USDT has become a settlement layer for organized crime networks operating across Southeast Asia, with more than 3.4 billion USDT flowing into addresses linked to illicit “guarantee platforms” during the first half of 2026, according to blockchain security firm Bitrace. The firm said more than 90% of that inflow was associated with Xinbi Guarantee, one of several platforms that continued operating after Tudou Guarantee, a major service linked to the Huilwang group, shut down earlier this year.
Bitrace’s research portrays these platforms as infrastructure for a criminal supply chain rather than simple payment channels. Public chat groups connect vendors offering trafficked workers, stolen personal data, scam software, call-relay services and laundering routes with operators running online fraud and illegal gambling schemes. USDT is used to pay suppliers, hold funds in escrow-like arrangements and move proceeds through cross-border networks.
The model gives criminal groups a shared settlement asset after tighter banking controls made direct transfers more difficult. A stablecoin transfer can settle between parties in different jurisdictions without relying on a conventional correspondent-bank chain, while guarantee platforms attempt to reduce the risk that anonymous counterparties will refuse delivery or disappear with payment.
Guarantee platforms link specialized criminal services
Bitrace described guarantee platforms as public-group marketplaces with entry checks, deposits and recognizable branding. They function as brokers between sellers and buyers, while also holding USDT until the parties agree a transaction has been completed.
The platforms serve actors at different stages of an operation. Upstream providers sell recruitment services, databases, scripts and software. Fraud and gambling operators buy those products to establish scam operations. Downstream services help convert stolen bank funds into USDT or route crypto payments through intermediaries.
This structure resembles an outsourced commercial market, where a fraud group does not need to maintain its own recruitment network, data-access contacts, development team and laundering operation. Instead, it can purchase each component separately, with USDT providing a common payment method across the chain.
Bitrace said the closure of Tudou Guarantee did not end this activity. The concentration of reported inflows at Xinbi Guarantee suggests that business shifted toward competing platforms rather than disappearing, creating another large hub for transactions involving a broad range of illicit vendors.
Trafficking and stolen data offered as paid services
The report identifies human trafficking as one of the entry points for staffing scam compounds. Recruitment, transport and delivery are treated as commercial services, with the person being transferred effectively priced as an item in a transaction.
In one Telegram channel described as a direct-hire group for an unnamed organization, Bitrace found membership approaching 5,000. Listings ranged from several thousand USDT to more than 10,000 USDT, depending on the person and the requested terms.
The research outlined three ways these transactions are settled. A buyer may pay a wallet controlled by a seller directly after delivery. Parties may use a guarantee platform that holds the USDT and releases it after the transfer, charging a fee for its role. Trafficking merchants may also resell people between themselves, again settling the transaction in USDT.
After workers are obtained, operators can acquire personal information through a separate underground service known as “record checks,” Bitrace said. Providers accept USDT and use contacts with access to systems associated with police, courts, banks, logistics firms or telecommunications operators.
The information advertised in these markets can include household registration records, marital status, education, medical details, assets and travel-related data. One public Telegram group cited by Bitrace had more than 3,000 members and promoted searches involving individuals, companies and vehicles. Its listings included corporate invoices, payroll records, bank statements, property holdings and highway travel data.
Transaction records reviewed by Bitrace showed individual orders ranging from tens of USDT to several hundred USDT. Vendors claimed delivery within one or two days and used wording that promised authenticity while stopping short of guaranteeing complete results.
Scam tools are sold as modular products
Bitrace found that many fraud operations buy technical tools instead of building them internally. In an “app development/platform setup” group, sellers advertised cloned trading-app source code and multilingual decentralized application templates.
The advertised products used common web-development stacks, including React 18 paired with a Java backend and Vue-based front ends. Vendors promoted menus and functions modeled on legitimate financial platforms, such as spot trading, options, perpetual contracts, delivery products, U-margined instruments and copy trading.
These systems can be paired with deposit routes and wallet addresses controlled by the operators, Bitrace said. Guarantee platforms can then act as both intermediary and custodian for the software sale. The use of familiar market charts, asset categories and trading controls lowers the technical burden of launching a scam site that appears credible to a target.
Bitrace also described a call-relay service known as “phone mouth,” designed to make an overseas caller seem local. The arrangement uses two phones connected by an audio cable: one connects to the overseas caller through an internet application, while the other calls the target with a domestic SIM card.
A group offering the service listed a 300-USDT base price per team, plus charges of 5 USDT for 30 minutes, 10 USDT for 60 minutes and 15 USDT for 100 minutes, according to the report. Group rules required video verification and a minimum 20-minute call for settlement.
Social-media outreach, online games and internet advertising feed leads into these operations, followed by sustained chat conversations intended to convert targets. Bitrace said secondary markets also sell photographs, scripts and persona materials, while AI-generated text and images make it easier to operate large volumes of deceptive accounts.
Laundering routes return stolen funds to USDT
The final stage is often described in underground markets as “card receive, convert back to U,” referring to the conversion of stolen fiat currency into USDT. Bitrace said a first layer of intermediaries receives bank transfers directly, rapidly purchases USDT, sends an agreed portion back to upstream operators and retains the spread as compensation.
A second layer can involve anonymous OTC-style merchants that pass the funds through additional wallets or counterparties. By the end of the process, a payment sent by a victim through the banking system may have been converted into USDT through multiple intermediaries, complicating efforts to identify the final beneficiary.
Bitrace illustrated the consequences through two investigation templates. One involved a “mining pool arbitrage” fraud in which bots impersonated official community groups and persuaded targets to send ETH to a contract address in exchange for supposedly high BNB returns. The returned BNB was counterfeit, according to the firm, while operators retained the deposited ETH.
Bitrace said it assisted victims of that scheme in 2022 whose losses ranged from tens of thousands to hundreds of thousands of dollars. Some victims were still seeking updates in November 2025, but the case ended without asset recovery because of the time elapsed and the difficulty of tracing the funds.
A second case involved a fraudulent decentralized application designed to resemble the Orca DEX interface. The victim deposited several thousand USDT into a site branded “orcaen” after being offered high returns, then encountered blocked withdrawals and a purported customer-service process.
The fake platform displayed BTC and ETH prices, candlestick charts, “buy up” and “buy down” controls, and sections for crypto, foreign exchange, stocks, precious metals and energy. Bitrace traced the victim’s funds into Huilwang Pay, which it linked to laundering activity under the Prince Group. Once funds entered that network, the firm said, recovery became substantially more difficult.
Want a deeper look at stablecoin risks and safeguards? Read this guide on Asian stablecoin adoption to understand both innovation and abuse.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
