Crypto scam enforcement is moving upstream.
On September 9, the U.S. Department of Justice announced coordinated action against infrastructure tied to Southeast Asian scam operations.
The Scam Center Strike Force said approximately $52 million in cryptocurrency involved in scam money laundering was restrained in one day.
The action targeted Xinbi Guarantee, described by authorities as an illicit marketplace for scam-related services, while a Strike Force team also deployed to Madagascar to assist with the takedown of 13 Chinese-run scam compounds.
The Justice Department said the latest action brings the Strike Force’s total restrained crypto assets to approximately $938 million.
The scale matters.
But the more important development is the target.
Authorities are not only tracing individual victim payments.
They are attacking the business infrastructure that allows scam compounds to operate.
Scam centers operate like supply chains
Large online fraud operations are not simply groups of people sending deceptive messages.
Industrial-scale scam compounds require services.
These can include:
- money laundering;
- payment accounts;
- crypto wallets;
- identity documents;
- telecommunications;
- advertising accounts;
- software;
- data;
- recruitment;
- physical facilities.
When those services can be purchased through specialized marketplaces, fraud becomes easier to scale.
A scam operator does not need to build every capability internally.
It can buy the pieces.
That is why marketplaces such as the one alleged by U.S. authorities matter.
They can function as B2B infrastructure for criminal organizations.
Why crypto is attractive to scam networks
Crypto can move across borders quickly.
It can be transferred outside bank hours.
Wallets can be created without the same physical infrastructure required for conventional banking.
Those properties are useful for legitimate global commerce.
They are also useful for criminals.
But public blockchains create a trade-off for illicit users.
Transactions can be permanently visible.
Once law enforcement links a wallet cluster to criminal activity, years of historical movement can be analyzed.
Crypto therefore combines high transfer efficiency with unusual forensic transparency.
That is why large seizure and restraint actions have become possible.
What “restrained” means
A restraint is not the same as a final forfeiture judgment.
Authorities may obtain legal control or prevent movement of assets while cases proceed.
The distinction matters.
News headlines can make seized or restrained assets sound as if the government has already permanently taken ownership.
Legal processes can continue after the initial action.
For risk analysis, the important operational fact is that the targeted actors can no longer freely use the restrained assets.
That can disrupt the network even before final adjudication.
Why it matters
The enforcement strategy is becoming analogous to infrastructure disruption in cybersecurity.
Instead of chasing every scammer individually, authorities can target common services.
If hundreds of scam operations depend on the same laundering marketplace, payment facilitator or hosting infrastructure, removing that service can create a much larger effect.
This is a force-multiplier strategy.
It also changes the risk model for crypto businesses.
Exchanges, OTC desks and stablecoin issuers can become critical chokepoints.
When law enforcement identifies illicit clusters, regulated intermediaries may be asked to freeze assets, supply records or block counterparties.
Compliance therefore becomes increasingly network-based.
Stablecoins and centralized services can become enforcement chokepoints
A common misconception is that crypto laundering is impossible to stop because blockchains are decentralized.
In practice, many illicit flows eventually touch centralized services.
Criminals may need to:
- convert into stablecoins;
- cash out;
- use exchanges;
- purchase real-world goods;
- pay service providers.
Those points create dependencies.
A decentralized blockchain may not have a central operator, but the broader economy around it does.
This is where sanctions, subpoenas, freezing powers and transaction monitoring become effective.
The global coordination problem
The Justice Department’s announcement also emphasized international deployment.
Scam compounds can operate in one country, target victims in another, recruit workers from a third and launder crypto through services located elsewhere.
No single domestic regulator can address that chain alone.
Enforcement requires:
- international law-enforcement cooperation;
- blockchain analytics;
- exchange records;
- telecom evidence;
- financial-intelligence sharing;
- asset-freezing coordination.
The Madagascar operation illustrates how geographically distributed these cases have become.
Why this matters for exchanges
Exchanges face two distinct risks from industrialized scam networks.
The first is direct compliance risk.
If an exchange repeatedly processes funds from known illicit clusters, regulators may question its transaction-monitoring controls.
The second is reputational risk.
Even when an exchange has not violated law, large flows from scam networks can make users and counterparties question its controls.
That means exchange risk intelligence should monitor not only hacks and solvency but also exposure to sanctioned or law-enforcement-identified wallet clusters.
The victim-protection angle
Infrastructure enforcement can also improve recovery.
If funds are restrained before being fully dispersed or converted, victims may have a better chance of eventual restitution.
But recovery is rarely simple.
Funds may be mixed across victims, jurisdictions and assets.
Legal ownership needs to be established.
Administrative processes can take time.
Therefore, a $52 million restraint should not be interpreted as $52 million immediately returned to victims.
The two figures are not the same.
Risks and counterarguments
Government descriptions of alleged criminal infrastructure are claims made in an enforcement context and may be tested in legal proceedings.
Asset restraint does not prove every transaction associated with a service was criminal.
Large marketplaces can also contain mixed activity.
Coverage should therefore distinguish between:
authorities’ allegations
and
final judicial findings.
It is also important not to portray crypto itself as the cause of scam compounds.
The underlying fraud techniques — impersonation, coercion, investment deception and forced labor — can exist with conventional payment systems as well.
Crypto is a payment and laundering rail within a larger criminal business model.
What to watch next
Monitor:
- forfeiture proceedings involving the $52 million;
- identification of restrained assets and chains;
- actions against Xinbi-linked operators;
- sanctions or designations from Treasury;
- additional exchange freezes;
- victim-restitution plans;
- wallet clusters published by analytics firms;
- enforcement against upstream service providers;
- additional scam-compound takedowns;
- whether total restrained assets surpass $1 billion.
The important shift is strategic.
Authorities are increasingly treating scam networks like industrial systems.
Industrial systems have suppliers, marketplaces, payment rails and chokepoints.
That means the next phase of crypto scam enforcement will not be only about finding bad wallets.
It will be about disabling the infrastructure that makes thousands of bad wallets useful.
FAQ
What did the DOJ announce on September 9?
The Scam Center Strike Force announced coordinated actions against scam infrastructure and said approximately $52 million in crypto linked to scam money laundering was restrained in one day.
What is Xinbi Guarantee?
U.S. authorities described Xinbi as an illicit marketplace providing services used by scam operations.
How much crypto has the Strike Force restrained in total?
The DOJ said the total had reached approximately $938 million.
Was the $52 million already returned to victims?
Not necessarily. Asset restraint and victim restitution are separate legal and administrative steps.
Why target infrastructure instead of individual scammers?
Shared infrastructure can support many scam operations, so disrupting it can have a larger effect than pursuing each scammer separately.