Xinbi Guarantee: The $8.4B USDT Marketplace Your AML Controls Must Flag
A Chinese-language marketplace operating through Telegram has processed at least $8.4 billion in USDT since 2022, selling money-laundering services, stolen personal data, and scam infrastructure to fraudsters across South East Asia, while also handling proceeds linked to North Korean state hackers. Blockchain analytics firm Elliptic published research on 8 September 2026 identifying Xinbi Guarantee as the second-largest illicit online market ever recorded. For accounting firms, CFOs, and compliance officers whose clients or businesses interact with stablecoin flows, that ranking is not an academic curiosity. It is a counterparty-risk event that demands immediate action. Any robust crypto accounting software or AML screening workflow must now incorporate the address clusters Elliptic has identified.
What Xinbi Guarantee Is and How It Operates
Xinbi Guarantee is a Telegram-based marketplace conducting all business in Chinese. It had approximately 233,000 registered users at the time of Elliptic's report, up from 119,000 in August 2024, a near-doubling in roughly twelve months. Every transaction on the platform is settled in Tether's USDT stablecoin, making the entire flow theoretically traceable on-chain, yet vast in scale.
Merchant Categories and Service Offerings
Merchants on the platform fall into nine categories. The largest share of transaction volume flows through four distinct money-laundering service categories. Vendors openly advertise which types of criminal proceeds they will accept, using terminology such as "material" for dirty funds and "white capital" for laundered output. Many state explicitly that they handle the proceeds of pig-butchering scams, a category of long-con investment fraud that has caused billions in losses globally, particularly targeting victims in the United States, Europe, and East Asia.
Beyond laundering, the marketplace lists vendors selling Starlink satellite internet equipment (widely used in remote scam-compound operations), databases of stolen personal contact information, and counterfeit identity documents. Elliptic's report also flagged a smaller number of vendors offering entirely separate illicit services, including stalking and intimidation, illegal surrogacy arrangements, and apparent sex-trafficking listings involving minors. These categories are noted here because they signal the breadth of criminal activity the platform facilitates, not because they carry a distinct accounting treatment.
Growth Trajectory and Scale
The fourth quarter of 2024 was the first period in which Xinbi's inflows exceeded $1 billion in a single quarter. Elliptic's figures are described as a lower bound, since they reflect identified addresses only. The $8.4 billion total since 2022 places Xinbi ahead of every Tor-based darknet market ever operated, including those that dominated illicit online trade for more than a decade. Telegram-based guarantee marketplaces have, in Elliptic's assessment, rendered the old darknet model obsolete in terms of sheer volume.
The Colorado Incorporation: A Regulatory Red Flag
One of the most operationally significant details in the Elliptic report is the corporate structure. Xinbi's own website described the entity as an "investment and capital guarantee group company" and stated it operated as a Colorado-registered corporation. The Colorado corporate register confirmed that "Xinbi Co., Ltd" was incorporated in August 2022, with a principal office listed in Aurora, Colorado. By January 2025, the Colorado Secretary of State had updated its status to "Delinquent" for failure to file a required periodic report.
Why Corporate Registration Matters for Compliance Teams
The Colorado registration creates a direct US nexus. Under the Bank Secrecy Act and FinCEN's virtual currency guidance, any financial institution or money services business that knowingly or unknowingly processes funds originating from or destined for a US-registered entity engaged in money laundering faces Suspicious Activity Report (SAR) filing obligations and potential civil or criminal liability. A delinquent corporate status does not dissolve the legal entity or erase the nexus; it simply means the company failed a state administrative requirement. The underlying registration, and therefore the US jurisdictional hook, remains a matter of public record.
For accounting firms advising US-regulated clients, this is material. A client exchange or wallet provider that has processed USDT through addresses associated with Xinbi may have unknowingly handled funds connected to a US-registered money-laundering operation. That exposure needs to be assessed, documented, and disclosed where required. See also FinCEN's $13 billion crypto scam network analysis for the broader regulatory context in which this discovery sits.
North Korea Connections and the WazirX Link
The report documents a specific, traceable instance of Xinbi Guarantee handling proceeds from a state-level cyber heist. In July 2024, approximately $235 million was stolen from the Indian cryptocurrency exchange WazirX in a security breach that Elliptic and other researchers attributed to actors linked to the Democratic People's Republic of Korea (DPRK). On 12 November 2024, roughly $220,000 in USDT traceable to that theft was sent to a Xinbi Guarantee address across nine separate transactions, indicating that at least one vendor on the platform was engaged to help launder those stolen funds.
OFAC Exposure and Sanctions Screening Obligations
DPRK-linked crypto activity sits squarely within the US Office of Foreign Assets Control (OFAC) sanctions framework. Facilitating, processing, or receiving funds that can be traced to DPRK-affiliated actors, even unknowingly, constitutes a potential sanctions violation. The standard is strict liability for certain OFAC prohibitions; intent is not always a defence. Any firm whose digital asset accounting software or transaction-monitoring system has not been updated to screen against DPRK-associated address clusters since the WazirX hack in mid-2024 has a gap that needs closing immediately.
Stablecoin issuers face an additional layer of obligation. Tether has previously frozen addresses at the request of law enforcement. The fact that $8.4 billion in USDT flowed through Xinbi-associated addresses without triggering complete interdiction raises questions that compliance officers at any firm accepting USDT should be prepared to address in their next audit or regulatory examination.
Accounting and Financial Statement Implications
Provisions, Contingent Liabilities, and Impairment
For firms that have processed transactions touching Xinbi-linked addresses, the accounting question is whether a contingent liability exists. Under both US GAAP (ASC 450) and IFRS (IAS 37), a provision is required where an outflow is probable and can be reliably estimated. Regulatory fines, disgorgement orders, and legal costs stemming from AML failures can qualify. If legal counsel advises that enforcement action is more likely than not, a provision needs to appear on the balance sheet, not just in the notes.
Separately, any digital assets held on-chain that are subsequently frozen by a stablecoin issuer or seized by law enforcement need to be written down or derecognised. A frozen USDT balance is not equivalent to an unrestricted cash equivalent. Under FASB's updated fair-value guidance for digital assets (ASU 2023-08), restricted or legally encumbered holdings should not be carried at the same level-1 fair value as freely transferable tokens. Firms need to reassess whether their crypto bookkeeping software is capturing these restrictions at the transaction level, or whether the restriction only surfaces at year-end when it may be too late to avoid a restatement.
Client Due Diligence and the Audit Engagement
Accounting firms conducting audits of virtual asset service providers (VASPs) or crypto-native businesses need to treat the Xinbi disclosure as a prompt to revisit management's counterparty screening procedures. An auditor asking whether the client has screened transaction histories against Xinbi-associated addresses is not overreaching; it is part of evaluating whether the client's AML controls are designed and operating effectively. Where controls are absent or untested, the risk of material misstatement due to fraud or regulatory non-compliance rises, and audit procedures need to be extended accordingly.
Understanding how stablecoin flows affect your digital asset accounting software is relevant here: the same rails that carry legitimate USDT payments are the ones Xinbi's vendors use, and distinguishing clean from tainted flows requires address-level screening, not just counterparty-name checks.
Practical Steps for Compliance and Finance Teams
Immediate Actions
First, obtain the published list of Xinbi Guarantee-associated addresses from your blockchain analytics provider and run a historical look-back against your transaction records. The scope should cover at minimum all USDT transactions since August 2022, when Xinbi was incorporated. Document this screening exercise in your AML workpapers with a date stamp.
Second, assess whether any identified matches meet your SAR filing threshold. In the US, a SAR is required where a transaction involves at least $5,000 and the firm knows, suspects, or has reason to suspect that the funds derive from illegal activity. The $220,000 WazirX-linked USDT transfer cited in the report is a concrete precedent for the type of transaction that would meet this threshold.
Third, review your sanctions screening configuration. DPRK-linked address clusters from the WazirX hack should already be in your screening lists. If they are not, that is a control deficiency that needs to be remediated and documented before your next regulatory examination or audit.
Medium-Term Controls
Firms should consider whether their existing crypto accounting software integrates address-level risk scoring in real time, or whether AML screening is a separate, periodic process. The gap between transaction execution and screening is where exposure accumulates. Guarantee marketplaces like Xinbi and its larger peer Huione operate at high velocity; a quarterly look-back is not sufficient for a business processing significant daily USDT volumes.
Engagement letters and client onboarding questionnaires for accounting and advisory mandates should be updated to ask specifically about Telegram-based marketplace exposure. The Colorado incorporation of Xinbi means that a client might legitimately have had a business relationship with what appeared to be a US corporate entity, creating exactly the kind of inadvertent exposure that due diligence is designed to surface.
Elliptic notes that it is tracking approximately thirty similar Telegram-based marketplaces beyond Xinbi and Huione. The compliance infrastructure built to address Xinbi should be designed as a repeatable framework, not a one-off remediation exercise. The broader ecosystem of guarantee marketplaces collectively represents a China-based underground banking system built on stablecoins, and the regulatory response is likely to intensify.
Frequently Asked Questions
Does a firm face OFAC liability if it processed USDT that later turned out to pass through a Xinbi-linked address?
OFAC's strict-liability standard means that processing funds connected to sanctioned actors or programmes, such as DPRK-linked cyber theft proceeds, can constitute a violation even without intent. The key mitigant is a robust, documented screening programme. Firms that ran contemporaneous checks against available watchlists and found no match have a stronger compliance defence than those with no screening records at all. Any firm that discovers a historical match should consult sanctions counsel promptly and consider whether a voluntary self-disclosure is appropriate.
How should a USDT balance frozen by a stablecoin issuer be recorded in financial statements?
A frozen balance is no longer a freely transferable asset. Under ASU 2023-08 (FASB) or IAS 38/IAS 37 principles (IFRS), the carrying value should reflect the economic reality of restricted access. In practice, this typically means reclassifying the balance out of current liquid assets, applying a fair-value adjustment to reflect the restriction, and disclosing the circumstances. If recovery is uncertain, a full write-down may be required. Auditors will expect evidence that management has assessed recoverability and that the accounting treatment is consistent with the contractual terms of the freeze.
Is the Colorado incorporation of Xinbi enough to establish US jurisdiction for enforcement purposes?
Registration in a US state creates a domestic legal nexus. FinCEN, the DOJ, and OFAC have each used corporate registration, combined with US-dollar-denominated transactions, as grounds for asserting jurisdiction over entities involved in money laundering. The delinquent filing status noted in the Colorado register does not dissolve the entity or remove the nexus; it reflects a state administrative failure. US and international authorities could pursue the principals through the registered entity regardless of its administrative status.
What SAR obligations apply if a firm identifies a transaction linked to a guarantee marketplace like Xinbi?
In the US, financial institutions and money services businesses must file a SAR within 30 days of detecting a transaction of $5,000 or more that involves suspected illegal activity, including money laundering. The SAR narrative should describe the specific transaction, the basis for suspicion (for example, a blockchain analytics match to a known illicit address cluster), and any steps taken to investigate. Firms should not tip off the subject. Retention of supporting documentation, including the analytics output, for at least five years is required under BSA recordkeeping rules.
Should audit firms update their risk assessments for VASP clients in light of this disclosure?
Yes. The Elliptic disclosure is a relevant event that directly informs the fraud and AML risk landscape for any VASP audit. Auditors should consider whether the client's transaction-monitoring controls would have detected flows to Xinbi-associated addresses, whether management has performed a look-back, and whether the financial statements require additional disclosures relating to contingent liabilities. Failure to update the audit risk assessment in response to a major public disclosure of an illicit marketplace of this scale could itself be a quality-control issue.
Source: Elliptic
