US Disrupts Xinbi Guarantee Scam Market, Freezes $52.8M in Crypto
The U.S. Department of Justice announced coordinated actions on Wednesday targeting Xinbi Guarantee, a Telegram-based illicit marketplace that facilitated pig butchering romance scams, investment fraud, and money laundering on an industrial scale. Federal authorities seized the platform's Telegram channels, confiscated two cryptocurrency wallets, and deployed the Scam Center Strike Force to Madagascar to help dismantle 13 scam compounds operated by Chinese organized crime syndicates. In a single day, approximately $52 million in cryptocurrency tied to scam money laundering was restrained, bringing the Strike Force's total recoveries to roughly $938 million, according to the DoJ.
In parallel, the Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned a Chinese-language media organization for facilitating cyber scams, fraud, and money laundering targeting American victims. "Scam centers in Southeast Asia steal billions of dollars from American victims each year," Treasury Secretary Scott Bessent stated, adding that the Trump Administration is "united in its efforts to dismantle these overseas criminal enterprises." Blockchain analytics firm Elliptic worked alongside the U.S. Secret Service to identify and freeze wallets holding $52.8 million in Tether (USDT), describing Xinbi Guarantee as the second-largest illicit marketplace of its kind, with roughly $30 billion in cumulative transactions since its launch around 2022.
Xinbi Guarantee emerged as a successor to HuiOne Guarantee and Tudou Guarantee, which were shut down last year, and continued to thrive despite Telegram's prior interventions. The platform functioned as an escrow-based intermediary between vendors and scam compound operators, offering services ranging from custom-built fraudulent investment websites and fund-laundering pipelines to the trafficking of workers into Southeast Asian scam compounds. The DoJ noted that Xinbi's escrow model held payments until vendors delivered promised services, providing trust assurance within the criminal ecosystem. According to OFAC, the platform has also been used by North Korean hackers and several OFAC-designated entities, including Jin Bei Group Co., Ltd. and members of the Prince Group transnational criminal organization.
For individuals concerned about exposure to these fraud networks, security professionals recommend verifying whether personal information has surfaced in known compromises using an email breach checker, and investigating suspicious investment platform domains through a WHOIS lookup to identify recently registered or concealed registrations commonly associated with scam infrastructure. Operators of legitimate crypto services should also run a SSL/TLS checker to confirm their platforms are not being impersonated by lookalike phishing domains tied to these syndicates.