
The U.S. Secret Service froze $52.8 million in cryptocurrency tied to Xinbi Guarantee, a Telegram-based illicit marketplace, on September 8, working with Elliptic to identify wallets holding USDT; two wallets with ~$12 million were seized under a DOJ warrant, while Xinbi has processed at least $24 billion in transactions since 2022, making it the second-largest tracked illicit marketplace after Huione Guarantee.
AI-generated summary
Xinbi Guarantee operates as a Telegram-based escrow system for illicit transactions, including stolen data and money-laundering services, building on the trajectory of predecessors like Huione Guarantee. It relies on trust mechanisms among criminals, using crypto deposits to ensure transaction integrity in scam ecosystems such as pig butchering.
The U.S. Secret Service froze $52.8 million in cryptocurrency linked to Xinbi Guarantee on September 8, a Chinese-language marketplace that runs on Telegram and sells the tools scammers need to defraud people worldwide.
The government agents worked with Blockchain analytics firm Elliptic to identify and freeze the funds. “Elliptic has been tracking Xinbi and its wallet infrastructure for several years, and our intelligence directly enabled the freezing action, as well as the sanctions imposed on Xinbi today by the United States,” the company said today in a statement.
Fifty-two wallets were frozen beginning at 8am UTC on Sept 8, all holding USDT, Tether's dollar-pegged stablecoin. Two of those wallets, containing roughly $12 million, were seized outright under a warrant unsealed today by the Department of Justice. The rest were frozen pending further action.
A guarantee marketplace runs on trust between criminals, and crypto is a very popular payment method. Xinbi isn't a marketplace in the normal sense but more an escrow system where vendors post crypto deposits so operators trust they'll get what they paid for, from stolen personal data to the money-laundering services that turn stolen funds back into cash.
Buyers who feel cheated can be reimbursed from that deposit, which is the entire reason criminals use it instead of just trusting each other.
Since 2022, Xinbi and its merchants have processed at least $24 billion in transactions, according to Elliptic, making it the second-largest illicit online marketplace ever tracked. Only Huione Guarantee moved more, processing $31 billion before Telegram shut it down in May 2025 after years of exposure by Elliptic.
That came days after a separate Treasury finding that Huione's parent group was a primary money laundering concern. Xinbi absorbed much of that traffic once its predecessor vanished.
Much of the money that flows through platforms like this starts with "pig butchering," a scam where a stranger builds a fake romance or friendship online for weeks or months, then convinces the victim to pour savings into a bogus investment app that shows fabricated profits until the account is drained.
Treasury's Office of Foreign Assets Control—the Treasury unit that blocks assets tied to national security and crime threats—designated Xinbi as a transnational criminal organization on September 9, the same category used for drug cartels. Two more firms, Singapore-based SafeW Technology and Cambodia-based Anwen Technology, were sanctioned alongside it for supporting Xinbi's operations. The UK had already sanctioned Xinbi in March.
Xinbi didn't take the crypto freeze quietly. The marketplace posted a statement condemning the "arbitrary freezing" of its funds and promised to compensate its customers.
Xinbi seems to be shifting away from USDT toward USDD, a stablecoin launched by Tron founder Justin Sun that has no central issuer able to freeze wallets. It has already swapped about $2.8 million of its remaining USDT into USDD through a decentralized exchange.
There's just one problem. USDD markets itself as decentralized, but part of its own reserves are backed by USDT—the very asset with the freeze switch Xinbi is trying to escape.
Wednesday's action was part of a bigger day for the DOJ's Scam Center Strike Force, which also deployed agents to Madagascar to help local authorities take down 13 Chinese-run scam compounds and process evidence from nearly 400 arrestees, including more than 3,200 seized devices.
The Strike Force, launched in November 2025, has seized roughly $938 million in scam-linked cryptocurrency since it began operating—and Xinbi's outstanding balance is still on the board.
AI outlook — possibilities, not facts
Xinbi Guarantee will face additional wallet freezes or seizures as law enforcement traces its shift to USDD and other alternative cryptocurrencies.
Likely · Within weeks
The DOJ's Scam Center Strike Force will continue operations in Southeast Asia and Africa to dismantle scam compounds similar to those in Madagascar.
Very likely · Within months

Mexican authorities arrested two men for the murders of Camilo Séptimo keyboardist Jonathan Meléndez, his wife, daughter, and domestic worker in Atizapán de Zaragoza. The suspects allegedly sought a cold wallet containing Bitcoin, marking a rise in physical crypto-related attacks.

Britain's National Economic Crime Centre (NECC) has elevated crypto assets to its third-highest economic crime priority. The agency is shifting toward proactive, intelligence-led operations to combat money laundering networks utilizing crypto and AI.

Singaporean national Malone Lam pleaded guilty to participating in a racketeering conspiracy that used social engineering and home break-ins to steal and launder over $245 million in cryptocurrency. The operation, formed through online gaming platforms, ran from October 2023 to at least May 2025. Lam admitted guilt before a US federal judge for one count of RICO conspiracy, nearly two years after being charged in the theft of 4,100 Bitcoin from a Washington, DC resident.

Malone Lam, a 22-year-old Singaporean, is scheduled for a plea agreement hearing in federal court in Washington on Tuesday. Prosecutors allege he organized a racketeering group that stole over $245 million in Bitcoin from a single investor through social engineering scams impersonating Google and Gemini staff, burglarized homes to steal hardware wallets, laundered funds via Monero and peel chains, and spent millions on luxury items while continuing fraud operations from Dubai.

Ireland's Criminal Assets Bureau reports organized crime gangs are renting vaults to store cryptocurrency wallet seed phrases and private keys alongside cash, luxury watches, and passports. The bureau has shared this finding with the government committee preparing for new EU anti-money laundering rules, noting that while crypto use by criminals is growing, it remains 'still quite basic' and cash dominates dirty money transactions in Ireland.

The exploiter behind the Coldcard wallet hack has moved 45% of their stolen Bitcoin through THORChain and CoinJoin. Galaxy Research reports that 18% of total stolen funds across all waves have been moved, while 82% remain in attacker-controlled addresses.