DOJ Strike Force Hits $938 Million in Seized Scam Crypto After $52 Million Xinbi Guarantee Takedown
The DOJ Scam Center Strike Force restrained $52 million in cryptocurrency from the Xinbi Guarantee marketplace in one day, bringing cumulative seizures to approximately $938 million in the fight against industrial-scale crypto fraud.

The Department of Justice announced this week that its Scam Center Strike Force restrained approximately $52 million in cryptocurrency in a single day of coordinated action against the Xinbi Guarantee marketplace, a Chinese-language Telegram-based platform that functioned as an illicit infrastructure service for scam operators across Southeast Asia. The action brings the Strike Force's cumulative total of restrained cryptocurrency to approximately $938 million, a figure that would have been unimaginable in the early years of crypto enforcement when agencies struggled to trace blockchain transactions at all.
The Xinbi Guarantee seizure was not a simple wallet freeze. In a single day, the Strike Force and Treasury Department seized Telegram channels used to operate the marketplace, confiscated two cryptocurrency wallets, and deployed a team to Madagascar to assist local authorities in dismantling thirteen Chinese-run scam compounds. The coordination required across DOJ, Treasury, Secret Service, FBI, and foreign partners represents the most sophisticated crypto enforcement operation yet attempted.
Key Metrics at a Glance
| Metric | Detail |
|---|---|
| Single-Day Restraint | ~$52 million in cryptocurrency |
| Cumulative Strike Force Total | ~$938 million restrained |
| Target | Xinbi Guarantee (Chinese-language scam marketplace) |
| Platform | Telegram channels and cryptocurrency wallets |
| Wallets Confiscated | 2 |
| Foreign Deployment | Madagascar (13 scam compounds) |
| Coordinated Agencies | DOJ, Treasury OFAC, FBI, Secret Service |
| Treasury Designation | Xinbi Guarantee designated as criminal organization |
| Estimated Marketplace Volume | $24 billion (per Treasury estimates) |
What Xinbi Guarantee Actually Did
Xinbi Guarantee was not a scam operation itself. It was the infrastructure layer that made industrial-scale scamming possible. The marketplace operated through Telegram channels, providing services that scam centers needed to function: fake identity documents, bank account access, cryptocurrency wallet creation, and technical support for victim-facing platforms. In the scam ecosystem, Xinbi Guarantee played the role of a criminal AWS, providing the backend services that allowed frontline scammers to focus on victim engagement rather than technical setup.
The Treasury Department's designation of Xinbi Guarantee as a criminal organization, announced simultaneously with the seizure, provides important context for the marketplace's scale. Treasury estimated that the network facilitated approximately $24 billion in transaction volume. This figure, if accurate, suggests that Xinbi Guarantee was not a niche criminal service but a major financial infrastructure provider for the scam industry. The $52 million seized represents only the immediately traceable portion of funds linked to identifiable victims.

The Madagascar Deployment
The most operationally significant element of this action may be the deployment of Strike Force personnel to Madagascar, where they assisted in dismantling thirteen scam compounds. Unlike the domain seizures and cryptocurrency restraints, which are primarily U.S. actions against infrastructure, the Madagascar operation represents direct foreign capacity-building. By embedding U.S. investigators with local law enforcement, the Strike Force is attempting to address the safe harbor problem that has plagued scam center enforcement: the compounds operate in jurisdictions where local authorities lack the technical expertise, resources, or political will to act against them.
Madagascar is not the primary hub for scam centers, which are concentrated in Burma, Cambodia, and Laos. The deployment there suggests that the Strike Force is targeting the secondary and tertiary locations where compound operators have begun relocating as primary hubs face increasing pressure. If successful, this model could be replicated in other African and Southeast Asian jurisdictions where scam centers are expanding.
Comparing Major Crypto Seizure Operations
| Operation | Agency | Amount Seized | Target Type | Year |
|---|---|---|---|---|
| Xinbi Guarantee | DOJ Strike Force | $52M (single day) | Scam marketplace | 2026 |
| Bitfinex Hack | DOJ/IRS-CI | ~$3.6B | Individual hackers | 2022 |
| Silk Road | DOJ/FBI | ~$1B | Darknet marketplace | 2020-2021 |
| PlusToken | Chinese authorities | ~$4B | Ponzi scheme | 2020 |
| Various Strike Force actions | DOJ Strike Force | ~$938M cumulative | Scam centers | 2025-2026 |
This comparison reveals something important about the Strike Force's approach. Previous major seizures typically targeted either individual hackers (Bitfinex) or centralized platforms (Silk Road, PlusToken) where the funds were concentrated in identifiable wallets controlled by a small number of actors. The scam center challenge is structurally different: funds are distributed across thousands of wallets, laundered through multiple jurisdictions, and commingled with legitimate transactions. The $938 million cumulative total represents an extraordinary achievement in tracing and restraint under these conditions.

The $24 Billion Question
Treasury's estimate of $24 billion in Xinbi Guarantee-related transaction volume raises a question that enforcement officials rarely address publicly: what fraction of total scam revenue can realistically be intercepted? If the $52 million seized represents the immediately identifiable portion, and the total facilitated volume is $24 billion, then the seizure rate is approximately 0.2 percent. Even if the $24 billion figure includes non-scam transactions, the interception rate suggests that current capabilities, while impressive in absolute terms, remain modest relative to the scale of the problem.
This is not a criticism of the Strike Force, which has developed capabilities that did not exist three years ago. It is a measurement of the problem's magnitude. The cryptocurrency tracing tools that enable the $938 million cumulative total are operating against a criminal industry that may generate tens of billions of dollars annually. The technology race between law enforcement and criminals is not obviously tilting toward enforcement.
What Happens to Seized Crypto
The practical question for victims is whether any of the $52 million will be returned. The answer, unfortunately, is that victim restitution in cryptocurrency cases moves slowly if at all. Federal asset forfeiture procedures require identification of specific victims, proof of loss, and tracing of funds to specific deposits. When scammers commingle victim funds, convert them through multiple tokens, and launder them through decentralized exchanges, the evidentiary chain required for restitution becomes extraordinarily complex.
The Strike Force's approach of restraining funds quickly, before they can be further laundered, improves restitution prospects. But the legal and technical barriers remain substantial. Victims should understand that a seizure announcement is not a recovery announcement. The funds enter a legal process that can take years to resolve, and in many cases, only a fraction of restrained assets are ultimately returned.

TL;DR
- What: The DOJ Scam Center Strike Force restrained $52 million in cryptocurrency from the Xinbi Guarantee marketplace in one day, bringing cumulative seizures to approximately $938 million
- Why: Xinbi Guarantee functioned as a criminal infrastructure provider for scam centers, with Treasury estimating $24 billion in facilitated transaction volume
- Impact: Coordinated action included Telegram channel seizures, wallet confiscations, and deployment to Madagascar to dismantle 13 scam compounds
- Watch: Whether victim restitution processes can keep pace with seizure volumes, and whether the Strike Force's foreign deployment model expands to primary scam center jurisdictions
Sources
- U.S. Department of Justice - Xinbi Guarantee Seizure
- U.S. Secret Service - Joint Announcement
- CryptoPotato - DOJ Strike Force Coverage
- The Hacker News - Xinbi Guarantee Technical Analysis
- Crypto Times - Treasury Designation and Volume Analysis
- News.Bitcoin - Cumulative Seizure Analysis
Filip Peshko is Senior Opinion Columnist & Blockchain Technology Analyst at TotesTek. He writes about Bitcoin, blockchain technology, crypto markets, Web3 infrastructure, digital asset custody, institutional adoption, and legislation affecting the crypto industry.



