U.S. Department of Justice and Treasury Crack Down on Xinbi Guarantee, Disrupting Global Cyber Scam Network and Seizing Millions in Crypto

In a sweeping international law enforcement operation, the United States Department of Justice (DoJ) and the Department of the Treasury have executed a coordinated series of actions targeting Xinbi Guarantee, a massive illicit online marketplace operating primarily on Telegram. The crackdown resulted in the seizure of core Telegram channels, the confiscation of millions in cryptocurrency, and a high-profile physical intervention by the newly formed Scam Center Strike Force in Madagascar. These measures highlight an escalating global offensive against transnational organized crime syndicates that traffic humans, perpetrate devastating "pig butchering" romance scams, and launder billions of dollars extracted primarily from American victims.
The scale of the operation underscores the immense financial and societal toll exacted by Southeast Asian cyber-fraud compounds. According to statements released by federal authorities, approximately $52 million in cryptocurrency linked to scam money laundering was restrained in a single day, elevating the total amount frozen by the Scam Center Strike Force to an estimated $938 million. Concurrently, the Treasury Department’s Office of Foreign Assets Control (OFAC) instituted formal sanctions against Chinese-language media networks and associated entities accused of facilitating these cyber frauds, money laundering operations, and human trafficking rings.
The Anatomy of Xinbi Guarantee and the Guarantee Marketplace Ecosystem
Xinbi Guarantee rose to prominence as a vital financial intermediary and service bazaar for cybercriminals following the high-profile closures of similar underground storefronts, most notably HuiOne Guarantee and Tudou Guarantee, which collapsed under regulatory and platform pressures in previous years. Operating as an escrow-style marketplace on Telegram, Xinbi functioned as a one-stop shop for individuals and syndicates running romance scams, wire fraud schemes, and large-scale investment scams.
The marketplace did not execute scams directly; instead, it provided the vital infrastructure required for criminal enterprises to scale. Vendors within the Xinbi network peddled a wide array of illicit services, including the development of custom-built, highly convincing fraudulent investment platforms, the acquisition of stolen personal data for targeted phishing, the procurement of satellite internet equipment, and the recruitment or trafficking of forced labor to staff infamous scam compounds across Southeast Asia.
To establish trust between anonymous vendors and cybercriminal syndicate operators, Xinbi utilized an escrow mechanism. When a scammer purchased a service, Xinbi held the funds in reserve, only releasing payment to the vendor upon completion of the contract. This structural reliability made Xinbi the second-largest illicit marketplace of its kind in history, facilitating an estimated $30 billion in transactions since its inception around 2022. Blockchain analytics firm Elliptic confirmed that the platform’s volume and systemic integration into the criminal underworld made it a linchpin for global financial crime, with deep ties to North Korean state-sponsored hackers and OFAC-designated entities such as the Jin Bei Group and the Prince Group Transnational Criminal Organization (TCO).

Chronology of Regulatory Pressure and Law Enforcement Escalation
The dismantling of Xinbi Guarantee represents the culmination of years of intelligence gathering and international cooperation between blockchain analytics firms, foreign governments, and U.S. federal agencies.
The crackdown builds upon a steady accumulation of pressure that began to mount internationally in early 2025, when predecessors like HuiOne and Tudou faced severe disruptions. Following those closures, Xinbi managed to absorb displaced criminal traffic, aggressively expanding its operations even after initial interventions by Telegram’s moderation teams.
By March 2026, the United Kingdom took pioneering legislative steps, becoming the first nation to formally sanction Xinbi Guarantee for providing cryptographic and logistical services to scam centers. This set the stage for deeper multinational actions. In January 2026, industry experts, including Dr. Tom Robinson, Founder and Chief Scientist at Elliptic, noted that Xinbi had demonstrated resilience by adapting to platform moderation, prompting calls for more aggressive asset-level interventions.
The decisive blow arrived on a Wednesday in mid-2026, when U.S. authorities launched their synchronized multi-agency offensive. Working in tandem with the U.S. Secret Service, investigators identified and froze 52 cryptocurrency wallets holding approximately $52.8 million in Tether’s USDT stablecoin. Simultaneously, the Scam Center Strike Force was deployed beyond the digital sphere, executing physical raids on the ground in Madagascar.
Global Reach: The Madagascar Raids and Transnational Dimensions
While the freezing of cryptocurrency assets and the seizure of Telegram channels—including the ban of associated usernames via Fragment—dealt a heavy electronic blow to Xinbi, the physical enforcement actions marked a new strategic phase for the U.S. Scam Center Strike Force. Expanding its operational scope globally, the Strike Force assisted local authorities in Madagascar to dismantle 13 physical scam compounds operated by Chinese organized crime syndicates.

The raid yielded over 3,200 electronic devices and triggered formal investigations based on extensive interviews with nearly 400 individuals detained at the sites. Notably, approximately 30 of those detained were identified as high-ranking Chinese leaders of the scam compounds. In a demonstration of cross-border cooperation, these key figures were swiftly repatriated to China by local and international authorities to face criminal prosecution.
Official Reactions and Policy Implications
The coordinated intervention has drawn strong praise from high-ranking U.S. officials, who framed the enforcement actions as a vital national security imperative aimed at defending American citizens from financial ruin.
"Scam centers in Southeast Asia steal billions of dollars from American victims each year," said U.S. Treasury Secretary Scott Bessent in an official statement. "The Trump Administration is united in its efforts to dismantle these overseas criminal enterprises, and [the] Treasury will continue using its tools to disrupt the networks behind this egregious fraud and protect Americans."
Law enforcement agencies emphasized that cybercriminals operating from distant jurisdictions can no longer assume they are beyond the reach of international justice. Tara McLeese, Special Agent in Charge of the U.S. Secret Service Washington Field Office, noted that perpetrators who believed their use of decentralized networks shielded them from accountability drastically underestimated the capabilities of modern blockchain forensics and multi-agency cooperation.
Evasion Tactics and the Shift to Alternative Stablecoins
Faced with the sudden freezing of tens of millions of dollars in USDT assets—which feature built-in smart contract capabilities allowing issuers to blacklist and freeze funds—Xinbi Guarantee attempted an immediate tactical pivot.

Blockchain intelligence indicates that following the asset freeze, Xinbi’s operators directed the exchange of approximately $2.8 million of their remaining USDT reserves into USDD ("Decentralized USD"), an alternative stablecoin pegged to the U.S. dollar, utilizing decentralized exchanges to bypass centralized controls.
Experts have pointed out the inherent limitations and risks of this pivot. Unlike USDT, which is issued by a centralized entity (Tether) capable of direct freezes, USDD operates without a single central issuer. However, industry analysts remain skeptical about its true decentralization. Because USDD is partially collateralized by freezable assets like USDT, it remains fundamentally vulnerable to systemic risks and potential asset tracking by blockchain investigators. Furthermore, the chaotic transition signals panic within the marketplace’s administration, eroding the confidence of its criminal user base.
Broader Impact on the Cybercrime Economy
Cybersecurity and intelligence firms have hailed the multi-pronged takedown as a profound structural setback for the digital guarantee marketplace ecosystem. For years, these platforms relied on an unwritten social contract of absolute anonymity and guaranteed escrow security to facilitate illicit trade.
By demonstrating that law enforcement can systematically identify, infiltrate, and freeze assets across multiple blockchain networks while simultaneously uprooting physical compounds thousands of miles away, authorities have injected severe uncertainty into the criminal underworld. Merchants and scam operators now operate under the constant threat that their cryptographic wallets can be exposed and liquidated at any moment.
As regulatory bodies, intelligence agencies, and blockchain analytics firms continue to tighten the net, the traditional impunity enjoyed by decentralized scam facilitators is rapidly evaporating, signaling a transformative shift in the ongoing global campaign against cyber-enabled financial crime.





