News

Xinbi Guarantee Seized – Inside the $24B Telegram Scam Marketplace

Wireframe chat marketplace stamped "SEIZED" beside frozen crypto wallets, illustrating the Xinbi Guarantee takedown and $52.8M freeze.

If you ask the average person where the largest criminal marketplaces on the internet are located, they’ll say the dark web, things like Tor and onion links.

The second-largest one ever constructed operated on Telegram, primarily using Chinese, and included escrow, allowing sellers to make deposits and providing a method for settling disputes between buyers and sellers.

It was known as Xinbi Guarantee, and this week the US government launched its attack on it from three sides simultaneously. The Treasury sanctioned it, the Justice Department took over the Telegram channels that it used, and $52.8 million worth of crypto linked to the marketplace and its sellers was frozen all in one morning.

Here’s the true nature of Xinbi, what it offered for sale, who the customers were, and the reason why those involved had already started moving their funds somewhere harder to freeze before the government had made any announcement.

What Happened, Day by Day

The entire situation played out over three days.

  • Monday, September 7: A federal court in Washington, D.C. approved the seizure of the Telegram channels which hosted the marketplace.
  • Tuesday, September 8: Starting at 8am UTC, 52 wallets belonging to Xinbi and its merchants were frozen. Together they held $52.8 million in USDT, according to blockchain analytics company Elliptic, which assisted the US Secret Service in identifying them.
  • Wednesday, September 9: The Department of Justice and the Treasury made all the information public. By that afternoon Xinbi’s main Telegram channel had disappeared and many of the usernames associated with it had been disabled, The Record reported. TRM Labs states that Telegram has now formally banned it.

The announcement also included details about an event taking place on the other side of the world. In order to assist the local police, the DOJ’s Scam Center Strike Force had dispatched a team to Madagascar for a period of two weeks to help dismantle 13 scam centres operated by Chinese organised crime groups. There were nearly 400 arrests made there and more than 3,200 devices were processed. Around 30 of the people arrested were Chinese leaders of the compounds, and China’s government repatriated them.

So What Was Xinbi, Exactly?

Xinbi was a “guarantee” marketplace. That one word carries a lot of weight, so it is worth taking the time to consider it.

Criminals have a problem with trust. Suppose you hire someone to launder stolen money or to create for you a fake investment website, you can’t take them to court if they then disappear with your deposit. The guarantee marketplaces solve this. Sellers put up a deposit with the platform. When a buyer pays for an item, Xinbi keeps the money until the work has been completed and only then releases it to the seller. If a buyer is cheated, they can be reimbursed from the seller’s deposit.

It’s the same kind of logic that we explained in our article about how carders check out their suppliers, similar to how Amazon reviews work. Crime scales when strangers are able to trust one another. Xinbi sold that trust and took their share.

Almost everything on it was paid for in USDT, the stablecoin issued by Tether, mostly on the TRON blockchain. The fact that this is so turns out to be important, something we’ll deal with later.

What Was for Sale

The entries resemble a list drawn up for the purpose of running a scam operation.

The seizure warrant obtained by the DOJ lists vendors who provide custom scam investment websites, engage in money laundering, and recruit victims of trafficking to work inside scam compounds in Southeast Asia. One of the advertisements featured in the DOJ’s release was recruiting “Level 1” scam agents.

A number of researchers who looked into the platform discovered a great deal of other items. TRM Labs includes among its listings stolen personal data, fake identity documents, AI deepfake tools, satellite internet equipment and over-the-counter crypto exchanges. Elliptic’s research in 2025 found Starlink kits for sale (scam operators use them in order to remain online), databases containing stolen contact information for the purpose of locating victims, and money-laundering services which clearly stated the types of money they would accept. Some of the advertisements specifically mentioned that they would clean up the funds obtained from “pig butchering” scams, including money taken from victims in the United States.

It wasn’t all concerned with scams. Elliptic also identified vendors offering to stalk and intimidate people in China and to provide illegal surrogacy services, and found what appeared to be sex trafficking involving victims as young as 14.

How Big It Got

The official figure is $24 billion. According to the Treasury, Xinbi has dealt with an amount equivalent to over $24 billion in cryptocurrency and conventional currency since it began around 2022. Elliptic’s figure agrees with this and includes an additional $6 billion via its associated payment service, Xinbi Pay.

TRM Labs has given a figure of more than $36 billion. The difference probably comes down to how each company defines Xinbi-linked activity. Nevertheless, the extent of the figure is difficult to imagine.

To put it in context, only one online illegal marketplace has ever handled more: Huione Guarantee, which processed $31 billion over a period of four years before it closed in May 2025. Xinbi comes second in that list. According to Elliptic’s research, both of these markets far outstrip the earlier Tor drug markets which are the ones most people associate with the term “dark web”. Drugs were never the main source of profit. It was fraud.

What stands out is the growth. In May 2025 Elliptic recorded $8.4 billion in transactions and around 233,000 users. This month, TRM states that Xinbi’s Telegram subscriber number has reached 657,643. As of last week, threat intelligence company DarkTower counted more than 4,600 crime-as-a-service vendors on the platform.

There’s also an unusual point in Elliptic’s 2025 report: Xinbi stated on its website that it operated via a company registered in Colorado. The corporate records for that state show that “Xinbi Co., Ltd” was incorporated in August 2022 and had its principal office in Aurora. However, by January 2025 it had become delinquent for not having filed a report.

Who Was Buying

The principal customers were scam centre operators in Southeast Asia. These are the compounds you may have come across in the news, in which workers who have been trafficked are attracted there by false job advertisements and are then made to carry out romance and investment scams continuously.

The Treasury has also stated that the platform was used by North Korean hackers. As an example, in July 2024 $235 million was stolen from the Indian crypto exchange WazirX in a hack which was later linked to North Korea. Elliptic was able to trace about $220,000 of that amount to a Xinbi address through nine transactions on November 12, 2024. That means that vendors on Xinbi had apparently been hired to help launder the funds.

If North Korean crypto theft sounds familiar, it’s because North Korean hackers were also behind the fake Zoom calls draining crypto wallets that we reported on in July.

The Treasury also listed other sanctioned groups as users, such as the Jin Bei Group and the companies associated with the Prince Group, the Cambodian conglomerate that the United States and the United Kingdom targeted in October 2025.

It Already Survived One Crackdown

It hasn’t been the first attempt to get Xinbi shut down, and that is what makes this week’s action significant.

In May 2025, following the research that Elliptic had published on the matter, Telegram shut down thousands of the channels that belonged to both Xinbi and Huione Guarantee. Huione never returned, but Xinbi did.

Around June 2025 it began transferring its sellers and its money-laundering networks to SafeW, an end-to-end encrypted messaging app, and introduced its own crypto wallet, XinbiPay (which is also marketed as NewPay). Xinbi even set up a physical store within Yatai New City, a well-known complex of scam operations in Myanmar. However, that arrangement did not last, since the military in Myanmar carried out a raid on the area in late 2025 and subsequent footage revealed that the store was partly destroyed.

At the same time, those users who had lost Huione transferred to Xinbi. According to TRM, the amount of money flowing into Xinbi each day nearly doubled between May and December 2025. Elliptic states that Telegram then refused to shut down Xinbi even though there was clear evidence of its purpose.

On March 26, 2026 the UK became the first nation to impose sanctions on Xinbi, and the United States is now the second.

What Was Actually Seized (and What Wasn’t)

That’s where headlines tend to become careless, so it’s important to get this right.

“Frozen” and “seized” are not identical. The following explanation comes from the DOJ’s own statement:

  • Two of the wallets which Xinbi used for collecting payments from vendors were seized in full. They contained approximately $12 million.
  • The authorities requested that 47 additional wallets connected with money laundering and those associated with vendors who worked for the scammers should be placed under restraint.
  • A total of over $52 million was restrained. The Department of Justice specifically expressed its thanks to Tether, and it was Tether’s ability to freeze USDT that made this possible.

Restrained money is not money that has been returned. It remains locked in place while the legal proceedings continue. It hasn’t been given back to the victims so far, and there’s no guarantee that all of it will eventually be.

It’s also worth pointing out that the announcements say nothing about arresting the people who run Xinbi. This is a blow to its finances and infrastructure, not a story about people being arrested. At least not yet.

With regard to the sanctions, the US Treasury has designated Xinbi Guarantee as a significant transnational criminal organisation. The Treasury has also sanctioned the two companies which were responsible for the development of the tools that enabled Xinbi to survive the previous crackdown: SafeW Technology, the company based in Singapore that produced the SafeW messaging app, and Anwen Technology, the developer in Cambodia of XinbiPay. All of their assets in the United States or held by US persons are now blocked, and Americans are generally not allowed to carry on business with them.

Xinbi’s Response: Switch to a Coin Nobody Can Freeze

Xinbi did not go quiet. The operators stated in a message posted on Telegram that Xinbi “strongly condemns Tether’s arbitrary freezing of addresses”, committed to paying compensation to its customers, and announced that it was moving away from USDT.

The replacement is USDD, a stablecoin linked to the US dollar and built on the TRON blockchain, launched by Justin Sun, the founder of TRON. Unlike USDT, it does not have a central issuer who can use a freeze button. During the hours following the freeze, Elliptic observed Xinbi exchanging approximately $2.8 million of the USDT it still had into USDD via a decentralised exchange.

However, there is a drawback: Elliptic points out that USDD is in part backed by USDT, which can be frozen. Therefore, the escape route isn’t as straightforward as Xinbi is making it appear.

Tom Robinson, co-founder of Elliptic, told The Record that Xinbi will probably attempt to rebuild and relaunch, but the sanctions will make that very difficult.

The greater problem facing Xinbi may not be the money it has lost at all. Guarantee markets function entirely upon trust; the reason for paying Xinbi a commission was so that people would know their funds were safe. All the sellers on the platform now know that their wallet could at any moment be frozen. And that is something difficult to get around by advertising.

Why This Matters Even If You’ve Never Heard of Xinbi

You have most likely never gone to Xinbi, but it’s quite possible that you’ve come across its customers.

The “wrong number” message which then develops into a friendly conversation. The dating app match who just happens to be very good at crypto trading. The investment platform that shows you massive returns which you cannot quite withdraw. Many of these scams are operated from the compounds that shopped on Xinbi. The fake investment website may have been purchased there. The phone list containing your number may have been bought there. The money laundering service that was used afterwards may have been hired there.

The situation is severe. The Department of Justice, citing figures from the FBI, states that in 2025 cyber-enabled fraud amounted to almost 85% of all the losses reported to the FBI’s Internet Crime Complaint Center (IC3). Losses reported in connection with crypto investment fraud increased from $4.57 billion in 2023 to $8.65 billion in 2025. The actual figure is very likely to be higher since most victims do not come forward.

A few things worth knowing if you or someone you love gets targeted:

  • Scams of this kind seldom begin with a request for money. Instead, they begin with weeks of friendly chat, and the mention of money comes later, typically in the form of an “opportunity”.
  • When a platform allows you to make deposits but then keeps coming up with reasons preventing you from withdrawing (such as taxes, fees, or “verification”), it’s a scam.
  • If you have already lost money, you should report it at ic3.gov. Be very careful with anyone who contacts you offering to retrieve your money. The FBI issued a warning in July 2026 about scammers who are pretending to be IC3 staff and even using AI-generated videos of FBI officials in order to target people who have already been scammed once.

If you’d like to know more about the way your personal information ends up in lists such as those sold on Xinbi, then see our analysis of identity theft and the dark web, and our guide on what to do if your information is on the dark web.

What to Watch Next

A few questions will determine whether this actually sticks.

First of all, does Xinbi relaunch on SafeW and USDD, and do its vendors do the same? The previous crackdown only made it bigger.

Second, could issuers’ freeze features still function if the marketplaces switch to coins that don’t have a freeze button? This week demonstrated the extent of Tether’s cooperation. It also made criminals aware of what to avoid the next time.

Third, who will fill the gap? In 2025 Elliptic stated that it was keeping track of about 30 other guarantee marketplaces operating on Telegram and using stablecoins. When Huione went down, Xinbi took in its customers, so someone will now attempt the same move.

And last, the lesson for anyone following this space: the “dark web” people imagine is increasingly not where the biggest crime happens. The largest illicit marketplaces in history didn’t hide behind Tor. They ran on a mainstream messaging app with more than a billion users, in plain view, for years.

We’ll update this piece if Xinbi resurfaces or if any of the restrained funds make it back to victims.

Written by hanna

I'm Hanna, a security consultant based in Berlin with more than twelve years of experience across offensive and defensive security. I started out on a blue team chasing alerts at 3 a.m., moved into red teaming because I wanted to understand the other side of the console, and now run an independent practice advising companies on threat intelligence, penetration testing, incident response planning, and security architecture.

📋 Latest Articles

View all →
Infostealer logs illustration showing a glowing ZIP archive leaking stolen passwords, browser cookies, credit cards, and crypto wallet data from a laptop
Guides

Infostealer Logs – The Breach That Rarely Gets Reported

Infostealer logs: In the first half of 2025, over 1.8 billion credentials containing saved passwords, usernames, phone numbers,…

Sep 10, 2026
12 min read
How Threat Actors Vet Stolen Credit Card Shops
News

Carders Now Vet Their Suppliers Like Amazon Reviews. Here’s How the Stolen Card Economy Actually Works.

There’s a document circulating on underground forums right now with a title that sounds like a Reddit post…

Sep 9, 2026
12 min read
Substack Data Breach
News

Substack Data Breach: 663,000 Accounts Were Exposed for Four Months Before Anyone Noticed

In October 2025, someone got into Substack’s systems and quietly pulled out data on hundreds of thousands of…

Sep 8, 2026
10 min read
News

ValueFirst Appeared in a Dark Web Alert. Here’s Why That’s Worth Paying Attention To.

On September 7, 2026, at around 6:16 PM, a dark web intelligence monitoring account called @DailyDarkWeb posted a…

Sep 8, 2026
7 min read
Cracked magnifying glass made of blue circuit lines powering down while data fragments drift away, illustrating the shutdown of Google's Dark Web Report
Monitoring

Google Killed Its Dark Web Report – What to Use Instead

Starting from the 16th of February 2026, Google dark web report shut down its operation completely. This comes…

Sep 5, 2026
13 min read
Glowing wireframe file icon labelled wp-config.php.bak alone in a dark server corridor, illustrating the WordPress backup files allegedly left publicly accessible on Sonora government portals.
News

Sonora Government Portals Allegedly Left Live Database Passwords Sitting in Plain Sight

A threat actor has posted what they claim are publicly accessible WordPress configuration backup files from municipal government…

Sep 5, 2026
5 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted