BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Odaily & Bitrace Joint Report: A Complete Breakdown of the Crypto Money Laundering Chain in Southeast Asian Scam Compounds

Wenser
Odaily资深作者
@wenser2010
2026-09-09 02:21
This article is about 6441 words, reading the full article takes about 10 minutes
The Brutal Reality of Southeast Asia's Underworld: Humans Are Priced in Money, with USDT Serving as the Lifeblood of Funds.
AI Summary
Expand
  • Core Insight: USDT has become the primary payment and value transfer tool for organized crime networks in Southeast Asia, underpinning an industrialized criminal chain spanning human trafficking, online fraud, and money laundering. Moreover, this ecosystem is rapidly restructuring and expanding even after crackdowns on leading escrow platforms.
  • Key Elements:
    1. Highly specialized division of labor in the criminal chain: Encompassing "data brokering" for illegal acquisition of citizens' private information (ranging from tens to hundreds of USDT per transaction), "SIM bank" voice relay services for traffic diversion (300 USDT per group), and the development of customized, high-fidelity counterfeit exchange apps.
    2. Escrow platforms serve as the hub: Aggregating supply and demand through public groups and providing credit endorsement; in the first half of 2026, funds flowing into leading escrow platforms exceeded 3.4 billion USDT, with over 90% linked to new coin escrow services.
    3. Money laundering adopts the "card-to-USDT" model: Divided into "first-tier" (directly accepting illicit funds to purchase USDT) and "second-tier" (anonymous OTC merchants handling transfers) levels, ultimately converting fiat currency into hard-to-trace crypto assets.
    4. Black and grey industry marketing infiltrates mainstream channels: Deploying brainwashing scripts on short-video platforms and recruiting influencers as brand ambassadors (e.g., "X-Ge with tens of millions of followers") for brand packaging and recruitment.
    5. Typical scams include fake exchange mining pool arbitrage schemes (defrauding victims of ETH) and fraudulent DApps mimicking Orca's interface in "pig-butchering" operations, with funds ultimately flowing into underground payment networks like Huiwang Pay, making recovery extremely difficult.

Original|Odaily Planet Daily(@OdailyChina

Author|Wenser(@wenser 2010

When it comes to Southeast Asia, many people immediately think of islands and cuisine. But beneath this glossy surface, another "folded Southeast Asia" operates at full speed—fraud compounds, human trafficking, online gambling, and money laundering form a vast underground criminal network.

This network's sustained operation relies on a complete payment and settlement system. With traditional banking channels progressively blocked by regulators across various countries, cryptocurrencies—especially USDT—have become the core payment method and value carrier in Southeast Asian criminal activities. From human trafficking to fraud profit-sharing, from technical service procurement to money laundering and cashing out, nearly every link in the chain settles transactions in USDT.

Based on blockchain security team Bitrace's criminal investigations and first-hand real cases, Odaily Planet Daily provides a detailed breakdown of the complete operational chain of Southeast Asia's crypto black market and gray industry, along with 5 actionable anti-fraud guidelines compiled for readers' reference.

May the light dispel the darkness lurking in the corners.

The Assembly Line Hidden in Dark Corners: A Portrait of Southeast Asian Crime

According to Bitrace's long-term tracking and investigation, organized crime in Southeast Asia has become highly industrialized and assembly-line oriented. From personnel recruitment, information gathering, and website construction to traffic generation, social engineering scripts, and money laundering, every step has dedicated service providers with clear division of labor. Meanwhile, numerous crypto guarantee platforms act as "dark version Amazon marketplaces," aggregating these dispersed criminal resources, providing credit endorsement and transaction matching to reap exorbitant profits.

Next, we will use the most typical "pig butchering" scam as an example to break down the many stages of this "industrial assembly line."

The Three Core Elements of the Criminal Chain: People, Information, and Tools

Human trafficking is the starting point of the entire criminal chain. Southeast Asia's black market compounds require substantial manpower to engage in illegal activities such as fraud operations and gambling customer service. Around this demand, a trafficking chain has formed covering recruitment, transport, and delivery.

On Telegram, such transactions are conducted openly under the guise of "labor services." A group named "XXX Group Direct Recruitment" boasts nearly 5,000 members, with clearly listed prices ranging from several thousand USDT to over ten thousand USDT. Here, gender doesn't matter, age is irrelevant—people are priced solely in monetary terms, treated as bargaining chips in transactions.

Human trafficking group publicly quotes prices, graded by "quality" (Source: Bitrace investigation screenshot)

Transaction methods typically fall into three categories:

  • "Bare" transactions, where intermediaries deliver people directly to overseas buyers, and buyers pay the intermediary's address;
  • Escrow transactions, where buyers first deposit USDT into an illegal guarantee platform, which releases funds after delivery is completed and charges a commission;
  • "Second-hand" transactions, where trafficking merchants resell victims among themselves.

USDT serves as the cross-border payment mechanism, while guarantee platforms provide credit endorsement and fund custody.

Once human resources are secured, the next step is acquiring target information.

The black market industry refers to illegally obtaining citizens' private information as "file checking." Practitioners collect USDT from clients, then assign query tasks to individuals with internal access within public security, court, banking, courier, and telecom operator systems. These insiders use their privileges to illegally obtain specific individuals' household registration, marriage records, academic history, medical information, assets, whereabouts, and other data, which is then returned to the fraud syndicates.

Bitrace's investigation materials show that a single Telegram public group named "XXX File Check" has over 3,000 members, openly listing available query categories. These range from personal information such as individual household registration, family registry, and marriage records, to corporate information including company archives, invoices, business licenses, company bank cards, business account statements, employee and payroll data, company-owned properties and land, and account balances. Even vehicle information such as highway toll records, vehicle trajectories, and parking lot surveillance footage is prominently listed.

Illegal file-checking public group's business catalog, covering dozens of data types across personal, corporate, and vehicle categories (Source: Bitrace investigation screenshot)

Transaction records within the group show that individual file-checking fees range from dozens to hundreds of USDT, with order completion times of 1 to 2 days and acceptance criteria stating "authenticity guaranteed, but omissions not covered." This private information is ultimately used for targeted fraud—once scammers grasp their victims' true identities, family situations, and asset conditions, they can tailor deceptive scripts for precision scams.

Furthermore, tool preparation is equally highly industrialized. Fraud syndicates don't need to develop their own scam websites and fake trading applications; dedicated technical service providers take custom orders in guarantee platform public groups. In one "APP Development/Platform Building Public Group," service providers openly peddle source code for high-fidelity exchange clones: a DAPP mimicking OKX in 15 languages, with React 18 frontend and Java backend, fully open source and modifiable, supporting forex, commodities, indices, stocks, spot trading, options, various contract types, social trading, NFT digital collectibles, plus DeFi lending and lock-up earning features. Another DAPP exchange supports multiple languages with a Vue frontend, including demo account modes, delivery contracts, perpetual contracts, USDT-margined contracts, forex contracts, spot trading, precious metals, price manipulation controls, K-line manipulation, loans, and staking. These interfaces and features are virtually indistinguishable from legitimate official apps—let alone outsiders being fooled, even many industry veterans would struggle to tell them apart at first glance.

Technical service providers offer "customized professional services" (Source: Bitrace investigation screenshot)

Moreover, after fraud syndicates specify their target market, fake identity personas, investment projects, and deposit methods, technical service providers can build counterfeit investment platforms, fake trading interfaces, or app download pages accordingly, integrating crypto payment addresses controlled by the criminal groups. All related services are settled in USDT, with guarantee platforms playing the multi-faceted role of "banking system + payment system + neutral intermediary."

Crime in Action: From Traffic Generation to Deep Conversation

Once the tools are ready, fraud syndicates reach targets through traffic generation.

In cross-border telecom fraud, "phone relay" (hand-phone relay) is the most commonly used voice relay method. Since overseas scammers calling domestic numbers directly would display foreign country codes—heightening victims' wariness—phone relay provides fraudsters with a convenient gateway. The method works as follows: fraud syndicates connect two phones via an audio cable, with one phone linked to overseas scammers through a network application and the other inserted with a domestic SIM card to call victims, enabling real-time voice relay—ultimately achieving the effect of "overseas scammers talking directly to victims while the caller ID shows a local number."

The "cannon fodder" (also called "gunners") engaged in phone relay operations are typically a mixed lot scattered across the country, making enforcement crackdowns less effective. One "Phone Relay Public Group" rules state: must cooperate with video calls during operation, no settlement for sessions under 20 minutes, and those caught using fake identities are immediately dismissed. Recruitment ads show that phone relay services across China Mobile, China Unicom, and China Telecom uniformly pay 300 USDT per team, with early morning shifts (before 11 PM) receiving breakfast plus "lotus flowers" (cigarette code language), and private red packets arranged after shifts—30 minutes adds 5 USDT, 60 minutes adds 10 USDT, and 100 minutes adds 15 USDT. Through intricate collaboration between domestic and overseas criminal groups, fraud syndicates weave far-reaching scam networks.

Phone relay public group recruitment information (Source: Bitrace investigation screenshot)

Beyond phone relay, traffic generation also employs more systematic methodologies. A Telegram channel called "Labor Scripts" categorizes these into 3 types, involving primary channels such as social media, online gaming, and internet advertising. Fraud syndicates design targeted traps based on demographic profiles and vigilance levels, making them extremely difficult to avoid.

Screenshot from traffic generation script training channel (Source: Bitrace investigation screenshot)

After traffic generation, criminal operations enter the "deep conversation" phase. During this stage, fraud syndicates typically employ elaborate scripts, image materials, and forged videos to conduct targeted deception against victims. This even involves scriptwriting, persona-building, and conversation scheduling. Since these processes require vast amounts of scenery photos, portraits, and copywriting materials, corresponding service providers have emerged to sell such "assets"—complete sets of attractive men and women photos from various countries are readily available. Following the explosion of AI deepfake technology, numerous AI models are now used to generate copywriting and image materials, further lowering the technical barrier for executing sophisticated fraud conversations.

Screenshot of deep conversation material channel (Source: Bitrace investigation screenshot)

The Final Chapter of Crime: Converting Fraud Funds into Black-market USDT

After successfully defrauding victims, criminal syndicates typically move quickly to launder funds to evade law enforcement tracking.

The currently prevalent method is known as "card-to-USDT conversion," which involves converting defrauded funds into USDT. Depending on the laundering layer involved, this process is typically divided into "first-tier" and "second-tier" operations. The former refers to public groups that directly use bank cards to receive illicit funds, such as victims' direct transfers or funds from Ponzi schemes on the verge of collapse; launderers use this money as quickly as possible to purchase USDT, returning a portion as compensation to the upstream criminal syndicate, with the difference representing the public group's profit. The latter serves as the downstream link: after first-tier groups collect illicit funds, the next transfer destination is second-tier groups, typically anonymous OTC merchants. Compared to providing exchange services for legitimate investors, helping money laundering groups move funds yields considerably higher profits, leading many OTC merchants down this path of no return.

At this point, funds transferred from a victim's bank account—having passed through first-tier and second-tier card-to-USDT laundering—ultimately become USDT that law enforcement finds extremely difficult to trace, providing nourishment and raw material for the criminal syndicates' massive blood-sucking machine.

When Stablecoins Become the Lifeblood of Criminal Networks

Throughout the entire criminal chain, crypto guarantee platforms serve as the hub connecting upstream and downstream operations.

Numerous platforms operate extensive "public groups" on Telegram, with upstream aggregating technical service providers and material suppliers, midstream renting to guarantee merchants conducting fraud, gambling, and human trafficking operations, and downstream aggregating exchange, OTC, money laundering, and payment services. Platforms reduce trust costs between unfamiliar transaction parties through admission screening, security deposits, and brand endorsement. Strictly speaking, they may not directly commit crimes themselves, but they serve criminal organizations, making them accomplices and breeding grounds for criminal activity.

The current guarantee platform landscape has formed an oligopolistic structure. Although Huiwang Group's Tudou Guarantee shut down in early 2026, the illegal crypto transaction guarantee industry didn't disappear—it simply migrated to competitors like Xinbi Guarantee and Dali Guarantee. In the first half of 2026, over 3.4 billion USDT flowed into guarantee platform addresses, including both public group deposits and monthly rents from guarantee merchants as well as dedicated group deposits from ordinary traders, with over 90% of revenue associated with Xinbi Guarantee.

Even more alarming, these black market platforms have begun encroaching on domestic Chinese internet platform content.

Searching for a major guarantee platform on a short-video platform reveals extensive related content: beyond platform introductions, there are brainwashing scripts that blur the lines of criminality with phrases like "In this society, nobody cares what you do for a living. As long as you're doing well and can produce money when it matters, you're good." Under the influence of such toxic values, some users even voice exonerating rhetoric like "It's not us who are guilty—it's this society that demands money for everything."

Search results on a short-video platform (Source: Bitrace investigation screenshot)

Some black market entities also invite domestic influencers for marketing promotion. One guarantee platform openly announced in its Telegram group, "Nationwide influencer with 10 million followers, Brother X, enthusiastically endorses us," even using "Brother X will perform in the group later" as a gimmick to attract traffic. Reports indicate this blogger is a niche internet personality whose meme stickers circulate widely throughout black market communities. Whether this influencer genuinely collaborates with the fraud syndicate or is merely fabricated material created by the latter remains unknown for now.

Guarantee platform leveraging influencer videos for promotion (Source: Bitrace investigation screenshot)

Blockchain and cryptocurrency were originally conceived to build decentralized, trustworthy financial infrastructure. Yet within Southeast Asia's criminal networks, USDT's cross-border payment capabilities, anonymity, and difficulty of timely freezing have been exploited by fraud syndicates to provide settlement services for severe crimes including human trafficking, fraud, and money laundering.

When one major guarantee platform collapses, affiliated merchants can rapidly migrate to other platforms and continue operations. The platforms, public groups, merchants, and payment tools maintain relative independence while remaining capable of splitting apart and recombining—this elastic organizational structure makes enforcement crackdowns extremely challenging.

In just the first half of 2026, funds flowing into major guarantee platforms reached $3.4 billion. Behind these numbers lie countless defrauded families, trafficked individuals, and lives destroyed by scams.

Two Real Fraud Cases: Fake Mining Pool Arbitrage and Fake DAPP Pig Butchering

Beyond the cases above, cryptocurrency-related fraud schemes are too numerous to count. Here, we briefly introduce two real stories investigated by Bitrace as illustrative examples.

Case One: Fake Exchange Mining Pool Arbitrage Fraud

This is an ancient, low-cost scam targeting newcomers specifically. Fraudsters use bots to impersonate official communities of major exchanges, claiming to "reward exchange users" and requiring potential victims to send ETH to specific contract addresses, promising excess BNB returns. In reality, the scammers return fake BNB, with the primary goal of stealing victims' genuine ETH. The image below is a screenshot of the scam group provided by the victim, showing that multiple group members were all part of the fraud syndicate.

Performance by numerous shills inside the scam group (Source: Bitrace investigation screenshot)

Previously, Bitrace assisted a batch of victims of this type of scam in 2022, with losses ranging from tens of thousands to hundreds of thousands of dollars. As recently as November 2025, victims were still asking about case progress in the group, but due to tracking difficulties and the passage of time, the case ultimately fizzled out without resolution.

Even the crudest scams, amplified by cryptocurrency's anonymity and cross-border nature, can inflict massive losses with extremely low recovery probability.

Case Two: Fake DAPP Pig Butchering Fraud

In late 2024, a victim visited a website named orcaen that cloned the front-end interface of Orca DEX, falsely claiming to offer high returns. Believing that accessing funds through a legitimate exchange wallet guaranteed security, the victim invested several thousand US

Safety
industry
USDT
Welcome to Join Odaily Official Community