From hacks to romance scams: how dirty money converged in a single crypto network

From hacks to romance scams: how dirty money converged in a single crypto network

The underground marketplace used a system of guarantee deposits and temporary holding of payments to reduce the risks of buying illegal services.

Sep 11, 2026

On September 9, the US Treasury's Office of Foreign Assets Control (OFAC) and the US Department of Justice (DOJ) announced coordinated measures against Xinbi Guarantee. OFAC added Xinbi Guarantee and two companies that provided operational support to the platform to the sanctions list, while the Scam Center Strike Force, an interagency group created by the DOJ, seized infrastructure and crypto wallets linked to the platform.

Sanctions against Xinbi Guarantee and its partners, and the seizure of related assets

OFAC added Xinbi Guarantee to the sanctions list as a significant transnational criminal organization under US Executive Order 13581, as subsequently amended. The sanctions also hit Singapore-registered SafeW Technology and Cambodia-based Anwen Technology. The US Treasury said the first company developed the SafeW communication app, which buyers and sellers on Xinbi Guarantee used to talk to each other, while the second developed XinbiPay, also known as the NewPay wallet — an application for crypto payments and for storing digital assets.

The DOJ's actions targeted the platform's channels and its money directly. On September 7, the US District Court for the District of Columbia authorised the seizure of the Telegram channels used to run this marketplace.

The DOJ said the coordinated action restricted more than $52M in crypto assets, and separately thanked Tether, the issuer of the USDT stablecoin, for its assistance.

Freezing of Xinbi Guarantee funds. Source: X
Freezing of Xinbi Guarantee funds. Source: X

How fraud proceeds entered the Xinbi Guarantee transaction network

Xinbi Guarantee began operating around 2022 and is a Chinese-language online marketplace built on the guarantee-service model.

The structure of Xinbi Guarantee. Source: US Treasury
The structure of Xinbi Guarantee. Source: US Treasury

In terms of how it works, Xinbi Guarantee combines seller listings, the holding of funds and a deal guarantee mechanism. Sellers post information about their services through channels such as Telegram, where fraud groups look for money laundering services, purpose-built fraudulent websites and other resources for illegal activity. According to the DOJ, once a buyer purchases a service, the platform can temporarily hold the payment intended for the seller and release it once the service has been performed. Xinbi Guarantee listings also stated that sellers must place a guarantee deposit, and that if a buyer is defrauded by a seller, they can be compensated through the corresponding mechanism. Historically, sellers mostly used USDT on the TRON blockchain to place the guarantee deposit.

For fraud groups, this mechanism reduces the risks of dealing with unfamiliar underground service providers and makes services such as money laundering easier to access. Once victims' funds have been received, the money can move on to sellers who launder funds and find clients through the platform. They offer services such as money transfers, currency and crypto exchange or cashing out. The DOJ said that in several cases investigators managed to trace the movement of money from American victims to specific sellers. These sellers advertised money laundering services in Xinbi Guarantee channels and openly published crypto wallet addresses to receive payments.

At the same time, the sources of funds inside the network formed by these sellers can also differ. An analysis of the related addresses showed that some sellers dealing in the so-called «black U» received stolen crypto assets whose origin could be traced to hacks, and then passed on to their clients stablecoins obtained from other illegal sources. Those sources included proceeds from pig butchering scams and romance scams. This indicates that different types of illicit funds can converge inside one and the same network of sellers and then be transferred and exchanged through different addresses and in different forms of digital assets.

Analysing underground marketplaces of this type therefore requires more than simply studying the platform itself. It is also necessary to identify the network of sellers behind it and the addresses to which they receive funds. The platform makes deals possible through listings, the holding of money and guarantee deposit mechanisms, while the specific laundering operations may be carried out by different sellers.

FinCEN ties nearly $13 billion to crypto scams operated by overseas scam centers

From Huione Guarantee to Xinbi Guarantee: continuing to track illicit financial networks

The rise of Xinbi Guarantee is also connected with the migration of business after regulatory and law enforcement measures against similar marketplaces. The US Treasury said that after the Huione ecosystem ran into regulatory restrictions, part of the cybercriminal activity moved to Xinbi Guarantee, which went on providing similar services to roughly the same client base. The Treasury also said that from around June 2025 Xinbi Guarantee began moving its sellers and the related money laundering networks to SafeW, while at the same time launching XinbiPay, also known as the NewPay wallet.

Analysts have already identified and classified dozens of variants linked to Huione Guarantee, including Tudou Guarantee, Qitian Guarantee, Fulilai Guarantee, Jinbei Guarantee and Xinbi Guarantee.

This creates a basis for identifying risks on the blockchain and analysing the movement of funds. Continuous monitoring also makes it possible to compare known address characteristics with actual changes in the movement of funds, giving organisations additional information for assessing their own risk.

On the basis of these capabilities, financial and payment organisations can use AML (Anti-Money Laundering) and KYT (Know Your Transaction, the analysis of specific transactions) tools to monitor addresses continuously, identify risks and track the movement of funds. Such capabilities can be built into workflows related to checking clients and counterparties, deposits and withdrawals, and processing payments. This makes it possible to identify risks directly or indirectly linked to fraud, money laundering and sanctioned organisations, while keeping blockchain data as evidence for the later analysis of suspicious operations and for investigations.

What KYT is in crypto and how transaction monitoring worksRead more

Illicit transaction networks may keep moving from one platform to another, but sellers, wallet addresses and the links between flows of funds still leave traces on the blockchain. For financial and payment organisations, identifying such links on an ongoing basis can help spot potential risks in time and assess the degree of their own exposure. As new marketplaces and schemes appear, monitoring the relevant addresses and financial links remains an important tool for controlling on-chain operations and analysing the illicit movement of funds.

#Hack
$24 billion in turnover and dozens of wallets: the US exposes an underground financial network