Highlights
- OFAC sanctioned Xinbi Guarantee on September 9, 2026, a Telegram-based marketplace the US Treasury says has processed more than $24 billion since 2022.
- Southeast Asian guarantee platform Fuli Lai began purging money-laundering merchants after the sanctions, and its associated wallet has already recorded a $9.3 million USDT outflow.
- Chainalysis traced tens of millions of dollars from the Bybit and WazirX hacks through Xinbi's "Black U" laundering service, used by North Korea-linked actors to swap tainted funds for cleaner stablecoins.
- The US Justice Department has restrained more than $52 million in crypto tied to Xinbi's vendor network.
The US Treasury's Office of Foreign Assets Control sanctioned Xinbi Guarantee on September 9, 2026, designating the Telegram-based marketplace as a significant transnational criminal organization alongside two affiliated technology vendors. Xinbi has operated since 2022 as a guarantee platform connecting scam-center operators in Southeast Asia with merchants selling everything from stolen data to money-laundering services, and Treasury estimates it has processed more than $24 billion in digital and fiat currency in that time. The designation, which follows a UK sanctions action against the same network in March 2026, is already rippling through the region's guarantee-platform ecosystem: rival operator Fuli Lai Guarantee has begun expelling money-laundering merchants from its channels, and on-chain trackers have already logged a multimillion-dollar outflow from its associated wallet.
Blockchain analytics firm Bitrace reported that Fuli Lai Guarantee began clearing out illicit merchant groups the night after the OFAC action, targeting operations known in local parlance as "card-connecting" rings that launder stolen credit-card funds and "cash-car" networks that convert fraud proceeds into physical currency. Bitrace said the platform's associated wallet has recorded roughly $9.3 million in USDT outflows since the sanctions were announced, a sign that merchants and users are rushing to move funds before further enforcement action or platform freezes.
Separately, Chainalysis published findings tying North Korea-linked hacking groups to Xinbi's vendor network through a specialized laundering service called "Black U." According to the firm's analysis, DPRK-linked actors funneled tens of millions of dollars in stolen crypto — including proceeds from the $1.5 billion Bybit breach and the $235 million WazirX theft — through Xinbi intermediaries who swapped traceable stolen assets for less-tainted stablecoins before off-ramping through unlicensed OTC desks. Chainalysis said the 52 addresses OFAC ultimately designated had collectively received more than $8.4 billion in stablecoins. On the enforcement side, the US Justice Department's Scam Center Strike Force has already seized roughly $12 million in crypto directly and sought restraints on 47 additional wallets, placing more than $52 million beyond the network's reach.
A Region-Wide Laundering Problem
The Xinbi action is the latest sign that Washington and its allies are treating Southeast Asia's guarantee-platform economy — a loose network of Telegram-based marketplaces that underpin the region's scam-compound industry — as a systemic money-laundering risk rather than a series of isolated bad actors. FinCEN has separately tied $12.7 billion in crypto flows to scam compounds operating out of the same region, and the pattern of one guarantee platform's shutdown pushing users toward, or away from, rivals has repeated before: a $2.8 billion underground banking ring dismantled by Shanghai police earlier this year relied on a comparable network of OTC brokers and merchant guarantees.
Related: Chainalysis Sues US Over $95M ICE Contract Handed to TRM Labs
For stablecoin issuers, the episode is a reminder that the same rails that make USDT useful for legitimate cross-border payments also make it the preferred settlement asset for scam-center economies processing tens of billions of dollars a year. For exchanges and compliance teams, the Black U findings sharpen an uncomfortable reality: stolen funds from a major hack can be several hops removed from the original theft, laundered through informal guarantee networks, and re-enter the traceable financial system as ostensibly clean stablecoins well before an exchange's own screening tools would flag them. Expect wallet-screening providers to move quickly to blacklist addresses linked to Xinbi's vendor network, and expect rival platforms like Fuli Lai to face growing pressure — self-imposed or otherwise — to distance themselves from the same merchant pool.
What Comes Next
Treasury's designation freezes any US-linked assets tied to Xinbi and its two named technology vendors, but enforcement against a Telegram-native, cross-border marketplace is inherently harder to make stick than a sanctions listing against a bank or exchange. Watch for whether Fuli Lai's merchant purge holds or reverses once immediate scrutiny fades — the $9.3 million already withdrawn from its wallet suggests users aren't waiting to find out. Also worth tracking: whether Chainalysis or Elliptic identify further North Korea-linked flows through Xinbi's remaining vendors, and whether other jurisdictions beyond the US and UK move to sanction the network, which would tighten the noose on its remaining fiat off-ramps.
FAQ
What is Xinbi Guarantee?
Xinbi Guarantee is a Telegram-based online marketplace that has operated since 2022, connecting Southeast Asian scam-center operators with merchants selling money-laundering services, stolen data and other illicit goods; US Treasury estimates it has processed more than $24 billion.
Why did the US sanction Xinbi Guarantee?
OFAC designated Xinbi Guarantee a significant transnational criminal organization on September 9, 2026, for enabling cyber scams, fraud and money laundering targeting Americans, following a similar UK sanctions action in March 2026.
What is the "Black U" laundering service Chainalysis identified?
Black U was a laundering service operating within Xinbi's vendor network that Chainalysis says North Korea-linked hackers used to swap traceable stolen crypto, including funds from the Bybit and WazirX hacks, for less-tainted stablecoins.
How much crypto has been frozen or restrained so far?
The US Justice Department has seized about $12 million directly and sought restraints on 47 additional wallets, placing more than $52 million in crypto beyond the reach of Xinbi and its vendor network.
