Back to Feed
Threat IntelligenceSep 9, 2026

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

US disrupts Xinbi Guarantee scam marketplace, freezing $52.8M in crypto.

Summary

The U.S. Department of Justice has dismantled the illicit online marketplace Xinbi Guarantee, which facilitated various scam services. Coordinated actions included seizing Telegram channels, confiscating cryptocurrency wallets holding $52.8 million in USDT, and disrupting scam compounds in Madagascar. The marketplace, a successor to previous illicit storefronts, acted as an intermediary for romance scams and money laundering, reportedly used by North Korean hackers and designated entities.

Full text

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto Ravie LakshmananSep 09, 2026Cybercrime / Cryptocurrency The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime syndicates. "Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million," DoJ said. In tandem, the Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned the Chinese-language media for facilitating cyber scams, fraud, money laundering, and other criminal activity targeting Americans. "Scam centers in Southeast Asia steal billions of dollars from American victims each year," said Secretary of the Treasury Scott Bessent in a statement. "The Trump Administration is united in its efforts to dismantle these overseas criminal enterprises, and [the] Treasury will continue using its tools to disrupt the networks behind this egregious fraud and protect Americans." Xinbi Guarantee is a Telegram-oriented marketplace that rose to prominence following the closure of two other similar storefronts, HuiOne Guarantee and its successor Tudou Guarantee, last year. Blockchain analytics firm Elliptic, which worked with the U.S. Secret Service to identify and freeze wallets holding $52.8 million in Tether's USDT stablecoin, said Xinbi is the second largest illicit marketplace of time, with $30 billion in transactions to date since its inception around 2022. Earlier this January, Elliptic's Founder and Chief Scientist, Dr. Tom Robinson, told The Hacker News that Xinbi Guarantee recovered following Telegram's intervention and has refused to take further actions, leading to the emergence of a number of markets on the messaging platform. Like HuiOne and Tudou, Xinbi acts as an intermediary between vendors and scam center operators running "pig butchering" romance scams, effectively turning it into a one-stop shop to peddle various services, such as creating custom scam investment websites, laundering funds scammers obtain from victims of wire fraud, and soliciting trafficking victims to work in scam compounds in Southeast Asia. "Once a scammer 'purchases' a service from the vendor, Xinbi as an organization holds money to be paid to the vendor until the vendor's services are complete, to assure the scammers that the vendors will perform the services," the DoJ said. "Xinbi Guarantee's platform has reportedly been used by North Korean hackers and by several OFAC-designated entities, including Jin Bei Group Co., Ltd. and entities that are part of the Prince Group TCO," the Treasury added. Besides dismantling the Telegram channels hosting the marketplace and banning the associated usernames, the Justice Department said the Scam Center Strike Force seized two cryptocurrency wallets Xinbi used to collect payments for vendors. The wallets are said to have held about $12 million in funds. In all, $52.8 million worth of cryptocurrency has been frozen from 52 wallets associated with Xinbi and its network of merchants that enabled the organized crime groups running scam centers worldwide. "After scamming money from hardworking Americans, criminals operating overseas laundered it through the Xinbi Guarantee network, which operated under the false assumption that they were out of the reach of U.S. law enforcement," Tara McLeese, Special Agent in Charge of the U.S. Secret Service Washington Field Office, said. Furthermore, the Justice Department announced that the Scam Center Strike Force will expand its scope to target scam center compounds globally going forward. This has resulted in the takedown of 13 scam centers in Madagascar. More than 3,200 electronic devices and investigations have been opened based on interviews with nearly 400 arrestees. Of these, roughly 30 are said to be Chinese leaders of the scam compounds who have been repatriated to China by the Chinese government. Historically, all payments on Xinbi have been made in Tether's USDT stablecoin, mainly on the TRON blockchain. Following the asset freeze, Xinbi has responded by switching to USDD ("Decentralized USD"), another stablecoin pegged to the U.S. Dollar. Xinbi is estimated to have exchanged approximately $2.8 million of its remaining USDT assets into USDD using a decentralized exchange. "Unlike USDT, which is issued by Tether and has a built-in feature that allows the company to freeze wallets, USDD has no central issuer or freezing capability," Dr. Robinson said. "However, its claims of decentralization are contested, and it is still exposed to freezing risk, since USDD is partly collateralized with freezable USDT." The latest development comes more than five months after the U.K. became the first country to sanction Xinbi for selling cryptocurrency-based services to scam centers, including "stolen personal data, which can be used to target scam victims, and satellite internet equipment, which is used to contact victims." Elliptic has described the latest actions as a "severe setback" to the Guarantee marketplace ecosystem as it undermines the trust that merchants and criminal users have in these marketplaces. "Merchants and users of these services will now be operating with the knowledge that their wallets may be identified and frozen at any time," it added. "This uncertainty undermines the core mechanism these marketplaces rely on to function." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cryptocurrency, Cybercrime, Fraud, law enforcement ⚡ Top Stories This Week Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain GeoNetwork Fixes Unauthenticated RCE Chain Affecting Governm

Indicators of Compromise

  • malware — pig butchering

Entities

Chinese organized crime (threat_actor)North Korean hackers (threat_actor)USDT (product)Telegram (product)Xinbi Guarantee (vendor)Jin Bei Group Co., Ltd. (vendor)