based in Cambodia, developed the XinbiPay cryptocurrency payment application. SafeW Technology produced an encrypted messaging application allegedly used by Xinbi merchants and money-laundering networks.

No wallet addresses, domains, Telegram identifiers or other technical indicators have been publicly provided. This limits what financial institutions and security teams can independently search for in their internal records.

A one-stop supplier for industrialized fraud

Created in 2022, Xinbi operated as an escrow intermediary between specialized vendors and the criminal groups running scam compounds. Elliptic describes it as the second-largest illicit online marketplace recorded to date.

Estimates of its transaction volume vary. One reported figure places activity at approximately $30 billion since the marketplace’s creation, while another says it processed at least $24 billion. DarkTower counted more than 4,600 crime-as-a-service vendors on Xinbi as of the previous week.

The marketplace supported pig-butchering and romance scams, in which operators cultivate relationships with victims before directing them toward fraudulent investments. Xinbi’s role extended beyond payments.

Services advertised through the platform reportedly included:

  • Custom investment websites designed to impersonate legitimate trading services.
  • Money laundering for proceeds originating from wire fraud.
  • Stolen personal information used to profile or impersonate victims.
  • Deepfake tools for social engineering and fraudulent identities.
  • Recruitment or trafficking of workers into Southeast Asian scam compounds.
  • Financial and communications services for merchants serving those compounds.

This structure allowed scam operators to purchase the components of a campaign from different vendors while relying on Xinbi to hold or transfer payment. The escrow model reduced distrust among criminals who might otherwise be reluctant to transact with anonymous suppliers.

Treasury said the platform had reportedly been used by North Korean hackers and by previously sanctioned organizations. Those included Jin Bei Group Co., Ltd. and entities belonging to the Prince Group transnational criminal organization.

USDT freezes strike at the marketplace’s payment model

Xinbi historically relied on Tether’s USDT stablecoin, primarily transferred over the TRON blockchain. That dependence created a critical enforcement point because Tether can centrally freeze tokens associated with designated addresses.

The freezing of $52.8 million demonstrates how blockchain transactions can remain technically transferable while the assets themselves are rendered unusable by their issuer. Blockchain analytics helped identify the relevant wallets, while Tether’s cooperation enabled the restrictions.

Xinbi administrators responded by announcing a transition to USDD, another dollar-pegged stablecoin operating on TRON. The marketplace reportedly exchanged approximately $2.8 million in remaining USDT for USDD through a decentralized exchange.

The move may make direct intervention more complicated, but it does not remove freeze exposure. USDD’s degree of decentralization is disputed, and part of its collateral reportedly consists of USDT that remains subject to Tether’s controls.

Xinbi’s administrators publicly criticized what they characterized as arbitrary freezes. They also acknowledged that unlocking substantial quantities of USDT and demonstrating compliance had become more difficult and time-consuming than expected.

The financial action therefore reaches beyond the restrained funds. Guarantee marketplaces depend on confidence that vendors will receive payment and that operators can withdraw balances. Once merchants know their wallets can be traced, sanctioned and frozen, the escrow service becomes less credible.

Xinbi grew after rival marketplaces collapsed

Xinbi expanded following the closures of HuiOne Guarantee and its successor, Tudou Guarantee, last year. HuiOne had handled approximately $31 billion in activity before Telegram shut it down under international pressure.

Criminal merchants subsequently migrated to Xinbi. Researchers had urged Telegram to take action against that marketplace as well, but additional intervention did not immediately follow.

Xinbi also recovered from an earlier Telegram disruption. Elliptic co-founder Dr. Tom Robinson said in January that the platform had resumed operations after Telegram intervened and that the messaging company declined to take further action, contributing to the growth of additional markets.

The latest channel seizures change that equation by combining platform disruption with sanctions and cryptocurrency freezes. Removing a Telegram channel alone may only prompt administrators to create a replacement. Restricting the marketplace’s financial infrastructure raises the cost of rebuilding.

Xinbi could still rebrand or relaunch, as HuiOne attempted through Tudou. Researchers nevertheless expect sanctions and damaged merchant confidence to make survival harder. Tudou itself did not remain active for long.

The United Kingdom had already sanctioned Xinbi in March, becoming the first country to designate it. The British action cited activities including the sale of stolen personal data and satellite internet equipment used to contact scam victims. The U.S. measures followed more than five months later.

Madagascar operation targets the physical scam compounds

The enforcement campaign was not confined to Telegram and cryptocurrency. The Scam Center Strike Force deployed personnel to Madagascar as it expanded its mandate to pursue scam compounds globally.

The operation helped disrupt 13 centers allegedly controlled by Chinese organized crime syndicates. Authorities seized more than 3,200 electronic devices and opened investigations using information obtained through interviews with nearly 400 arrestees.

Approximately 30 alleged Chinese leaders of the compounds were repatriated to China by the Chinese government. U.S. Attorney Jeanine Pirro separately described the rapid repatriation of dozens of alleged leaders as an interesting development.

Scam compounds are the operational layer behind many pig-butchering campaigns. Workers may be recruited under false pretenses or trafficked, then compelled to contact victims, develop relationships and steer them toward fraudulent financial platforms.

Xinbi’s vendor ecosystem supported that activity by connecting compound operators with payment services, data sellers, website developers and laundering providers. The Madagascar deployment targeted the people and equipment behind the scams, while the wallet freezes attacked their financial channels.

No patch exists for this threat

This is a law-enforcement and financial disruption, not a software vulnerability. There are no affected software versions, CVE identifiers, patches or workarounds.

Nor have authorities released victim-specific defensive instructions. Without wallet addresses, domains or account identifiers, companies cannot build precise detection rules from the public information alone.

The reported U.S. operation nevertheless establishes several pressure points: Telegram infrastructure can be seized under court authority, stablecoin balances can be frozen, and vendors can be sanctioned alongside the central marketplace.

The immediate impact is substantial but not necessarily permanent. Xinbi’s operators may move to new channels, adopt a different name or experiment with assets designed to resist centralized freezing.

Rebuilding trust will be the harder task. Merchants now know that apparently stable escrow balances can become inaccessible, while transactions can help investigators map a wider criminal network. For a marketplace built to solve trust problems among criminals, that uncertainty is a direct threat to its business model.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsXinbi Guaranteecrypto scamTether freezepig butcheringTelegram seizureOFAC sanctionsmoney launderingUSDT
Back to home