US authorities have escalated their crackdown on Xinbi Guarantee, restraining more than $52 million in crypto and seizing key infrastructure.
A federal court authorized the seizure of Telegram channels tied to the Chinese-language marketplace on Sept. 7, while investigators seized two wallets holding about $12 million and sought restraint of 47 additional addresses linked to vendors and suspected money laundering.
The Treasury Department simultaneously designated Xinbi a significant transnational criminal organization and sanctioned SafeW Technology and Anwen Technology, companies tied to messaging and payment infrastructure used by the marketplace.
The measures extend beyond individual wallets. Xinbi had begun shifting merchant coordination and alleged laundering activity to the encrypted SafeW application around June 2025 and introduced XinbiPay, also known as NewPay, as scrutiny of its operations intensified.
By sanctioning those service providers alongside wallet seizures, US authorities targeted both the movement of funds and the infrastructure used to organize transactions.
The action follows earlier pressure on Xinbi’s USDT network, including freezes affecting operational wallets used to receive, route and withdraw stablecoins. That had already pushed the marketplace to explore alternatives, including greater use of USDD.
Meanwhile, this US action follows sanctions imposed by the UK and comes as governments increasingly focus on the service providers that let stolen crypto and scam proceeds move between wallets, stablecoins, and cash-out networks.
North Korean hackers reveal Xinbi’s role in crypto laundering
Xinbi had become more than a marketplace for Southeast Asian scam operators, providing financial infrastructure that connects cyber theft, fraud proceeds, and underground cash-out networks.
Blockchain analysis firm Chainalysis said North Korea-linked threat actors moved tens of millions of dollars in stolen cryptocurrency through vendors operating on the platform.
Among the services available were specialist operators known as “Black U” launderers, which help criminals break the direct on-chain link between stolen assets and the money they ultimately withdraw.
The vendors accept cryptocurrency traceable to hacks and replace it with stablecoins sourced from separate illicit revenue streams, including pig-butchering and romance scams. That lets stolen tokens disappear into a much larger pool of criminal flows, while hackers receive different assets they can move through unlicensed over-the-counter desks and convert into fiat.
The model made Xinbi useful to actors trying to evade blockchain tracing without relying solely on conventional mixers or bridges.
Chainalysis said the platform hosted vendors offering cash delivery, bank-card fraud, personal data sales, know-your-customer bypasses, scam-platform development, surveillance equipment and malware services.


Its vendor channels also served as recruitment pipelines for some Southeast Asian scam compounds where trafficked workers have been subjected to forced labor and physical confinement.
Xinbi processed an estimated $24 billion in digital assets and fiat after emerging around 2022, making it one of the largest transaction-guarantee markets serving the region’s underground economy.
Its role in connecting different categories of illicit finance helps explain the breadth of the latest enforcement.
Rather than targeting a single token or laundering address, US authorities moved against the marketplace’s communications channels, payment wallets, and companies providing supporting infrastructure.
Sanctions trigger withdrawals and merchant exits
The impact of the US measures is already showing up onchain.
Bitrace said it detected abnormal outflows from a Xinbi sub-guarantee platform that had previously operated with little public visibility. Daily USDT withdrawals ranged from about $389,000 to $564,000 between Sept. 1 and Sept. 7, then jumped sharply as enforcement pressure intensified.
Outflows reached about $1.28 million on Sept. 8 and climbed to $1.81 million on Sept. 9. Another $708,125 had left by Sept. 10, Bitrace data showed.


The firm said large numbers of guarantee merchants were moving funds rapidly to reduce the risk of having assets caught in subsequent freezes or sanctions measures.
That defensive behavior has spread to competing platforms.
Fulilai Guarantee, another major transaction-guarantee marketplace, began removing money-laundering merchants from public groups after the Xinbi sanctions, Bitrace said. The purge included operators offering services commonly described as “card-to-USDT” and “cash car,” both used to move or convert illicit funds.
Fulilai Wallet, operated by the platform, has recorded about $9.3 million in outflows since OFAC announced the Xinbi sanctions.
The reaction raises the cost of Xinbi’s adaptation efforts. The marketplace had already explored shifting activity away from USDT after issuer-level freezes demonstrated how centralized stablecoins could become an enforcement choke point.
Moving to another token may reduce exposure to a direct issuer freeze, but it does little to solve the broader problem created by sanctions on service providers, payment infrastructure and counterparties.
For rival platforms, the calculation is becoming more immediate. Continuing to host merchants linked to laundering operations could preserve transaction revenue, but it also increases the risk that wallets, channels and affiliated companies become the next targets.



