After 52 Xinbi Guarantee USDT wallets were frozen, how did an AI agent find the new wallet?
After 52 USDT wallets linked to Xinbi Guarantee were frozen, we gave an AI agent only the old wallets, the freeze time and a goal, to see whether it could find the wallet that took over the business from on-chain data alone. It did, and it ruled out an older address that looked even more like the answer.
What happened
Around 16:00 on September 8, 2026, a batch of USDT wallets on the TRON chain linked to Xinbi Guarantee and its merchant network was frozen.
Elliptic’s figures put it at 52 wallets and about $52.8 million in USDT. The US Treasury’s OFAC later published the addresses involved. Bitrace’s follow-up analysis grouped them by the business they actually served and identified at least 22 business addresses holding more than $45 million.
These figures don’t cover exactly the same scope. So here we treat the 52 public addresses as the starting point of the investigation, without assuming they were “all directly controlled by one person.”
Public reports also mentioned that after the old wallets were frozen, the new business wallet brought in as a stopgap was itself frozen in less than 12 hours.
That makes a very good test for an on-chain AI agent.
We gave the agent only three things
First, the 52 old wallets.
Second, the approximate time of the freeze.
Third, a goal: find out whether, once the old wallets stopped working, any new wallet picked up the business they had been handling.
We did not give it the new wallet address from the public reports, did not tell it the answer, and did not let it look the result up on the internet. This wasn’t “take the answer and go find evidence for it.” It started from a set of old wallets and had to find its own leads among a large volume of ordinary transfers.
The run took about 4 minutes and made 34 queries.
Step one: don’t rush to find the new wallet
The agent first looked at how the 52 old wallets changed around the time of the freeze.
The result was clear: their last outgoing transfers all stopped at around 16:00:36, but incoming transfers didn’t stop right away. 136 payers kept sending money to the old wallets.
It’s like a shop’s till suddenly being locked: customers don’t know, so they keep paying into it, but the shop can no longer take the money out.
Nothing in the local data says “this wallet has been frozen.” The agent found the real break in the business from a shared change: the wallets were still receiving money but had all stopped sending it.
This step matters. The time the user gives is only a hint; the actual handover point should be confirmed by what happens on chain.
The old wallets didn’t send the money straight to a new one
The first thing traditional fund tracing tends to look for is:
old wallet → new wallet
But there was no such direct transfer this time.
The reason is simple: the old wallets had been frozen and couldn’t move their balances to a new wallet. If you only wait to see “who the old wallets sent money to,” the investigation stops right here.
The agent turned the question around: the old wallets can’t move, but the people who used to pay them still can.
So it grouped the payers that were still active around the time of the freeze, and then looked at where those payers sent money afterwards.
The address that looked most like the answer was a wrong candidate
Following the payers, the agent quickly found a very prominent wallet.
It shared 11 payers with the old network, and its transaction volume jumped about 9-fold after the freeze. Whether you looked at shared payers or at the amount of money, it stood out more than the new wallet that was found later.
If you only ranked candidates once, it would be easy to write this one up as “the replacement wallet.”
But the agent kept going. It checked what this wallet looked like before the freeze and found that it had existed since as early as April, and had already been receiving large amounts before the freeze.
It looked more like an old channel that had been running in parallel all along and simply took on more traffic after the other wallets were frozen. It may be connected to the same larger network, but that doesn’t make it the new wallet brought in this time.
So the agent downgraded this most answer-like wallet to “existing collection hub” and kept looking.
The real new wallet was where several leads pointed at once
Next, a wallet that had only just appeared entered the candidate list. This was new collection wallet A: TMJf...eiXu.
It was activated at 16:41 on September 8, about 41 minutes after the old wallets stopped sending. It received its first USDT at 16:48, only about 7 minutes after activation.
Over the next few hours, A received transfers from 418 payers, about 1.85 million USDT in total. Of those payers, 8 also appeared among the old wallets’ payers.
Eight shared payers isn’t very many, and on its own it isn’t enough to draw a conclusion. What put A at the top was a different lead: the wallet that activated A had earlier activated 3 business nodes in the old network.
That carries more weight than “used the same energy service.” A public energy service may serve thousands of wallets at once, so having used the same one doesn’t show that wallets belong to the same network. But one activating wallet that had activated several old nodes, then activated A 41 minutes after the freeze, is much tighter in both timing and relationship.
In other words, A wasn’t picked because of any single feature. It was picked because its appearance time, its payers, who activated it and how it received and sent money all lined up at once.
After A was found, the money kept moving
A didn’t spread the money it received across many addresses.
Between 01:25 and 01:29 on September 9, it sent about 1.8 million USDT in two transfers to relay wallet B. B was also a wallet that had only just appeared, and less than 34 minutes after receiving the money it split it into two outgoing transfers: one of 800,000 and one of 1 million.
The full picture looks like this:

Public on-chain records show that A and B were added to the USDT blacklist at the same moment, 02:29:15 on September 9.
A still held about 37,839 USDT, so that amount was frozen. B’s balance had already been emptied, so although it was frozen too, the amount frozen was 0.
So the agent didn’t just find the new collection wallet named in public reports. It followed it further, to the relay wallet and the two transfers that split off after it.
How did the agent actually do it?
On the surface, this was a “find the new address” problem. In practice, what the agent did was investigate a business migration.
It first found the break point from changes in what the old wallets received and sent, then looked for continuity in four directions: where the old payers went, where money was still flowing, which addresses were activated or supplied with resources by the same wallets, and whether the old wallets had moved money out directly or one or two hops away.
Once it had candidates, it compared their behavior before and after the freeze. An address that was already very active before the freeze is more likely an old hub; an address that appeared right after the freeze and quickly took over a similar role in receiving and sending money is the one that looks like the new successor.
Finally, for every candidate it actively looked for evidence against it. Shared payers might just be shared customers, a shared energy source might just be a public service, and a surge in volume might just be the existing business growing.
Only after these ordinary explanations had been ruled out one by one did the remaining relationships earn a place in the conclusion.
We focus on AI agents for analyzing, mining and tracing USDT funds on the TRON chain. We want to turn work that used to depend on people checking layer after layer by hand into an investigation process that finds leads, verifies relationships and organizes the evidence on its own.
If this direction interests you, or you’re dealing with a real problem like this in your work, feel free to get in touch.
Sources
- Elliptic: 52 related wallets and $52.8 million in USDT frozen https://www.elliptic.co/insights/elliptic-helps-us-secret-service-freeze-xinbi-scam-marketplace-assets/
- Bitrace: the Xinbi Guarantee freeze, and the stopgap replacement wallet frozen again https://blog.bitrace.io/xinbi-guarantee-loses-over-45-million-in-aggressive-enforcement-action-highlighting-frozen-funds-risk/
- US Department of Justice: joint action against Xinbi Guarantee and related networks https://www.justice.gov/usao-dc/pr/scam-center-strike-force-conducts-seizures-chinese-run-illicit-scammer-marketplace-and
- US Treasury OFAC: sanctions information published on September 9, 2026 https://ofac.treasury.gov/recent-actions/20260909