Skip to content
RiskTemplates · The Daily Brief Tuesday, September 15, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Compliance Strategy

OFAC Just Sanctioned the $36 Billion Scam Factory. Here's What Your Compliance Program Needs to Find Next.

On September 9, 2026, Treasury sanctioned Xinbi Guarantee — a Chinese-language escrow marketplace that moved $36B+ in illicit funds via TRON USDT. Here's what financial institutions need to verify now.

By Rebecca Leung · September 11, 2026 ·
Table of Contents

TL;DR

  • On September 9, 2026, OFAC designated Xinbi Guarantee — a $36B+ Chinese-language scam marketplace operating on TRON — as a Transnational Criminal Organization alongside its wallet provider and messaging app.
  • The designation added 52 TRON cryptocurrency addresses to the SDN List. Any U.S. financial institution that processes transactions involving these addresses or entities is in violation.
  • DOJ’s Scam Center Strike Force coordinated the action, seizing $52M in cryptocurrency. The same DOJ unit has active investigations across the scam center ecosystem — more designations are likely.
  • This is not just a crypto-firm problem. Payment processors, MSBs, banks with crypto-adjacent customers, and any institution with USDT/TRON settlement exposure needs to verify screening coverage now.

The $36 Billion Scam Factory Just Got Named

On September 9, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control made one of the most significant sanctions designations in the history of crypto-related financial crime enforcement.

OFAC designated Xinbi Guarantee as a Transnational Criminal Organization (TCO) — a Chinese-language escrow marketplace that had, by TRM Labs analysis, processed more than $36 billion in transactions since approximately 2022. The platform operated primarily on the TRON blockchain, settling in USDT (Tether). Its business model: connect scam syndicates with vendors selling stolen personal data, fake identity documents, deepfake tools, and cash-out services. Escrow guaranteed that both sides of a transaction held up their end of the deal.

Think of it as an Amazon-with-escrow for the fraud supply chain. The marketplace served pig-butchering operations, romance scam syndicates, investment fraud networks, and money laundering services. Its customers were criminal operations targeting Americans. Its vendors provided the infrastructure to make those operations work.

The designation came alongside two supporting entities: Anwen Technology, which operated the XinbiPay/NewPay cryptocurrency wallet used for transactions, and SafeW Technology, which operated the SafeW encrypted messaging application that coordinated deals. All three entities are now on the SDN List. So are 52 specific TRON wallet addresses.

The action was coordinated with the Department of Justice’s Scam Center Strike Force (SCSF), which seized or restrained more than $52 million in cryptocurrency across the Xinbi network.

This is the enforcement action your transaction monitoring program needs to respond to today. Here’s what that means in practice.


What the Xinbi Designation Actually Means for Your Compliance Team

OFAC designations are black-and-white obligations. U.S. persons — including financial institutions of every type — are prohibited from:

  • Processing transactions involving any of the 52 designated TRON wallet addresses
  • Conducting business with Xinbi Guarantee, Anwen Technology, or SafeW Technology
  • Facilitating any transfer that benefits a designated party, even indirectly

The 10-business-day blocking report requirement kicks in when you identify and block a transaction. The unblocking report requirement applies if blocked assets are later released. These are non-discretionary.

What makes this designation operationally significant isn’t the legal obligation — it’s the screening gap it exposes. Most traditional financial institution sanctions programs were built around SWIFT and wire transfer screening. TRON blockchain addresses are a different infrastructure layer. If your AML/sanctions platform doesn’t cover TRON wallet address screening, or if your crypto-adjacent customers’ transactions aren’t running through your SDN screening workflow, you have exposure.

And if you’re wondering whether this applies to you — consider who is in your customer base. Payment processors serve merchants who accept USDT. Virtual currency exchangers settle on TRON. Neobanks and fintechs that offer crypto on-ramps and off-ramps touch this infrastructure. If any of that is part of your book of business, this designation is relevant to your program.


The Five Screening Questions Your Compliance Team Needs to Answer Now

1. Does your sanctions screening platform cover TRON wallet addresses?

The 52 addresses added to the SDN List are all on the TRON blockchain. If your AML platform screens wire instructions and ACH originator/beneficiary names but doesn’t have a blockchain address screening module, those 52 addresses are invisible to your controls.

Run your vendor’s coverage inventory. If TRON is not in scope, this is a gap that requires either a platform update, a supplemental vendor, or documented compensating controls while you remediate.

2. When is your SDN List refresh cycle?

OFAC publishes SDN List updates with no advance notice. For time-sensitive designations — especially where DOJ has simultaneously announced seizures and criminal charges — the window between designation and attempted transaction is short.

Best practice is a 24-hour maximum refresh cycle. If you’re refreshing weekly or ad hoc, that’s a documented gap that will come up in an exam.

3. Do you know which customers have USDT or TRON exposure?

The Xinbi network settled primarily in USDT on TRON. If you have customers who hold USDT, transact in USDT, or use TRON-based wallets, you need a process to cross-reference those customers’ known wallet addresses against the SDN list.

This is harder than it sounds. Many institutions with indirect crypto exposure — payment processors that transact through third-party crypto infrastructure, fintechs with crypto on-ramps managed by a vendor — don’t have direct visibility into the wallet-level transactions flowing through their systems. That’s a third-party risk question as much as a screening question.

4. Does your correspondent banking or MSB program include TRON exposure in due diligence?

Xinbi’s customer base was global — primarily operating out of Southeast Asia, with a vendor network spread across multiple jurisdictions. If you provide correspondent banking services to foreign financial institutions or maintain MSB relationships with virtual currency exchangers, you need to understand whether any of those relationships have TRON USDT settlement exposure.

The September 9 designation is the event. An examiner asking “did you update your correspondent due diligence” six months from now is the follow-on.

5. Have you updated your scam center typology training?

The DOJ Scam Center Strike Force has been building cases across the pig-butchering ecosystem since 2024. Xinbi is one of the most significant enforcement actions in that effort — but it is not the last. FinCEN’s September 2026 Scam Center Alert documented specific transaction typologies for scam center-related activity. Your transaction monitoring team should have those patterns in their detection library.


The SAR Trigger This Designation Creates

Here’s where the compliance strategy question gets practical.

A direct SDN match — a customer transaction involving one of the 52 TRON addresses — is not just a SAR obligation. It’s a potential OFAC violation. Block the transaction, file the blocking report, escalate to your sanctions officer and legal counsel. That’s the mechanical response.

But most institutions won’t see direct SDN matches. They’ll see transactions that look like scam center activity without a clean blockchain-address hit. A customer receiving small, frequent payments from multiple overseas sources. A customer converting USDT at scale with no apparent commercial purpose. A business account processing payments tagged to Southeast Asian gambling or “investment” platforms.

These are SAR trigger events under FinCEN’s scam center typology guidance — independent of whether any specific TRON address is on the SDN list. The Xinbi designation gives you a new reference point for understanding the scale of the ecosystem you’re monitoring for.

The practical compliance question: do your scam center monitoring rules match the volume and typology profile that a $36 billion marketplace creates? Or are your thresholds set for the small-dollar crypto transaction you saw three years ago?


Where Most Transaction Monitoring Programs Miss the Mark

This designation reveals a structural problem that’s been building across financial services for several years. The traditional AML program — built for cash, wire transfers, and check fraud — has been patched to handle crypto. But it wasn’t redesigned for it.

The result is a compliance program that screens SWIFT messages with sub-24-hour SDN refresh but runs blockchain address checks quarterly. Or screens for known wallet addresses but doesn’t have TRON in scope. Or has excellent scam center detection rules for fiat but no transaction monitoring for USDT settlement patterns.

The OFAC Exodus wallet designation in July 2026 was the same structural test — a privacy-enhancing cryptocurrency wallet sanctioned with specific addresses added to the SDN List. The institutions that handled that designation well were the ones that had already built blockchain screening into their compliance architecture.

Xinbi is a significantly larger enforcement action with more direct financial crime implications for traditional financial services. If you didn’t build blockchain screening after Exodus, you need to build it now.


What the DOJ Scam Center Strike Force Action Tells You About What’s Coming

The SCSF was stood up specifically to dismantle the transnational infrastructure of cyber-enabled fraud targeting Americans. Xinbi Guarantee is one of the largest actions it has taken — but the Strike Force has made clear that the ecosystem is wider than a single marketplace.

The DOJ’s coordination with State Department (which designated Xinbi as a TCO) and OFAC (which added the entities and addresses to the SDN List) reflects an interagency approach that is systematically working through the fraud supply chain. Vendors that sold services through Xinbi. Platforms that hosted similar marketplaces. Wallet providers that settled their transactions.

For financial institutions, the practical implication is that more designations are likely in the coming months. An institution that builds its screening program around the Xinbi designation — TRON coverage, scam center typologies, crypto-adjacent customer due diligence — will be better positioned to handle the next action.

The institutions that read the Xinbi press release and file it are the ones that will get the call from their examiner twelve months from now asking why they didn’t update their program.


So What? Five Things to Put on Your Compliance Agenda Now

1. Verify TRON coverage in your screening platform. Run a capability check with your AML/sanctions vendor. Confirm that TRON blockchain addresses are within scope for SDN screening. If not, that’s a documented gap and an open issues item.

2. Check your SDN refresh cadence. If your list refresh is longer than 24 hours, document the gap and propose a remediation timeline. Same-day refresh is the standard for institutions with any crypto exposure.

3. Pull your crypto-adjacent customer list. Identify customers with USDT or TRON exposure and verify their known wallet addresses against the SDN List. This is both a one-time remediation action for the Xinbi designation and an ongoing process you should have in place.

4. Update your scam center transaction monitoring rules. Cross-reference your current rules against FinCEN’s September 2026 scam center guidance and the Xinbi operation typology. TRON USDT settlement patterns, escrow-payment structures, and rapid conversion activity are the behavioral signatures to add.

5. Brief your correspondent banking and MSB monitoring teams. If you have virtual currency exchanger relationships or correspondent banking relationships with TRON-active institutions, those relationships need an updated screening review in the context of the Xinbi designation.

You can track these as open items in a structured compliance issues log — it gives you a dated record that you identified the gap, assigned an owner, and drove it to closure. If an examiner asks how you responded to Xinbi, that’s the answer.


The Compliance Strategy Question

Xinbi Guarantee is a landmark enforcement action in the history of scam-center-related financial crime. A $36 billion marketplace. Escrow infrastructure. Deep integration with the pig-butchering supply chain.

The compliance strategy question it raises isn’t new: how do you build a program that detects fraud infrastructure you didn’t know existed?

The answer is boring and practical. TRON coverage in your screening platform. Fast SDN refresh. Scam center typologies in your transaction monitoring rules. Crypto-adjacent customer due diligence that reflects what’s actually on the SDN list.

The institutions that do this work now aren’t the ones that react to enforcement. They’re the ones that use each major designation to pressure-test whether their controls are keeping pace with the threat.


For help tracking open compliance program gaps — including sanctions screening gaps identified after major OFAC designations — the Issues Management Tracker & Template gives you a structured Excel system for logging, assigning, and driving issues to documented closure. Built for financial services compliance teams managing 10–200 open items.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did OFAC actually sanction when it designated Xinbi Guarantee on September 9, 2026?
OFAC designated Xinbi Guarantee as a Transnational Criminal Organization (TCO) under Executive Order 13581, alongside two supporting entities: Anwen Technology (the XinbiPay/NewPay cryptocurrency wallet) and SafeW Technology (the SafeW messaging app used to facilitate transactions). OFAC added 52 cryptocurrency wallet addresses — all on the TRON blockchain — to the Specially Designated Nationals (SDN) List. U.S. persons are prohibited from conducting transactions with these entities unless licensed or exempt.
How large was Xinbi Guarantee's operation?
According to TRM Labs blockchain analysis, Xinbi Guarantee processed more than $36 billion in cryptocurrency transactions since approximately 2022, primarily settling in USDT (Tether) on the TRON blockchain. The DOJ's Scam Center Strike Force seized or restrained more than $52 million in cryptocurrency across Xinbi and its vendor network as part of coordinated enforcement action.
What types of transactions ran through Xinbi Guarantee's marketplace?
Xinbi ran an escrow-backed marketplace connecting scam syndicates with vendors selling stolen data, fraudulent identity documents, deepfake tools, and cash-out services. The marketplace primarily settled transactions in USDT on TRON. The platform was used extensively to support cyber scams, fraud, and money laundering operations targeting American consumers.
Does this OFAC designation affect traditional financial institutions or only crypto firms?
Both. Any U.S. financial institution — bank, credit union, payment processor, or money services business — that processes transactions involving the 52 designated TRON wallet addresses, Anwen Technology, SafeW Technology, or Xinbi Guarantee itself violates OFAC regulations. Traditional institutions with crypto-adjacent customers, USDT settlement exposure, or payment rails that touch TRON-based transactions need to verify their screening coverage.
What SAR obligation does this designation create?
If a U.S. financial institution identifies a transaction involving a designated entity or wallet and blocks or rejects it, the institution must file a blocking report with OFAC within 10 business days. It must also file an unblocking report if blocked funds are released. Separately, any transaction involving activity consistent with scam center operations — even without a direct SDN match — should be evaluated for SAR filing under the Bank Secrecy Act. FinCEN issued guidance on scam center transaction typologies in September 2026 that applies here.
What is the NIST-aligned safe harbor for compliance programs responding to this designation?
OFAC's Economic Sanctions Enforcement Guidelines provide that voluntary self-disclosure, a robust compliance program, and prompt corrective action are mitigating factors in any enforcement proceeding. Institutions should document that their sanctions screening tools cover TRON blockchain addresses, that SDN list updates are applied within 24 hours of OFAC publication, and that staff responsible for crypto or USDT transactions have received updated training on the Xinbi designation.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

◆ Keep reading

Related posts.

Compliance Strategy

Your BSA/AML Compliance Program Can't Scale in Arrears: What the CFSB Consent Order Means for Every Fintech

In April 2026, the OCC issued a consent order against Community Federal Savings Bank — sponsor bank for Wise, Crypto.com, Airwallex, ChipperCash, and LemFi — for BSA/AML compliance failures so severe that its alert system was auto-closing a very high percentage of suspicious-activity flags. Here's what that means for the fintechs riding those rails, and what every fintech compliance team can learn about scaling a BSA program that doesn't collapse under its own transaction volume.

Sep 14, 2026

Compliance Strategy

The CFPB Dropped Disparate Impact. State AGs Didn't.

Five months after the CFPB eliminated disparate impact liability under ECOA, state attorneys general are filling the gap with coordinated enforcement targeting AI lending models, pricing algorithms, and redlining — and they're better organized than they've ever been.

Sep 12, 2026

Compliance Strategy

DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.

The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.

Sep 9, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.