惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threatpost
Jina AI
Jina AI
S
SegmentFault 最新的问题
博客园 - 【当耐特】
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
The Cloudflare Blog
MyScale Blog
MyScale Blog
F
Full Disclosure
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
P
Privacy & Cybersecurity Law Blog
H
Help Net Security
A
Arctic Wolf
T
Tor Project blog
WordPress大学
WordPress大学
Cisco Talos Blog
Cisco Talos Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Project Zero
Project Zero
V2EX - 技术
V2EX - 技术
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
S
Securelist
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
PCI Perspectives
PCI Perspectives
雷峰网
雷峰网
J
Java Code Geeks
G
GRAHAM CLULEY
D
DataBreaches.Net
C
CXSECURITY Database RSS Feed - CXSecurity.com
Attack and Defense Labs
Attack and Defense Labs
美团技术团队
Security Archives - TechRepublic
Security Archives - TechRepublic
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Docker
Cloudbric
Cloudbric
L
LangChain Blog

Security Latest

British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos World Cup Scams Are Getting Harder to Spot A Critical Deadline Is Approaching for Windows and Linux Security Hackers Claim to Leak Stolen Madison Square Garden Data How the Peter Thiel-Linked Dialog Club Secretly Ranks Its Members How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras The UK Will Scan Asylum-Seekers’ Faces for Age Checks—Despite Knowing the Tech Is Flawed Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society ‘Dangerous’ AI Models Are Coming No Matter What Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses The FCC Wants to Kill Burner Phones Grok Is Still Hosting Sexualized Deepfakes of Famous Women Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcasts Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick Wrongful Arrest Exposes Failures in One of the Oldest Police Face-Recognition Tools in the US Soccer Fans, You’re Being Watched Mapping Every Flock License Plate Reader Near US World Cup Stadiums Amnesty International Warns That World Cup Fans Face Potential Human Rights Violations Anthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of You Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report All the Ways Europe Is Ditching American Technology Crypto-Funded Chinese Peptide Labs Are Booming Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity Android Is Fighting Phone Scams With a New Feature to Prove Who’s Calling The Manhattan Institute Helped Kill DEI. Now It’s Coming for Protests The Romance Scammer Who Made a Small Fortune Posing as a WWE Superstar Websites Can Now Spy on You Through Your Hard Drive Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow The White House’s Aliens.gov Site Brags That ICE Arrested More Than 700 US Citizens The Pentagon Knew Enemies Could Track Troops’ Phones for Years. Now They Are Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing Attacks Internet Starts to Return in Iran After 3-Month Blackout US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows The AI Era Is Creating a Bug-Hunting Arms Race The FBI Wants ‘Near Real-Time’ Access to US License Plate Readers ‘Creepy’ Listening Tool for Targeted Ads Didn’t Actually Work, FTC Says A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale The EU Is Going Through a Trump-Fueled Breakup With Big Tech A Bipartisan Amendment Would End Police License Plate Tracking Nationwide Madison Square Garden Bans Lawyer Representing New York Cop Injured at a Boxing Match Data Brokers’ and AI Firms’ Opt-Out Forms Are Built to Fail, Report Finds You Can Get Some of Your Nudes Removed From the Internet Under a New Law An ICE Firearms Trainer Was Involved in At Least 4 Deadly Shootings Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording Your iPhone Gets Stolen. Then the Hacking Begins DHS Plans Experiment Running ‘Reconnaissance’ Drones Along the US-Canada Border WhatsApp Adds Meta AI Chats That Are Built to Be Fully Private Foxconn Ransomware Attack Shows Nothing Is Safe Forever Iran Is Using Tiny ‘Mosquito’ Boats to Shut Down the Strait of Hormuz Hackable Robot Lawn Mower Unlocks a New Nightmare You Can Disable Gemini in Chrome if It’s Freaking You Out Cybercriminals Are Complaining About AI Slop Flooding Their Forums DHS Demanded Google Surrender Data on Canadian’s Activity, Location Over Anti-ICE Posts Disneyland Now Uses Face Recognition on Visitors OpenAI Rolls Out ‘Advanced’ Security Mode for At-Risk Accounts Exposed Data Illustrates the Nightmare Scenario for a Stalkerware Victim The Race Is on to Keep AI Agents From Running Wild With Your Credit Cards California Engineer Identified in Suspected Shooting at White House Correspondents Dinner Discord Sleuths Gained Unauthorized Access to Anthropic’s Mythos Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet AI Tools Are Helping Mediocre North Korean Hackers Steal Millions Mozilla Used Anthropic’s Mythos to Find and Fix 271 Bugs in Firefox Meta Is Sued Over Scam Ads on Facebook and Instagram They Built a Legendary Privacy Tool. Now They’re Sworn Enemies The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad It Takes 2 Minutes to Hack the EU’s New Age-Verification App Republican Mutiny Sinks Trump's Push to Extend Warrantless Surveillance The Shocking Secrets of Madison Square Garden’s Surveillance Machine Europe’s Online Age Verification App Is Here The Deepfake Nudes Crisis in Schools Is Much Worse Than You Thought In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy The FCC Has a Fast Lane for Complaints About Trump’s Media Critics Meta Is Warned That Facial Recognition Glasses Will Arm Sexual Predators The Dumbest Hack of the Year Exposed a Very Real Problem Your Push Notifications Aren’t Safe From the FBI How the Internet Broke Everyone’s Bullshit Detectors Anthropic’s Mythos Will Force a Cybersecurity Reckoning—Just Not the One You Think Politicians Are Spending More Money on Security as They Increasingly Become Targets ‘We Were Not Ready for This’: Lebanon's Emergency System Is Hanging by a Thread Men Are Buying Hacking Tools to Use Against Their Wives and Friends Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything Border Patrol Agents Sold Challenge Coins With ‘Charlotte’s Web’ Characters in Riot Gear Hackers Are Posting the Claude Code Leak With Bonus Malware Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk CBP Facility Codes Sure Seem to Have Leaked Via Online Flashcards ‘Uncanny Valley’: Iran’s Threats on US Tech, Trump’s Plans for Midterms, and Polymarket’s Pop-up Flop What Happens When a Nuclear Site Is Hit? Unmasking the Paramilitary Agents Behind Trump’s Violent Immigration Crackdown Apple Will Push Out Rare ‘Backported’ Patches to Protect iOS 18 Users From DarkSword Hacking Tool Iran Threatens to Start Attacking Major US Tech Firms on April 1 The US Military’s GPS Software Is an $8 Billion Mess The Broken System That Keeps Shipping Crews Stranded in the Strait of Hormuz Iranian Hackers Breached Kash Patel’s Email—but Not the FBI’s How Trump’s Plot to Grab Iran's Nuclear Fuel Would Actually Work
Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market
2026-04-15 · via Security Latest

For three and a half years, the messaging platform Telegram has served as the home of a sprawling black market known as Xinbi Guarantee, an anarchic, Chinese-language bazaar offering money laundering services to crypto scammers, products like electrified batons and tasers for those same scammers' human trafficking operations, and even at times other assorted criminal services ranging from harassment-for-hire to teen prostitution. Despite WIRED and crypto crime researchers repeatedly pointing out that blatantly criminal activity to Telegram, the company has since allowed Xinbi Guarantee to grow into the biggest black market on the internet, one that's facilitated a staggering $21 billion in total transactions.

The full extent of Telegram's failure to eradicate the scam marketplace was put to the test late last in March when the UK government officially sanctioned Xinbi Guarantee and designated it a facilitator of human trafficking. Yet now, nearly three weeks later, Telegram still hasn't removed Xinbi's accounts on its service, facilitating more than half a billion dollars’ worth of illicit deals in the time just since those sanctions were put in place.

According to cryptocurrency tracing firm Elliptic, Xinbi Guarantee carried out $505 million in transactions in the 19 days after the British government's sanctions and added tens of thousands more users to reach nearly half a million buyers and sellers in total. Elliptic says it has seen no signs that Telegram has taken any action to ban the market or its accounts. “Xinbi is still going strong,” says Elliptic's cofounder and chief scientist Tom Robinson. “They're on track to become the largest market of this kind that's ever existed.”

Telegram's apparent refusal to remove the black market—just one in an industry of Chinese-language black markets that operates on Telegram in full public view—represents an appalling lack of accountability, says Gary Warner, a security researcher who has tracked Xinbi Guarantee as director of intelligence at the cybersecurity firm DarkTower. “It boggles my mind,” Warner says. “There's literally no legitimate company in the world that hosts this level of criminal activity and is so open about it. There's nothing that even comes close.”

Telegram didn't respond to WIRED's multiple requests for comment on its hosting of Xinbi Guarantee following the UK's sanctioning. In June of last year, however, a Telegram spokesperson justified Telegram's hosting of Xinbi Guarantee and other Chinese-language black markets by arguing that they allow Chinese citizens “to seek alternative avenues for moving funds internationally” despite China's rigid financial controls.

“We assess reports on a case-by-case basis and categorically reject blanket bans—particularly when users are attempting to circumvent oppressive restrictions imposed by authoritarian regimes,” read Telegram's statement to WIRED at the time. "We remain unwavering in our commitment to safeguarding user privacy and defending fundamental freedoms, including the right to financial autonomy.”

That description of Xinbi Guarantee as an innocuous “alternative avenue” for international money transfers had already been undermined by Elliptic's findings that Xinbi was predominantly used as a money laundering service for the vast crypto scam industry, including Chinese-run organized syndicates that control compounds across Myanmar, Cambodia, and Laos that enslave hundreds of thousands of human trafficking victims forced to work as scammers. Elliptic found listings as recently as the past month that offer products that appear intended for those human trafficking operations, including electrified batons, tasers, and handcuffs.

On March 26, the UK's Foreign, Commonwealth and Development Office officially sanctioned Xinbi for its alleged role in scamming and human trafficking. “Xinbi has enabled and profited from the operation of scam centers in Southeast Asia,” the sanctions notice read. “The treatment of individuals in these scam centers amounts to a serious abuse of the right not to be subjected to cruel, inhumane, or degrading treatment or punishment, and of the right to be free from slavery, not to be held in servitude or required to perform forced or compulsory labour.”

Xinbi Guarantee has also hosted a wide variety of other black market offerings, including harassment services that threaten or throw feces at a victim for a fee, and even sex workers as young as 14 who are likely trafficking victims. One listing Elliptic shared with WIRED, found just in recent weeks, offered a 16-year-old sex worker, including the girl's body size measurements and available sex acts.

As clearly as all of those examples contradict Telegram's arguments for hosting Xinbi Guarantee, though, the UK government's official sanctions against Xinbi are even more clearcut, says Elliptic's Robinson. “It was already a weak argument, but the sanctioning of Xinbi makes the argument much weaker,” Robinson says. “There is now this official recognition that Xinbi is predominantly an illicit actor.”

Telegram's tolerance for Xinbi Guarantee is all the stranger because it did, in fact, ban the market at one point last year. After WIRED asked Telegram about Elliptic's findings regarding Xinbi Guarantee and a then-even-larger market known as Huione Guarantee, Telegram summarily purged the accounts of both. Telegram spokesperson Remi Vaughn wrote to WIRED at the time that “criminal activities like scamming or money laundering are forbidden by Telegram's terms of service and are always removed whenever discovered.”

Over the following month, however, Elliptic continued to share its findings about apparent money laundering activity in a Telegram group that included a WIRED reporter and a Telegram spokesperson. Yet after its initial bans, Telegram didn't remove any accounts for the black markets Elliptic highlighted, and Xinbi Guarantee simply rebuilt its marketplace despite Telegram's own statement that it had violated the messaging platform's terms of service.

Perhaps aware of its vulnerability to another Telegram ban, Xinbi Guarantee has asked its users to transition to another platform called SafeW. But the vast majority of Xinbi Guarantee's activity has remained on Telegram, and Elliptic's Robinson argues that the market will have a tough time moving users to SafeW. “Xinbi benefits from Telegram's huge installed user base, something that would be very challenging for SafeW to replicate,” Robinson says.

For now, of course, Xinbi Guarantee doesn't have to go anywhere, given Telegram hosting its blatantly criminal activity in plain sight. DarkTower's Warner argues that represents an inexcusable lack of attention to Telegram's enabling of Chinese-language black markets, both on the part of Telegram itself and law enforcement agencies worldwide.

When Russian cybercriminals have hosted black markets selling malicious software and stolen data, Warner points out, international law enforcement coalitions targeted those criminals and their infrastructure, leading to repeated seizures and arrests. Given how openly Telegram has hosted an even bigger criminal ecosystem, the company and its founder and CEO Pavel Durov deserve that same treatment, Warner argues. (Durov was, in fact, arrested and charged in France in 2024 but has since been released while the French government’s investigation reportedly continues.)

“He should be the subject of an international task force,” claims Warner. “He should be hunted down and arrested. He should be forced to be held accountable.”