In a decisive move against the infrastructure of global cybercrime, the United States Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced comprehensive sanctions on September 9, 2026, against Xinbi Guarantee. Identified as a cornerstone of the Chinese-language illicit finance ecosystem, Xinbi Guarantee has allegedly facilitated the laundering of over $24 billion in digital and fiat assets since its inception in 2022. The coordinated action, which included the Department of Justice (DOJ) and international partners in the United Kingdom, targets a sprawling network that provided the financial backbone for North Korean state-sponsored hackers, Southeast Asian scam compounds, and transnational organized crime syndicates.
The designation of Xinbi Guarantee is aimed at disrupting a critical node in the "scam-as-a-service" economy. According to federal authorities, the platform did not merely facilitate transactions but acted as a trusted intermediary for criminal vendors offering a menu of illicit services, ranging from money laundering and stolen personal data to the recruitment of individuals for forced labor in cyber-fraud centers.
The Rise of the Xinbi Ecosystem
Xinbi Guarantee emerged around 2022, rapidly scaling to become one of the most significant "guarantee" platforms in the darknet and gray-market spheres. Operating primarily through hundreds of Chinese-language channels on the messaging app Telegram, Xinbi functioned as an escrow service. This model allowed disparate criminal actors—who often had no prior relationship—to transact with a degree of enforced trust. The platform held deposits from vendors and managed payments, ensuring that "services" like money laundering or the delivery of stolen data were completed before funds were released.
The scale of Xinbi’s operations reflects a significant shift in the landscape of illicit finance. Treasury officials noted that Chinese-language money laundering services now dominate known cryptocurrency-related illicit activity. Recent data suggests these services have processed approximately 20% of all illicit crypto funds over the past five years. In 2025 alone, this sector was estimated to have handled $16 billion. Xinbi sat at the heart of this trend, providing the necessary liquidity and anonymity for actors to move billions across international borders.
The services advertised within the Xinbi network were comprehensive. Investigators identified vendors offering:
- "Black U" Laundering: Specialized services to swap "tainted" or traceable cryptocurrency for "clean" stablecoins.
- KYC Bypass and Fraudulent Identity Documents: Tools used to open accounts on legitimate exchanges under false pretenses.
- Stolen Personal Information: Databases of consumer data used for targeting victims in financial scams.
- Malware and Scam Infrastructure: Custom-built websites and software designed for "pig butchering" and romance scams.
- Forced Labor Recruitment: Advertisements for staff to be deployed in Southeast Asian scam compounds, often under conditions involving human trafficking and physical abuse.
North Korean Exploitation and the "Black U" Mechanism
Perhaps the most alarming aspect of the Xinbi investigation is the platform’s role in facilitating the financial goals of the Democratic People’s Republic of Korea (DPRK). Analysis of on-chain data revealed that threat actors linked to North Korea moved tens of millions of dollars in stolen funds through Xinbi’s vendor network. These funds originated from some of the most high-profile cryptocurrency thefts in history, including the $1.5 billion breach of the Bybit exchange and the $235 million theft from WazirX.

The laundering process employed by DPRK-linked actors through Xinbi is characterized by "substitution" rather than traditional "obfuscation." In this model, North Korean hackers provide specialized vendors—often referred to in the ecosystem as "Black U" launderers—with highly traceable, stolen cryptocurrency. In exchange, these vendors provide the hackers with stablecoins (typically USDT) sourced from entirely different illicit revenue streams, such as the proceeds from "pig butchering" scams or retail fraud.
By swapping stolen assets for scam proceeds, the DPRK-linked funds are effectively blended into a massive, global pool of illicit activity. This makes it significantly more difficult for blockchain investigators to pin specific wallets to the original state-sponsored hack. Once the hackers receive these nominally "cleaner" stablecoins, they can more easily exit into fiat currency through unlicensed over-the-counter (OTC) desks or sympathetic exchanges.
Coordinated Law Enforcement and Asset Seizures
The sanctions against Xinbi Guarantee were part of a multi-pronged offensive by U.S. and international law enforcement. On September 7, 2026, just days prior to the OFAC announcement, a federal court authorized the Justice Department’s Scam Center Strike Force (SCSF) to seize the Telegram channels hosting the Xinbi marketplace. This move effectively decapitated the platform’s primary communication and operational infrastructure.
In tandem with the digital seizure, the SCSF moved against the platform’s financial assets. Authorities seized two primary cryptocurrency wallets used by Xinbi to collect vendor deposits, which contained approximately $12 million. Furthermore, the court authorized the restraint of an additional 47 wallets believed to be associated with the network’s top-tier vendors. In total, the coordinated actions resulted in the freezing or seizure of more than $52 million in cryptocurrency.
OFAC’s designation also extended to the technical architects of the Xinbi ecosystem. Two technology firms, SafeW Technology and Anwen Technology, were sanctioned for their roles in developing the messaging and crypto-payment applications that underpinned Xinbi’s daily operations. These firms provided the bespoke tools that allowed criminal vendors to manage their illicit inventories and process payments away from the scrutiny of traditional financial regulators.
The 52 specific cryptocurrency addresses designated by OFAC in this action were found to have received a staggering $8.4 billion in stablecoins over their operational lifespan, highlighting the immense volume of capital flowing through these illicit pipelines.
The Human Rights Connection and Global Response
The crackdown on Xinbi is not merely a financial enforcement action but a response to grave human rights violations. The UK’s Foreign, Commonwealth & Development Office (FCDO) had previously sanctioned Xinbi in March 2026 under its Global Human Rights sanctions regime. This was due to the platform’s documented role in supporting Southeast Asian scam centers, where thousands of individuals are reportedly held in conditions of forced labor, debt bondage, and torture.

These scam compounds, often located in special economic zones in countries like Myanmar, Laos, and Cambodia, rely on marketplaces like Xinbi to acquire the technical tools and financial services necessary to operate. By facilitating the sale of "recruitment" services and the laundering of scam proceeds, Xinbi was deemed a primary enabler of modern slavery.
In conjunction with the U.S. action on September 9, the UK government updated its own sanctions list to include dozens of additional cryptocurrency addresses identified in the most recent investigation. This level of transatlantic cooperation signals a growing consensus among Western powers that cryptocurrency-enabled crime and human rights abuses must be tackled through synchronized, borderless enforcement.
Timeline of the Crackdown
The dismantling of Xinbi Guarantee is the result of a multi-year investigative effort:
- Early 2022: Xinbi Guarantee begins operations as an escrow service for Chinese-language criminal vendors.
- 2023-2025: The platform scales rapidly, becoming a primary conduit for DPRK stolen funds and Southeast Asian scam proceeds.
- March 2026: The UK’s FCDO issues the first major sanctions against Xinbi, citing human rights abuses.
- April 2026: Global blockchain analytics firms report a massive surge in "pig butchering" revenue flowing through guarantee platforms.
- September 7, 2026: U.S. federal courts authorize the seizure of Xinbi’s Telegram infrastructure.
- September 9, 2026: OFAC officially sanctions Xinbi Guarantee, SafeW Technology, and Anwen Technology. DOJ announces the restraint of $52 million in assets.
Implications for the Crypto Industry
The fall of Xinbi Guarantee sends a powerful message to the cryptocurrency industry and the broader financial sector. It underscores the reality that stablecoins, while offering efficiency for legitimate commerce, have become the preferred currency for transnational crime. The involvement of Tether in providing assistance to law enforcement during this investigation further illustrates the increasing pressure on stablecoin issuers to monitor their networks and cooperate with authorities.
For financial institutions and virtual asset service providers (VASPs), the Xinbi case highlights the necessity of sophisticated blockchain monitoring. Traditional "know your customer" (KYC) protocols are often insufficient when dealing with professional laundering networks that use substitution methods to mask the origin of funds.
The action also marks a strategic shift in how the U.S. government views the "infrastructure" of cybercrime. By targeting the guarantee platforms and the software developers who build the tools, rather than just the individual hackers or scammers, authorities are attempting to increase the "cost of doing business" for criminal syndicates. If the platforms that provide trust and liquidity are removed, the entire ecosystem of decentralized, anonymous crime becomes significantly more fragile.
As the investigation continues, authorities expect to identify further downstream beneficiaries of the Xinbi network. While the seizure of $52 million is a significant blow, it represents only a fraction of the $24 billion that passed through the platform. The challenge for global regulators remains the speed at which new "guarantee" platforms can emerge to fill the vacuum left by Xinbi’s demise. However, the precedent set by this coordinated international strike suggests that the shadows in which these marketplaces operate are becoming increasingly illuminated by the light of global law enforcement.















