In a decisive move aimed at crippling the financial infrastructure of international cybercrime, the United States Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced comprehensive sanctions on September 9, 2026, against Xinbi Guarantee. Identified as a premier Chinese-language illicit marketplace, Xinbi Guarantee has functioned as a central clearinghouse for money laundering, cyber-scam infrastructure, and the movement of billions of dollars in stolen cryptocurrency. The designation marks one of the most significant strikes against the "scam economy" of Southeast Asia, which has increasingly relied on digital assets to facilitate transnational organized crime and human rights abuses.
According to Treasury officials, Xinbi Guarantee has processed more than $24 billion in digital assets and fiat currency since its emergence in 2022. The platform did not merely exist as a passive exchange but served as a critical intermediary, offering an escrow-based "guarantee" service that allowed disparate criminal groups—ranging from North Korean state-sponsored hackers to human traffickers operating scam compounds—to transact with a degree of enforced trust. The sanctions also targeted associated entities SafeW Technology and Anwen Technology, developers of the messaging and payment applications that underpinned Xinbi’s day-to-day operations.
The Architecture of a Shadow Financial Empire
Xinbi Guarantee’s rise is emblematic of a broader shift in the landscape of global illicit finance. As traditional banking systems have bolstered their Anti-Money Laundering (AML) and Know Your Customer (KYC) protocols, criminal enterprises have migrated to specialized "guarantee" platforms. These platforms operate primarily through encrypted messaging apps like Telegram, where they host hundreds of channels dedicated to specific illicit services.
The marketplace’s primary value proposition was its escrow model. In an environment where "honor among thieves" is non-existent, Xinbi acted as a neutral third party, holding vendor deposits and managing payments to ensure that services were delivered and funds were paid out. This systemic reliability allowed the marketplace to scale rapidly, eventually becoming a cornerstone of the Southeast Asian scam industry.
Investigation into Xinbi’s vendor network revealed a sprawling ecosystem of criminal-enabling services. These included:
- KYC Bypass and Identity Theft: Vendors provided fraudulent bank cards, stolen personal data, and services designed to circumvent the identity verification processes of legitimate cryptocurrency exchanges.
- Scam-as-a-Service: The marketplace facilitated the sale of custom-built "pig butchering" (romance scam) websites, malware, and surveillance equipment.
- Logistical Support: Recruitment services for scam compounds were advertised, alongside cash delivery networks and money laundering "mules" who helped bridge the gap between digital assets and fiat currency.
The North Korean Nexus: Laundering Stolen Millions
Perhaps the most alarming aspect of Xinbi’s operations was its utility to the Democratic People’s Republic of Korea (DPRK). For years, North Korean-linked threat actors, such as the Lazarus Group, have targeted the decentralized finance (DeFi) sector to fund the regime’s weapons programs. Analysis of on-chain data indicates that these actors moved tens of millions of dollars in stolen funds through Xinbi’s network.

Notably, Xinbi provided a venue for laundering the proceeds of massive exploits, including the $1.5 billion breach of the Bybit exchange and the $235 million theft from WazirX. The laundering method employed was a sophisticated "substitution" strategy rather than simple obfuscation. Specialized vendors, known in the underworld as "Black U" (Black USDT) launderers, would accept the highly traceable, "tainted" cryptocurrency stolen by the North Koreans. In exchange, these vendors would provide "cleaner" stablecoins sourced from other illicit activities, such as the proceeds of romance scams or illegal gambling.
By swapping stolen funds for scam proceeds, the DPRK-linked actors were able to blend their loot into a much larger, more diverse pool of illicit activity. This made it significantly more difficult for blockchain investigators to trace the funds to their final off-ramps, where the assets were eventually converted into fiat currency through unlicensed over-the-counter (OTC) desks.
Coordinated Law Enforcement Action and Asset Seizures
The sanctions by OFAC were part of a multi-pronged offensive involving the U.S. Department of Justice (DOJ) and international partners. The DOJ’s Scam Center Strike Force (SCSF) executed a series of seizures that directly hit Xinbi’s liquidity. On September 7, 2026, just days before the official sanction announcement, a federal court authorized the seizure of Telegram channels hosting the marketplace.
Simultaneously, the SCSF seized two primary wallets used by Xinbi to collect vendor payments, which contained approximately $12 million in cryptocurrency. Authorities also moved to restrain an additional 47 cryptocurrency wallets associated with the network. In total, the coordinated action resulted in the freezing or restraining of over $52 million in digital assets.
The investigation was further supported by the private sector. Tether, the issuer of the world’s most widely used stablecoin (USDT), reportedly provided technical assistance to law enforcement, helping to identify and freeze addresses linked to the Xinbi ecosystem. This collaboration underscores a growing trend of public-private partnerships aimed at maintaining the integrity of the digital asset space.
Timeline of the Crackdown on Xinbi Guarantee
The downfall of Xinbi Guarantee was the result of a multi-year international effort to map the "scam-industrial complex" of Southeast Asia.
- Early 2022: Xinbi Guarantee emerges as a niche Chinese-language marketplace on Telegram, focusing on escrow services for small-scale crypto traders.
- 2023 – 2024: The platform experiences exponential growth, coinciding with the rise of "pig butchering" scams. It becomes a primary hub for vendors providing infrastructure to scam compounds in Myanmar, Laos, and Cambodia.
- March 2026: The United Kingdom’s Foreign, Commonwealth & Development Office (FCDO) becomes the first major regulatory body to sanction Xinbi. The UK cited the platform’s connection to grave human rights abuses, including forced labor and torture within the scam compounds it supported.
- July 2026: Blockchain analytics firms identify significant overlaps between the wallets used in the Bybit and WazirX hacks and the Xinbi vendor network.
- September 7, 2026: The U.S. Scam Center Strike Force (SCSF) obtains warrants to seize Xinbi’s online infrastructure and associated crypto wallets.
- September 9, 2026: The U.S. Treasury (OFAC) officially designates Xinbi Guarantee, SafeW Technology, and Anwen Technology as sanctioned entities. The UK FCDO updates its own list to include dozens of newly discovered addresses.
Human Rights and the "Scam Compound" Connection
Beyond the financial crimes, the sanctions on Xinbi highlight a dark humanitarian crisis. The UK’s decision to designate Xinbi under its Global Human Rights sanctions regime reflects the platform’s role in sustaining the "scam compounds" of Southeast Asia. These facilities are often staffed by victims of human trafficking who are lured by false job advertisements, only to be held captive and forced to conduct online scams under the threat of violence.

The infrastructure sold on Xinbi—ranging from the software used to deceive victims to the "security" equipment used to monitor captive workers—directly fueled this cycle of abuse. By targeting the financial heart of this ecosystem, regulators are hoping to make it economically unviable for these compounds to operate at scale.
Analysis: The Future of Illicit Finance and Regulatory Response
The targeting of Xinbi Guarantee signals a new era in the fight against crypto-enabled crime. For years, the focus was on individual hackers or specific mixers. However, the Treasury’s focus has shifted toward "nested" services—entities that operate within the broader crypto ecosystem but provide specialized tools for criminals.
The sheer scale of Xinbi—processing $24 billion—suggests that Chinese-language money laundering services now dominate a significant portion of the global illicit crypto market. Estimates suggest these services have handled roughly 20% of all illicit crypto funds over the past five years. By taking down a "guarantee" platform, law enforcement is not just removing a single player; they are destroying the "trust mechanism" that allows an entire marketplace of criminals to function.
Industry analysts suggest that while the seizure of $52 million is a blow, the more significant impact lies in the "chilling effect" on other vendors. The ability of the U.S. government to map out 52 specific addresses and seize Telegram channels suggests that the perceived anonymity of these platforms is rapidly eroding.
Official Reactions and Global Impact
In a statement following the announcement, U.S. Treasury officials emphasized that the United States would continue to use all available tools to disrupt the "financial lifelines" of cybercriminals and state actors like the DPRK. "Today’s action sends a clear message: we will not allow illicit marketplaces to facilitate the laundering of stolen assets or the exploitation of victims worldwide," the statement read.
The UK’s Foreign Secretary also lauded the coordinated effort, noting that the update to their sanctions list reinforces the international community’s commitment to tackling the "vile scam centers" that profit from human suffering.
As the digital asset landscape continues to evolve, the case of Xinbi Guarantee serves as a landmark example of how decentralized technology can be co-opted for massive criminal gain—and how a unified, data-driven international response can eventually dismantle even the most complex shadow financial empires. The focus now turns to whether the remnants of this network will attempt to regroup under new aliases, or if the increased scrutiny from OFAC and the DOJ will permanently fracture the Southeast Asian scam economy.















