US Seizes $52 Million in Crypto From Xinbi Scam Marketplace
Security

US Seizes $52 Million in Crypto From Xinbi Scam Marketplace

September 10, 20264 min read

The US Justice and Treasury departments hit the Xinbi Guarantee scam network with a coordinated strike, freezing more than $52 million in crypto. The operation targeted wallets, payment services and Telegram channels that had serviced fraud call centers across Southeast Asia for years. Analysts estimate the region's "guarantee" marketplace industry moves billions of dollars in stolen funds every year, and Xinbi ranked among its biggest players.

What investigators seized

The DOJ's Scam Center Strike Force seized two Xinbi wallets that collected vendor payments, holding roughly $12 million combined. Analysts at blockchain-tracing firm Elliptic first traced the funds, and federal agencies moved in only after that. Investigators also filed for restraints on 47 more wallets tied to the laundering network, so the final frozen total could still grow. Each of those wallets, according to the filing, served a separate cluster of vendors within the marketplace.

A court in Washington, DC authorized the seizure of the marketplace's Telegram channels on September 7. According to the unsealed warrant, vendors used those channels to advertise:

  • money laundering through wallet chains
  • custom fake investment websites built for individual victims
  • recruitment for scam compounds across Southeast Asia

Those fake sites usually copy the interface of real exchanges or brokerage platforms, so victims do not immediately realize the money is going straight to scammers.

Officials called it a first step in a broader campaign against marketplaces and service providers that keep the scam industry running, not just individual fraudsters. Enforcement used to focus mostly on operators on the ground, now the target is the infrastructure that arms them. The DOJ noted that cases like this take months of blockchain analysis before the full wallet list of a network becomes clear.

Who is behind Xinbi

On Wednesday the Treasury's Office of Foreign Assets Control designated Xinbi a significant transnational criminal organization. Two other firms were sanctioned alongside it, Singapore-based SafeW Technology and Cambodia-based Anwen Technology, which the department says provided technical and financial support to the marketplace. That status gives US authorities broader reach to pursue the firm's assets worldwide, not just inside the country. OFAC had mostly reserved this kind of designation for drug cartels and human trafficking networks before, and now it has extended it to crypto scam infrastructure too.

Treasury says more than $24 billion in crypto and fiat has flowed through Xinbi since around 2022.

For crypto exchanges and payment providers, the sanctions mean any dealings with Xinbi's wallets or its partners now carry legal risk even outside the US. Anwen allegedly built the XinbiPay wallet and payment app, also known as NewPay. In spring 2025, as law enforcement scrutiny grew, Xinbi began shifting its vendor network to SafeW's encrypted messaging app. The attempt to dodge monitoring eventually failed. Both partners ended up sanctioned alongside the parent marketplace.

Tether's role and TRM Labs' take

The DOJ separately thanked USDT issuer Tether for assisting the investigation. Treasury said the platform had also been used by North Korean hackers and by entities tied to Prince Group, a Cambodian conglomerate US authorities had already linked to scam call-center networks before. Overlaps like this between state-backed hacking groups and commercial scam networks keep turning up, since both sides rely on the same laundering infrastructure.

"OFAC sanctioned Xinbi for good reason. When Huione went down, Xinbi became the go-to escrow and cash-out layer for Southeast Asia's scam compounds and did it at industrial scale, moving more than USD 36 billion."

- Ari Redbord, Global Head of Policy at TRM Labs, from comments to Cointelegraph, September 10, 2026

Law enforcement had not reached this scale before. The previous benchmark case was Huione, which shut down under sanctions pressure. The operation builds on a broader alliance the US and UK announced earlier this year specifically to fight Southeast Asian scam centers. Washington's move also follows UK sanctions against Xinbi from March. Britain froze the marketplace's assets on its territory back then and barred it from its financial, trade and travel networks. Now two governments are pressing at once. Xinbi itself has already publicly called the asset freeze unfair, though it has not offered a detailed rebuttal.

What it means for ordinary users

In practice, marketplaces like this run as pseudo-escrow. A buyer and seller both trust a shared "guarantor" that may itself be part of the same criminal network. Legitimate exchangers, by contrast, carry licenses, support teams and a public track record you can check before a deal. Kurslog only lists exchangers with a real rating and review history for this exact reason. Any new counterparty deserves the same scrutiny before you hand over funds.

Xinbi formally operated as a guarantee P2P service, a setup that mirrors how legitimate exchangers verify deals between strangers. That is why, before you sell USDT for hryvnia through an unfamiliar counterparty, it pays to check their reputation and trade history rather than trust a promise of a great rate.

Victims of these call centers usually buy Bitcoin or USDT themselves to move funds onto a fake investment platform. The money is supposed to go toward "profitable trading," but really it lands straight in the scammers' wallets. The Xinbi case shows that this kind of infrastructure ran for years and served networks worth billions, before two governments finally drew a line under it.

Comments

Your email address will not be published. Required fields are marked *

or verify by email