A second Guarantee marketplace falls
On September 9, 2026, the Treasury Department's Office of Foreign Assets Control designated Xinbi Guarantee — a Chinese-language, Telegram-based marketplace — as a transnational criminal organization under Executive Order 13581, as amended, and President Trump's March 6, 2026 order on "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens" (Treasury press release). Two supporting firms were sanctioned alongside it: Cambodia-based Anwen Technology, developer of the XinbiPay wallet, and Singapore-based SafeW Technology, developer of the SafeW messaging app.
The same day, DOJ's Scam Center Strike Force and the Secret Service executed a judicially authorized seizure — a warrant signed September 7 by a federal court in Washington — taking down Xinbi's Telegram channels and freezing $52.8 million across 52 crypto wallets. Blockchain analytics firm Elliptic, which supported the seizure, estimates Xinbi has processed at least $24 billion since launching in 2022, making it the second-largest illicit online marketplace ever recorded, trailing only Huione Guarantee's $31 billion before that Cambodian platform shut down in May 2025 (Elliptic). The action complements the UK's own March 26, 2026 sanctions on Xinbi, underscoring rare US-UK alignment on this file.
What Xinbi actually did
Xinbi was not a scam center itself — it was infrastructure. Operating as an escrow-backed bazaar inside Telegram, it let vendors post crypto deposits so scam-compound operators could trust they'd receive what they paid for: stolen personal data, fake identity documents, deepfake tooling, and money-laundering services. That is precisely the kind of enabling layer — plumbing, not the fraud itself — that a Chinese organized-crime network needs to convert scraped-together "pig butchering" proceeds into usable cash. DOJ's Scam Center Strike Force, launched in November 2025 as a joint effort of the US Attorney's Office for DC, the FBI, the Secret Service, and Treasury, has now restrained roughly $938 million in scam-linked crypto across its operations to date, per contemporaneous reporting on the Xinbi action (The Hacker News) — up from the $700 million-plus reported in the Strike Force's April 2026 update on Southeast Asian scam centers (DOJ press release).
The case for going hard
The strongest argument for this kind of action is straightforward: the scale is not abstract. The FBI's Internet Crime Complaint Center logged $20.9 billion in reported fraud losses for 2025, a 26% jump over 2024, with $7.2 billion of that tied specifically to cryptocurrency investment fraud — the category that includes pig butchering (Techlicious, on the FBI IC3 2025 report). Marketplaces like Xinbi are the reason a scam compound in Cambodia or Myanmar can operate at industrial scale: without an escrow layer connecting laundering vendors to fraud operators, the economics of forced-labor scam centers get much harder. A sanctions-plus-seizure combination — hitting the financial rails and the communication channel simultaneously, backed by a specific judicial warrant rather than a standing surveillance mandate — is about as narrowly tailored as disruptive enforcement gets. It targets a named criminal enterprise with a quantified transaction history, not an entire technology or asset class.
Where proportionality still needs watching
That precision is exactly why this action should be the template, not the floor, for what comes next. The temptation after a win like this is to generalize the tool: broader TCO designations reaching further down the vendor chain, permanent data-sharing arrangements with platforms justified by one successful warrant, or calls to impose KYC mandates on stablecoin transfers broadly rather than on identified bad actors. None of that is on the table yet in the Xinbi action itself, and it shouldn't need to be. The Treasury designation names three specific entities with documented transaction histories; the seizure rested on a signed warrant reviewed by a federal judge, not an administrative subpoena. That is the proportionate model — sanctions and seizures scoped to evidence, not dragnets scoped to a technology.
The harder problem is durability. Xinbi did not emerge in a vacuum — it scaled into the gap Huione Guarantee left when enforcement pressure closed it in May 2025. A marketplace processing $24 billion took over almost exactly where a $31 billion one left off. That succession pattern suggests sanctions against any single Guarantee-style marketplace buy disruption, not resolution, unless paired with the less glamorous work: pressuring Tether and other stablecoin issuers to freeze illicit flows proactively, and pressuring Telegram to enforce its own terms of service against known scam channels before a US warrant forces the point. Treasury and DOJ deserve credit for a well-evidenced, jurisdictionally coordinated strike. The test of whether this approach scales is whether the next Guarantee marketplace takes longer than three months to fill the vacancy.
The bottom line
This is enforcement done the right way: specific targets, a real warrant, quantified harm, and coordination with an allied government rather than unilateral overreach. Policymakers should resist the urge to convert a clean win into a broader regulatory mandate on crypto rails or messaging platforms — the marginal case for that hasn't been made by this action. What has been made is the case that targeted, evidence-based disruption works, and that its durability now depends on upstream compliance from stablecoin issuers and platforms, not on expanding the government's own authorities.