U.S. Department of Justice and Treasury Crack Down on Xinbi Guarantee, Disrupting Global Cyber Scam Networks

The global infrastructure supporting high-tech financial fraud suffered a severe blow this week as United States law enforcement and financial regulators launched a synchronized, multi-pronged offensive against Xinbi Guarantee, one of the world’s largest illicit online marketplaces. Operating primarily through the Telegram messaging app, Xinbi served as a critical nexus for organized crime syndicates, facilitating everything from money laundering and custom website development for "pig butchering" scams to human trafficking operations in Southeast Asia.
In a coordinated announcement on Wednesday, the U.S. Department of Justice (DoJ) and the Treasury Department detailed sweeping punitive measures. These actions included the seizure of critical Telegram channels and associated usernames, the confiscation of illicit cryptocurrency wallets holding millions in stolen funds, and the deployment of the specialized Scam Center Strike Force to foreign soil. The operation underscores a rapidly escalating international campaign to dismantle the institutionalized web of cybercrime networks that siphon billions of dollars from American citizens annually.
A Coordinated Global Strike: Seizures and Sanctions
The crackdown on Xinbi Guarantee involved intense cross-agency collaboration and international partnerships. According to the DoJ, law enforcement actions successfully restrained approximately $52 million in cryptocurrency linked to scam money laundering in a single day. This latest seizure elevates the total amount of funds restrained by the federal Scam Center Strike Force to an estimated $938 million.
Simultaneously, the Treasury Department’s Office of Foreign Assets Control (OFAC) levied formal sanctions against Chinese-language media networks and entities found to be actively facilitating cyber scams, fraud, and financial crimes targeting U.S. residents.

"Scam centers in Southeast Asia steal billions of dollars from American victims each year," said Secretary of the Treasury Scott Bessent in an official statement. "The Administration is united in its efforts to dismantle these overseas criminal enterprises, and the Treasury will continue using its tools to disrupt the networks behind this egregious fraud and protect Americans."
Working in tandem with blockchain intelligence firms such as Elliptic and federal law enforcement bodies like the U.S. Secret Service, authorities froze roughly $52.8 million worth of digital assets across 52 individual wallets linked to Xinbi and its expansive merchant ecosystem. Tara McLeese, Special Agent in Charge of the U.S. Secret Service Washington Field Office, emphasized the message sent to overseas actors: "After scamming money from hardworking Americans, criminals operating overseas laundered it through the Xinbi Guarantee network, which operated under the false assumption that they were out of the reach of U.S. law enforcement."
Rise of the Guarantee Model: From HuiOne to Xinbi
To fully understand the significance of the Xinbi takedown, analysts point to the evolution of the "Guarantee" marketplace ecosystem. Xinbi rose to prominence following the high-profile closures of two analogous storefronts last year: HuiOne Guarantee and its direct successor, Tudou Guarantee.
Blockchain analytics firm Elliptic estimates that since its inception around 2022, Xinbi has processed an astonishing $30 billion in transactions, making it the second-largest illicit marketplace of its kind in history. These platforms function as sophisticated escrow services or "one-stop shops" for transnational criminal syndicates. When a cybercriminal group running romance scams or investment frauds requires infrastructure—such as custom-coded fraudulent trading platforms, bulk personal data for victim targeting, or professional money-laundering services—they contract vendors through platforms like Xinbi.
The platform’s core utility lies in its escrow mechanism. Xinbi holds the buyers’ funds until the contracted cybercrime services are successfully delivered, providing a layer of commercial trust among otherwise anonymous and cutthroat criminal elements.

Dr. Tom Robinson, Founder and Chief Scientist at Elliptic, noted earlier this year that Xinbi managed to bounce back following past pressure from Telegram and regulatory bodies, stubbornly refusing to self-police. Over time, its reach expanded significantly; the U.S. Treasury reported that Xinbi’s platform has been utilized by North Korean state-sponsored hackers as well as several entities previously designated by OFAC, including the Jin Bei Group Co., Ltd. and networks associated with the Prince Group Transnational Criminal Organization (TCO).
Expanding the Battlefield: The Madagascar Raids
Beyond digital asset seizures and the dismantlement of Telegram communication channels, the DoJ announced that the Scam Center Strike Force is aggressively expanding its geographic reach. In a striking cross-continental operation, the strike force deployed personnel to Madagascar to dismantle 13 physical scam compounds operated by Chinese organized crime syndicates.
The raid in Madagascar yielded a massive evidentiary haul, including the seizure of more than 3,200 electronic devices. Investigators have initiated formal inquiries based on extensive interviews with nearly 400 detained individuals. Among those arrested, approximately 30 are identified as high-ranking Chinese leaders of the overseas compounds. Through cooperative international arrangements, these key figures have already been repatriated to China to face further legal proceedings.
This physical intervention highlights a grim reality of modern cybercrime: the digital theft of American retirement savings and life savings is inextricably linked to brutal human trafficking operations on the ground. Workers lured to compounds in Southeast Asia and parts of Africa with false promises of legitimate employment are frequently trapped, coerced, and subjected to forced labor under threat of violence to execute daily "pig butchering" scams.
The Crypto Pivot: Shifting from USDT to USDD
Faced with relentless law enforcement pressure and the vulnerability of centralized stablecoin freezing mechanisms, illicit actors are already attempting to adapt. Historically, transactions within the Xinbi ecosystem relied almost exclusively on Tether’s USDT stablecoin, predominantly operating on the TRON blockchain. Because Tether maintains the technological capability to blacklist and freeze wallets upon law enforcement request, platforms like Xinbi suffered massive liquidity disruptions during the recent asset seizures.

In response to the multi-million-dollar asset freeze, Xinbi reportedly pivoted toward alternative digital assets. Blockchain monitors observed the marketplace exchanging approximately $2.8 million of its remaining USDT assets into USDD ("Decentralized USD"), another U.S. dollar-pegged stablecoin, via decentralized exchanges.
Experts, however, caution that this maneuver offers only a temporary or illusory shield. Dr. Robinson of Elliptic explained the technical limitations of the criminals’ new strategy: "Unlike USDT, which is issued by Tether and has a built-in feature that allows the company to freeze wallets, USDD has no central issuer or freezing capability. However, its claims of decentralization are contested, and it is still exposed to freezing risk, since USDD is partly collateralized with freezable USDT."
Broader Implications and International Pressures
The concerted takedown of Xinbi Guarantee marks a notable escalation in the global regulatory and enforcement posture against cyber-enabled financial crime. The United Kingdom previously made waves by becoming the first nation to formally sanction Xinbi for peddling stolen personal data and satellite internet hardware to scam compounds. With the United States now pairing financial sanctions with aggressive law enforcement seizures and physical compound raids, the operational landscape for cybercriminal syndicates is tightening dramatically.
Cybersecurity and financial compliance experts view these coordinated interventions as a severe structural setback for the Guarantee marketplace model as a whole. By repeatedly freezing funds and disrupting escrow operations, international law enforcement is systematically eroding the foundational trust required for these criminal marketplaces to operate profitably.
As merchants and scammers alike realize that their digital wallets can be identified, tracked, and frozen at any moment, the perceived safety of operating via encrypted messaging apps is rapidly evaporating. While transnational syndicates will undoubtedly attempt to mutate or migrate their infrastructure to new platforms, the systematic dismantling of Xinbi Guarantee demonstrates that global authorities are increasingly equipped to strike at the financial lifeblood of industrial-scale cyber fraud.







