-1.36%
-0.84%
-3.01%
-5.76%
-11.43%
-3.78%
The Seizure
On September 9, 2026, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned Xinbi Guarantee, targeting what officials describe as critical financial infrastructure used by threat actors worldwide.
- The Justice Department’s Scam Center Strike Force (SCSF) seized $12 million directly from Xinbi
- An additional 47 associated cryptocurrency wallets were restrained
- Total restrained funds now exceed $52 million
How Xinbi Built a $24 Billion Operation
Xinbi emerged around 2022 and quickly grew into a major marketplace for scam infrastructure, processing more than $24 billion in digital assets and fiat currency according to the U.S. Treasury. The platform connected transnational organized crime through hundreds of Telegram channels, where vendors offered services including money laundering, custom scam websites, and stolen personal data.
Xinbi’s escrow model is what made this scale possible. By acting as a trusted middleman for transactions, the platform gave criminal buyers and sellers enough confidence to complete large deals without knowing each other, the same trust mechanism that makes legitimate marketplaces functional, repurposed for illicit trade.
North Korea’s Role in the Network
DPRK-linked actors moved tens of millions in stolen funds through Xinbi’s vendor network, including proceeds from major hacks like the Bybit breach and the WazirX theft. Specialized launderers known as “Black U” operators swapped traceable stolen funds for less-tainted stablecoins sourced from other illicit revenue streams, including pig butchering scams. That substitution made the stolen funds significantly harder to trace back to their origin.
Part of a Wider Global Effort
These actions fit into a broader series of international efforts against cybercrime networks. The UK’s Foreign, Commonwealth & Development Office (FCDO) had already sanctioned Xinbi back in March 2026, months before this latest US action.
The scale of the broader problem is significant. Chinese-language money laundering services now process an estimated 20% of illicit crypto funds globally, amounting to $16 billion in 2025 alone.
Hashlytics Take
The recurring “Chinese-language” detail in this story describes the operating language of scam infrastructure, not a state actor. Xinbi’s own customer base spanned North Korean state hackers, pig butchering operators, and general cybercriminals working in multiple languages and jurisdictions. The UK sanctioned this same platform six months before the US did, and Chainalysis attributes the 20% laundering share to a criminal ecosystem, not a government. Reading this as a US versus China story misses what’s actually happening: Telegram-based markets built around a shared operating language have become the default laundering rails for cybercrime regardless of where the criminals or victims are located.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates
