Loading article…
The DOJ’s Scam Center Strike Force restrained $52M in crypto linked to the Xinbi Guarantee marketplace, which facilitated industrial-scale fraud schemes.
The U.S. Department of Justice’s Scam Center Strike Force restrained approximately $52 million in laundered cryptocurrency on September 9, 2026, as part of a coordinated crackdown on the Chinese-language marketplace Xinbi Guarantee [1]. The operation, which also involved the Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioning the platform as a significant transnational criminal organization, marks a major escalation in efforts to dismantle the financial infrastructure supporting global pig-butchering and investment fraud schemes [1, 3].
| At a glance | |
|---|---|
| Assets restrained | $52 million |
| Date of action | September 9, 2026 |
| Cumulative seizures | $938 million |
| Primary catalyst | DOJ and OFAC enforcement action |
Xinbi Guarantee operated primarily through Telegram, functioning as a centralized hub where vendors advertised services including the creation of fraudulent investment websites, money laundering, and the recruitment of forced labor for scam compounds [2, 3]. Prosecutors allege the platform held vendor payments in escrow, a mechanism that allowed investigators to trace victim funds to specific wallet addresses [3]. During the September 9 operation, authorities seized two wallets containing roughly $12 million and sought restraint orders against 47 additional wallets connected to the network [2, 3].
The enforcement action extends beyond the digital marketplace. Simultaneously, a two-week operation in Madagascar resulted in the dismantling of 13 Chinese-run scam compounds and the arrest of approximately 400 to 500 individuals [1, 3]. These compounds are accused of using trafficked labor to execute "pig butchering" scams, where perpetrators cultivate long-term relationships with victims to solicit investments into fake platforms [1]. The Treasury Department also sanctioned Singapore-based SafeW Technology and Cambodia-based Anwen Technology, alleging they provided the technical and financial architecture—including the XinbiPay wallet—that allowed the marketplace to scale [2].
The $52 million restraint brings the Strike Force’s cumulative total of seized or frozen assets to $938 million, a figure reached in less than one year of operations [1, 3]. The DOJ credited stablecoin issuer Tether with assisting in the investigation, noting that the company cooperated to identify and lock down relevant wallets [1, 2]. This collaboration highlights a shift in law enforcement’s technical capacity to coordinate with private-sector firms to execute restraint orders in compressed timeframes [1].
Despite the scale of this intervention, the platform has proven resilient in the past. The UK government previously sanctioned Xinbi in March 2026, yet the group continued operations by migrating to new Telegram channels [3]. Estimates from Chainalysis suggest the platform processed nearly $20 billion in crypto between 2021 and 2025, while the Treasury Department reports that Xinbi has handled over $24 billion in crypto and fiat transactions since 2022 [2, 3].
The effectiveness of this strike force will be measured by its ability to disrupt the "industrial-scale" service providers that allow scam networks to function, rather than just individual operators. The open question remains whether these coordinated sanctions can permanently degrade the platform's utility or if the underlying criminal infrastructure will simply pivot to new, less-regulated service providers.
Coverage is mostly measured — 216 of 218 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Sep 14, 2026 · How we report
As of 14 September 2026, the Peru Ministry of Economy and Finance reported that its official X account was compromised by attackers who used the platform to promote a fraudulent token called $HYLO. The ministry confirmed the posts were unauthorized and stated that no financial losses were reported in connection with the incident.
The Revolut data disclosure, reported in September 2026, involved the release of customer full names, birth dates, occupations, postal addresses, email addresses, and telephone numbers. Additionally, the impersonator obtained copies of passports or driving licenses, verification selfies, IBANs, and complete Bitcoin transaction histories.
MetaMask utilizes AI-powered security partners like Blockaid to analyze websites, social feeds, and on-chain bytecode to identify phishing and malicious behavior in real time. The wallet also employs Added Protection, a feature that automatically reverts transactions that do not match their previews, and provides warnings for lookalike addresses and first-time recipients.
Scammers exploit government accounts because these platforms command high levels of public trust, which can be used to legitimize fraudulent schemes. By posting on official channels, perpetrators can more effectively use urgency—such as fake token launch dates—to bypass the critical thinking of potential victims.