The United States has imposed sanctions on Xinbi Guarantee, a Chinese-language online marketplace accused of supporting cyber scams, money laundering and other criminal operations targeting Americans.
The US Treasury Department’s Office of Foreign Assets Control designated Xinbi Guarantee as a transnational criminal organisation, alleging that the platform provided infrastructure and financial services to scam centres, cybercriminals and money-laundering networks.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
$24 Billion in Transactions Passed Through Xinbi Marketplace
According to the US Treasury, Xinbi Guarantee and its marketplace have processed the equivalent of more than $24 billion in digital assets and fiat currency since operations began around 2022.
The marketplace primarily facilitated transactions involving countries in Southeast Asia and allegedly became an important financial and commercial hub for criminal groups operating online.
US authorities allege that Xinbi allowed scam-centre operators to obtain goods, financial services and other resources needed to sustain cyber fraud operations.
How Did Xinbi Allegedly Support Cybercrime Networks?
Xinbi allegedly provided escrow services through its marketplace, acting as an intermediary between buyers and sellers.
According to Treasury, those services were used by scam operators, money-laundering networks and cybercrime syndicates to facilitate transactions linked to financial fraud and other illegal activity.
The platform was also allegedly used by entities already under US sanctions, including Jin Bei Group and entities belonging to the Prince Group transnational criminal organisation.
North Korean Hackers Allegedly Used the Platform
US authorities said Xinbi Guarantee’s platform had also been used by North Korean hackers.
Blockchain investigators have previously linked the marketplace to the laundering of cryptocurrency stolen by North Korea-linked cyber actors.
This connection puts Xinbi within a broader international effort to disrupt financial infrastructure allegedly used by North Korean cyber operations to move and conceal stolen assets.
India Crypto Exchange Theft Linked to Xinbi Addresses
The network has also been linked to the July 2024 theft of approximately $235 million from Indian cryptocurrency exchange WazirX.
Blockchain analysis by Elliptic attributed the attack to North Korea-linked actors and traced part of the stolen cryptocurrency through laundering routes.
Around $220,000 in USDT originating from the theft was sent to a Xinbi Guarantee address in November 2024 through nine transactions, according to Elliptic.
The finding indicated that vendors operating through Xinbi may have been used to help launder part of the proceeds from the exchange hack.
Why Did Xinbi Shift Activity to SafeW?
Treasury said that around June 2025, Xinbi Guarantee began moving merchant activity and money-laundering networks towards SafeW, an encrypted messaging platform.
Xinbi allegedly encouraged users to coordinate transactions between buyers and sellers through the service as scrutiny of criminal marketplaces and online scam infrastructure intensified.
The latest US action also targeted entities accused of supporting Xinbi’s operations through digital currency and other financial services.
US Action Goes Beyond Financial Sanctions
The action against Xinbi was coordinated with the US Department of Justice’s Scam Center Strike Force.
US authorities also seized infrastructure and digital asset wallets linked to Xinbi Guarantee as part of the coordinated operation.
Separately, blockchain analytics firm Elliptic said the US Secret Service froze wallets belonging to Xinbi and its merchants containing approximately $52.8 million in cryptoassets.
Southeast Asian Scam Centres Under Growing Pressure
The action comes amid a wider US crackdown on scam centres operating across Southeast Asia.
Treasury Secretary Scott Bessent said such centres steal billions of dollars from American victims each year and that US authorities would continue targeting the financial infrastructure supporting them.
These criminal networks have been accused of running investment scams and other forms of online fraud while relying on complex systems of payment processors, digital assets, intermediaries and encrypted communications.
The US has also previously targeted the Prince Group and associated entities over alleged involvement in scam-centre operations.
What Do the Sanctions Mean for Xinbi?
The designation generally requires property and interests in property belonging to sanctioned entities that are within US jurisdiction or controlled by US persons to be blocked.
Transactions involving sanctioned parties are also generally prohibited for US persons unless authorised under applicable sanctions rules.
US authorities said the objective is to disrupt the financial, technological and commercial infrastructure that allows cyber fraud networks to operate across borders.
The Xinbi action represents one of the latest attempts to cut off criminal networks from the digital-payment systems, messaging infrastructure and financial intermediaries allegedly used to move and conceal proceeds from cybercrime.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics
Click Here For The Original Source.
