Odaily, in a joint investigation with blockchain security team Bitrace, said USDT has become the main settlement tool and value carrier inside Southeast Asia’s underground crime economy after tighter controls reduced the use of traditional banking channels. The report links the stablecoin to a wide range of activities, including human trafficking, scam revenue distribution, technical service procurement and money laundering.

The article was published by Odaily and credited to Wenser. It draws on Bitrace’s crime research and real cases to break down how the region’s crypto-enabled gray and black markets operate, then closes with five practical anti-fraud tips for the public.
How the payment layer supports the scam economy
Bitrace said organized crime in Southeast Asia has become highly industrialized, with specialized providers handling each stage of the workflow. That includes recruitment, data collection, website construction, victim acquisition, scripted deception and final fund laundering.
At the center of that system are crypto guarantee platforms operating through Telegram groups. The report describes them as marketplaces that gather scattered criminal resources in one place, offer escrow and credibility, and match buyers with sellers across different illicit services.
The three building blocks: people, data and tools
The article frames the supply chain around three essentials: people, information and tools.

Human trafficking comes first. Scam compounds and gambling operations in the region need a steady labor supply, and that demand has produced a trafficking pipeline covering recruitment, transport and delivery. Bitrace said some Telegram groups openly market people as "labor." One group identified as "XXX Group Direct Hiring" had nearly 5,000 members, with asking prices ranging from several thousand USDT to more than 10,000 USDT.
The report lists three common transaction types:
- Direct delivery, where a broker hands a person over to an overseas buyer and receives payment at a designated address.
- Escrowed transactions, where the buyer first deposits USDT with an illegal guarantee platform, and the platform releases funds after delivery while taking a commission.
- Resale transactions, where trafficked individuals are sold again between merchants.
In those trades, USDT functions as the cross-border payment rail, while the guarantee platform acts as the escrow and trust layer.
Once labor is secured, the next step is identifying targets. In the gray-market jargon cited in the report, illegally obtaining personal records is called "checking files." Operators collect USDT from clients, assign requests to insiders with access at public departments, banks, courier networks or telecom systems, and receive data on a target’s household registration, marital status, education, medical history, assets and movements.
Bitrace said one Telegram group focused on this business, labeled "XXX Data Check," had more than 3,000 members. Its public menu included personal, corporate and vehicle data. Services ranged from household registration and marriage records to company files, invoices, business licenses, corporate account statements, payroll information, land holdings, card balances, highway records, vehicle tracking and parking-lot surveillance.

Transaction records shown in the article indicate fees from tens of USDT to several hundred USDT per request, with completion in one to two days. The stated acceptance standard was "authentic but not guaranteed complete." The information was then used to tailor scam scripts to a victim’s identity, family situation and asset profile.
Tooling is also sold as a service. The report said scam groups no longer need to build fake exchanges or investment apps on their own because dedicated developers openly market turnkey products in guarantee-platform groups.
In one Telegram group for app development and platform setup, vendors advertised cloned exchange codebases. One fake DApp exchange package offered 15 language versions, a React 18 front end and a Java back end, with source code available for modification. Its features included forex, commodities, indices, stocks, spot trading, options, various contracts, copy trading, NFT collectibles, DeFi borrowing and locked-yield products. Another exchange-style DApp offered multilingual support, a Vue front end, demo accounts, delivery contracts, perpetual contracts, USDT-margined contracts, forex contracts, spot trading, precious metals, price controls, K-line controls, lending and staking.
Odaily said the interfaces and features were close enough to real products that even many experienced crypto users might struggle to tell them apart. The article adds that service providers can also build fake investment platforms, counterfeit trading interfaces and download pages around a buyer’s requested target market, fake identity, investment narrative and top-up method, then connect those pages to wallet addresses controlled by the criminal group. USDT is used for settlement here as well, while the guarantee platform serves as a mix of bank, payment processor and intermediary.
From traffic acquisition to one-on-one manipulation
Once the tools are in place, the operation moves to outreach.

The report says one of the most common methods in cross-border telecom fraud is the "phone port" setup. Since calls placed directly from overseas numbers tend to raise suspicion, scammers use two phones linked by an audio cable. One phone connects the overseas operator through internet software, and the other uses a domestic SIM card to call the victim. That lets an overseas fraudster speak with a target in real time while the incoming caller ID appears local.
Workers in that part of the chain are scattered across many locations, which the report says weakens enforcement results. Rules from one Telegram group for this business required participants to make video calls available on request, denied payment for sessions shorter than 20 minutes and said fake participants would be removed immediately. A recruitment ad cited in the article offered a flat 300 USDT rate for China Mobile, China Telecom and China Unicom phone-port work, plus breakfast and "Lotus" before 11 a.m., and additional pay of 5 USDT for 30 minutes, 10 USDT for 60 minutes and 15 USDT for 100 minutes.
Traffic acquisition is not limited to voice routing. Another Telegram channel focused on scripts and labor guidance divided outreach methods into three categories built around social media, online games and internet advertising. The report says scam groups tailor setups to different audiences and different levels of caution.
After the first contact comes the "deep chat" stage, where operators try to build trust and push victims into the next step. According to the article, this can involve images, fabricated video materials and highly targeted scripts. The workflow may include story writing, identity construction and planned conversations. Demand for those materials has created a market for photo sets and text packages, while the spread of AI deepfake tools has lowered the technical barrier for generating images and copy.

Turning stolen money into crypto: "card-to-U" laundering
Once funds are taken from victims, the next task is moving them into crypto quickly enough to complicate law-enforcement tracing. The report says a common method is known as "card-to-U," meaning the conversion of stolen funds into USDT.
This process is usually divided into two layers. In the first layer, called "first channel," group operators use bank cards to receive illicit funds directly, including transfers from victims or proceeds from pyramid schemes near collapse. Launderers then use the money to buy USDT as fast as possible and send a portion back to upstream criminal groups, keeping the spread as profit.
The second layer, or "second channel," comes next. After the first group receives the money, it forwards funds to another group, often made up of anonymous OTC merchants. The report says the profit from helping laundering networks move money can be higher than serving ordinary investors, which has drawn many OTC operators into the trade.
By the time a victim’s bank transfer passes through these first and second channels, it has been transformed into USDT that is much harder for investigators to follow.
Guarantee platforms sit at the center of this structure. Upstream, they connect technical service providers and suppliers. In the middle, they host merchants involved in scams, gambling and human trafficking. Downstream, they aggregate settlement, OTC, laundering and payment services. Through entry checks, deposits and branding, they reduce trust costs between unfamiliar parties. The report says such platforms may not directly execute crimes in every case, but they serve criminal organizations and become facilitators.

Bitrace said the market structure has already become oligopolistic. Although Tudou Guarantee, under Huione Group, shut down in early 2026, the illegal crypto guarantee business did not disappear. It shifted to competitors including Xinbi Guarantee and Dali Guarantee. In the first half of 2026 alone, more than 3.4 billion USDT flowed into guarantee-platform addresses. That total included public-group deposits and monthly rent from guarantee merchants, as well as deposits from ordinary traders in private groups. More than 90% of the related revenue was tied to Xinbi Guarantee.
The article also says these gray-market platforms have begun pushing into domestic internet content channels. Searches for a leading guarantee platform on one short-video app returned large amounts of related content, including messaging that tried to blur criminal boundaries with lines such as "No one in this society cares what kind of work you do. If you’re doing well and can come up with money when it matters, then you’re somebody." Some users posted comments such as "The guilty party is not us, but a society where everything costs money."
Some operators have also tried to use online influencers in promotion. The report cites one Telegram group post in which a guarantee platform claimed that "Brother X," described as an influencer with tens of millions of followers across the internet, was endorsing the service and might later appear in the group. The article says it remains unclear whether the influencer had any real connection to the scam network or whether the promotional material was fabricated.
Two real cases cited by Bitrace
Case 1: fake exchange mining-pool arbitrage
The first scheme is described as an old, low-cost scam aimed at beginners. Fraudsters use bots to impersonate official communities of major exchanges and claim they are offering a special user reward. Victims are told to send ETH to a specified contract address and are promised an oversized return in BNB. In reality, the returned tokens are fake BNB, and the goal is simply to steal real ETH.
Odaily said Bitrace helped a group of victims in 2022 who had been caught in this type of scam. Losses ranged from tens of thousands of dollars to hundreds of thousands of dollars. Even in November 2025, victims were still asking for updates in the group, but the case ultimately went nowhere because of the tracing difficulty and the time elapsed.

Case 2: fake DApp pig-butchering scheme
At the end of 2024, one victim visited a website called orcaen, which copied the front-end page of Orca Dex and claimed to offer high returns. Believing funds would be safe when accessing it through an exchange wallet, the victim put in several thousand USDT for supposed arbitrage. Only when a withdrawal request was rejected by customer service did the victim realize it was a scam.
The article says the fake DApp looked convincing. Its homepage included categories for cryptocurrencies, forex, stocks, precious metals and energy. It displayed live prices and K-line charts for assets such as BTC and ETH, offered "buy up" and "buy down" buttons, and showed tabs for home, trading, assets and records. It also had top-up, withdrawal, transfer and earnings trend functions. The funds, however, never came back.
Bitrace described this as a standard pig-butchering pattern: first show the victim apparent profits on screen, then block withdrawals by citing trading-volume requirements, security deposits or personal income tax, pushing the victim to add more money. The report says Bitrace traced the victim’s funds to Huione Pay, under Prince Group, for laundering. At that time, the Huione guarantee platform was still active, and once funds entered that network, recovery became extremely difficult.
Five anti-fraud reminders for ordinary users
- Be wary of any side-hustle tied to bank cards, SIM cards or crypto transfers. The article says law-enforcement agencies in multiple countries now monitor the telecom-fraud supply chain end to end. People handling payments, transport, cards, security or traffic are exposed to legal risk. Requests framed as student jobs, spare-cash work or household support can amount to recruitment for expendable front-line roles.
- Protect personal data and reduce your exposure. Personal information is raw material for targeted fraud. The report advises users to limit disclosure of facial images, phone numbers, blockchain addresses, physical addresses and repeated usernames across platforms, and to avoid uploading ID cards or bank information to untrusted services.
- Learn the common pattern of pig-butchering scams. The sequence outlined in the article starts with contact through social platforms or games, moves to a fabricated high-status persona, then trust-building, a supposedly low-risk investment opportunity, small early returns and later large deposits, followed by withdrawal denials. Claims about overseas work, finance jobs or insider information, and demands to download unofficial apps or use unfamiliar websites, are key warning signs.
- Use legitimate platforms for crypto trading. Do not install unknown trading apps recommended by Telegram or WeChat "teachers," and do not trust exchange lookalike domains. The article gives the example of "orcaen.cc" being used to imitate "orca." Users should verify domains and contract addresses before connecting a Web3 wallet and avoid blind approvals. It also mentions the use of trusted AI tools to help screen contract-code risk, domain authenticity and scam patterns.
- Watch for hidden traps in everyday online life. The report says gray-market promotion has entered ordinary digital spaces. Search results on short-video platforms, influencer content, online gaming contacts and overseas high-pay job listings can all be used as scam funnels or trafficking bait. Claims such as "make 100,000 a month," "easy money," "inside channel" or "guaranteed profit" should be treated with caution.
The report ends by saying the scale of Southeast Asia’s crypto-linked gray and black economy is still growing and its techniques are still evolving. For ordinary people, understanding how the system works is part of basic self-protection.

