U.S. Department of Justice Dismantles Xinbi Guarantee Marketplace in Global Crackdown on Organized Cyber-Fraud Networks

The United States Department of Justice (DoJ) has officially announced a series of high-stakes, coordinated international operations aimed at dismantling Xinbi Guarantee, an expansive illicit online marketplace that has functioned as a central hub for global cyber-scam operations. This multi-agency intervention, which involved the U.S. Secret Service, the Treasury Department’s Office of Foreign Assets Control (OFAC), and international partners, marks a significant escalation in the American government’s campaign against the sophisticated criminal syndicates orchestrating industrial-scale fraud, including the pervasive "pig butchering" romance scams that have bilked thousands of American victims out of billions of dollars.
The operation saw the seizure of critical digital infrastructure, including Telegram channels that served as the backbone for the marketplace’s operations, and the confiscation of cryptocurrency wallets containing millions in illicit proceeds. Furthermore, the Scam Center Strike Force, a specialized unit tasked with disrupting the financial lifelines of these criminal enterprises, successfully extended its reach to Madagascar. This expansion resulted in the physical disruption of 13 separate scam compounds, leading to the recovery of over 3,200 electronic devices and the initiation of investigations based on testimonies from nearly 400 detained individuals, including the repatriation of 30 alleged high-ranking Chinese organizers.
The Rise and Function of Xinbi Guarantee
Xinbi Guarantee emerged as the successor to a lineage of illicit digital marketplaces, most notably HuiOne Guarantee and Tudou Guarantee. Following the closure or disruption of those entities in the previous year, Xinbi stepped into the power vacuum, leveraging the Telegram messaging platform to facilitate a "one-stop shop" for criminal operators.

Functionally, the platform acted as a sophisticated escrow service. It bridged the gap between specialized vendors—who provide tools like custom-coded investment fraud websites, stolen personal data, and money laundering infrastructure—and the operators of scam compounds located primarily in Southeast Asia. By holding payments in escrow, Xinbi provided a veneer of "professionalism" and security for criminals, ensuring that vendors were paid only upon the successful delivery of their fraudulent tools. Since its inception in 2022, blockchain analytics firm Elliptic estimates that Xinbi has facilitated approximately $30 billion in transactions, cementing its status as one of the most significant illicit marketplaces in recent history.
A Chronology of Escalation
The disruption of Xinbi follows a strategic timeline of increasing regulatory and law enforcement pressure:
- 2022: Xinbi Guarantee is established on Telegram, quickly growing into a primary hub for scam-related services.
- 2025 (May): Public reports highlight the marketplace’s role in facilitating $8.4 billion in suspected illicit transactions.
- 2026 (January): Following the halt of the Tudou Guarantee marketplace, Xinbi solidifies its dominance, resisting early attempts at oversight.
- 2026 (March): The United Kingdom becomes the first nation to formally sanction Xinbi, targeting its trade in stolen personal data and illicit satellite communications equipment.
- 2026 (June): The U.S. DoJ and Treasury initiate the current, comprehensive takedown, seizing assets and deploying the Scam Center Strike Force to global locations including Madagascar.
Financial Impacts and the Shift in Asset Strategy
The financial scale of the operation is staggering. The DoJ reported the restraint of approximately $52 million in cryptocurrency within a single 24-hour period, bringing the total value of assets seized by the Scam Center Strike Force to nearly $938 million. This capital, often held in Tether’s USDT stablecoin, represents the lifeblood of the scam networks.
Notably, the crackdown has triggered a tactical pivot by the marketplace’s operators. Historically reliant on the TRON-based USDT—which possesses a centralized "freeze" function that allows developers to block funds—Xinbi has attempted to migrate its remaining assets to USDD (Decentralized USD). This move represents an attempt to bypass law enforcement’s ability to "blacklist" or seize funds. However, experts note that this transition is inherently flawed. As Dr. Tom Robinson, Founder and Chief Scientist at Elliptic, has pointed out, USDD remains partially collateralized by freezable assets, meaning the platform’s attempt to achieve "true" decentralization remains largely theoretical and vulnerable to ongoing scrutiny.

Official Responses and Strategic Policy
The U.S. government has framed this operation as a vital component of national security. Secretary of the Treasury Scott Bessent emphasized the severity of the threat, noting that Southeast Asian scam centers are responsible for stealing billions from American citizens annually. "The Trump Administration is united in its efforts to dismantle these overseas criminal enterprises," Bessent stated, highlighting the Treasury’s commitment to using every available financial tool to protect the public from what he described as "egregious fraud."
Tara McLeese, Special Agent in Charge of the U.S. Secret Service Washington Field Office, echoed these sentiments, noting that the criminals behind Xinbi operated under the dangerous delusion that they were beyond the reach of international law. The success of the Madagascar operation, which resulted in the identification of 30 key leaders who have since been returned to China for prosecution, demonstrates a new era of transnational cooperation between the U.S., China, and local authorities to address the scourge of cyber-human trafficking and forced-labor scam compounds.
Analysis: Implications for the Cybercrime Ecosystem
The dismantling of Xinbi represents more than just a momentary interruption of service; it is a fundamental blow to the trust-based model of the "Guarantee" marketplace ecosystem. These marketplaces rely entirely on the perceived reliability of their escrow services. By demonstrating that the U.S. government has the capability to track, identify, and seize funds from these platforms, law enforcement has introduced a persistent "uncertainty tax" on all participants.
For the criminals involved, the barrier to entry has increased. Merchants and scammers must now grapple with the reality that their digital wallets can be identified and frozen at any moment. This creates a ripple effect of suspicion, where vendors are less likely to trust the platforms they use, and operators are less likely to rely on centralized digital hubs.

However, the threat remains fluid. The swift, albeit imperfect, migration to USDD demonstrates that these criminal networks are highly adaptive and are already planning for a post-USDT landscape. The future of this fight will likely depend on the ability of international coalitions to maintain this pressure, targeting not only the marketplaces themselves but the financial rails that allow them to monetize their crimes.
The expanded mandate of the Scam Center Strike Force—to target compounds globally rather than focusing on specific geographic hotspots—suggests that the U.S. is preparing for a long-term, distributed conflict against these decentralized criminal syndicates. As the digital and physical worlds continue to converge in the realm of organized cyber-fraud, the success of the Xinbi takedown serves as a template for future international enforcement, underscoring that the reach of justice is increasingly matching the global footprint of those who seek to profit from the exploitation of the vulnerable.






