Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion
A Telegram-based guarantee marketplace known for advertising a broad range of illicit services appears to be winding down its operations, according to new findings from Elliptic. The blockchain intelligence company said Tudou Guarantee has effectively ceased transactions through its public Telegram groups following a period of significant growth. The marketplace is estimated to have processed
AI Analysis
Technical Summary
Tudou Guarantee was a prominent Telegram-based guarantee marketplace that facilitated a wide range of illicit services, including the sale of stolen personal data, money laundering, scam infrastructure such as fraudulent investment platforms and phishing websites, and advanced AI-powered tools like face swapping, voice cloning, and deepfake impersonation. It processed over $12 billion in transactions, making it the third-largest illicit marketplace by volume. The platform emerged as a successor to HuiOne Guarantee after Telegram shut down many related channels, with HuiOne acquiring a financial stake in Tudou Guarantee to maintain vendor continuity. The marketplace's recent cessation of transactions on public Telegram groups coincides with law enforcement actions against the Cambodian conglomerate Prince Group and its CEO Chen Zhi, implicated in large-scale romance baiting and pig butchering scams involving forced labor camps. Despite the shutdown of public transactions, parts of Tudou Guarantee, such as gambling operations, remain functional, indicating a possible pivot rather than a full closure. The ecosystem of Telegram-based scam marketplaces remains resilient, with other platforms like Xinbi Guarantee recovering and continuing operations. The use of AI services by scammers has grown exponentially, enabling more convincing and scalable fraud campaigns. Law enforcement agencies, including a U.S. Scam Center Strike Force, are actively targeting these networks, seizing hundreds of millions in cryptocurrency and disrupting infrastructure. However, the decentralized nature of these marketplaces and their migration across platforms pose ongoing challenges for global cybersecurity efforts.
Potential Impact
European organizations are at risk primarily through indirect exposure to the advanced fraud tools and services offered by Tudou Guarantee and similar marketplaces. These illicit platforms enable cybercriminals to conduct sophisticated scams, including identity theft, phishing, investment fraud, and AI-driven impersonation attacks that can target European individuals and businesses. The availability of AI-powered deepfake and voice cloning technologies increases the likelihood of successful social engineering and business email compromise attacks. Financial institutions, critical infrastructure, and enterprises handling sensitive personal data are particularly vulnerable to these evolving threats. Additionally, the laundering of illicit funds through cryptocurrency can impact European financial systems and complicate regulatory compliance efforts. The disruption of Tudou Guarantee may temporarily reduce certain fraud activities but is unlikely to diminish the overall threat landscape, as displaced actors migrate to other platforms. This persistence necessitates heightened vigilance and adaptive security measures within Europe to counter increasingly sophisticated cyber fraud campaigns.
Mitigation Recommendations
European organizations should implement multi-layered defenses tailored to combat AI-enhanced social engineering and fraud. This includes deploying advanced email and communication filtering solutions capable of detecting deepfake audio and video content, and integrating behavioral analytics to identify anomalous user activities indicative of impersonation. Financial institutions should enhance transaction monitoring with AI-driven anomaly detection to flag suspicious transfers potentially linked to laundering. Organizations must conduct regular employee training focused on recognizing AI-driven scams and social engineering tactics. Collaboration with law enforcement and participation in information-sharing initiatives can improve threat intelligence on emerging scam marketplaces. Additionally, enforcing strict identity verification processes, including multi-factor authentication and biometric checks resistant to spoofing, can reduce fraud risk. Monitoring cryptocurrency transactions for links to known illicit wallets and cooperating with blockchain intelligence firms can aid in disrupting financial flows. Finally, organizations should prepare incident response plans that account for AI-enabled fraud scenarios to ensure rapid containment and remediation.
Affected Countries
United Kingdom, Germany, France, Netherlands, Italy, Spain, Belgium, Sweden, Poland, Ireland
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion
Description
A Telegram-based guarantee marketplace known for advertising a broad range of illicit services appears to be winding down its operations, according to new findings from Elliptic. The blockchain intelligence company said Tudou Guarantee has effectively ceased transactions through its public Telegram groups following a period of significant growth. The marketplace is estimated to have processed
AI-Powered Analysis
Technical Analysis
Tudou Guarantee was a prominent Telegram-based guarantee marketplace that facilitated a wide range of illicit services, including the sale of stolen personal data, money laundering, scam infrastructure such as fraudulent investment platforms and phishing websites, and advanced AI-powered tools like face swapping, voice cloning, and deepfake impersonation. It processed over $12 billion in transactions, making it the third-largest illicit marketplace by volume. The platform emerged as a successor to HuiOne Guarantee after Telegram shut down many related channels, with HuiOne acquiring a financial stake in Tudou Guarantee to maintain vendor continuity. The marketplace's recent cessation of transactions on public Telegram groups coincides with law enforcement actions against the Cambodian conglomerate Prince Group and its CEO Chen Zhi, implicated in large-scale romance baiting and pig butchering scams involving forced labor camps. Despite the shutdown of public transactions, parts of Tudou Guarantee, such as gambling operations, remain functional, indicating a possible pivot rather than a full closure. The ecosystem of Telegram-based scam marketplaces remains resilient, with other platforms like Xinbi Guarantee recovering and continuing operations. The use of AI services by scammers has grown exponentially, enabling more convincing and scalable fraud campaigns. Law enforcement agencies, including a U.S. Scam Center Strike Force, are actively targeting these networks, seizing hundreds of millions in cryptocurrency and disrupting infrastructure. However, the decentralized nature of these marketplaces and their migration across platforms pose ongoing challenges for global cybersecurity efforts.
Potential Impact
European organizations are at risk primarily through indirect exposure to the advanced fraud tools and services offered by Tudou Guarantee and similar marketplaces. These illicit platforms enable cybercriminals to conduct sophisticated scams, including identity theft, phishing, investment fraud, and AI-driven impersonation attacks that can target European individuals and businesses. The availability of AI-powered deepfake and voice cloning technologies increases the likelihood of successful social engineering and business email compromise attacks. Financial institutions, critical infrastructure, and enterprises handling sensitive personal data are particularly vulnerable to these evolving threats. Additionally, the laundering of illicit funds through cryptocurrency can impact European financial systems and complicate regulatory compliance efforts. The disruption of Tudou Guarantee may temporarily reduce certain fraud activities but is unlikely to diminish the overall threat landscape, as displaced actors migrate to other platforms. This persistence necessitates heightened vigilance and adaptive security measures within Europe to counter increasingly sophisticated cyber fraud campaigns.
Mitigation Recommendations
European organizations should implement multi-layered defenses tailored to combat AI-enhanced social engineering and fraud. This includes deploying advanced email and communication filtering solutions capable of detecting deepfake audio and video content, and integrating behavioral analytics to identify anomalous user activities indicative of impersonation. Financial institutions should enhance transaction monitoring with AI-driven anomaly detection to flag suspicious transfers potentially linked to laundering. Organizations must conduct regular employee training focused on recognizing AI-driven scams and social engineering tactics. Collaboration with law enforcement and participation in information-sharing initiatives can improve threat intelligence on emerging scam marketplaces. Additionally, enforcing strict identity verification processes, including multi-factor authentication and biometric checks resistant to spoofing, can reduce fraud risk. Monitoring cryptocurrency transactions for links to known illicit wallets and cooperating with blockchain intelligence firms can aid in disrupting financial flows. Finally, organizations should prepare incident response plans that account for AI-enabled fraud scenarios to ensure rapid containment and remediation.
Technical Details
- Article Source
- {"url":"https://thehackernews.com/2026/01/tudou-guarantee-marketplace-halts.html","fetched":true,"fetchedAt":"2026-01-21T03:06:10.436Z","wordCount":1184}
Threat ID: 697042a44623b1157c81b958
Added to database: 1/21/2026, 3:06:12 AM
Last enriched: 1/21/2026, 3:08:26 AM
Last updated: 2/7/2026, 2:55:44 AM
Views: 78
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2026-25764: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in opf openproject
LowCVE-2026-25729: CWE-863: Incorrect Authorization in lintsinghua DeepAudit
LowCVE-2025-15320: Multiple Binds to the Same Port in Tanium Tanium Client
LowCVE-2026-25724: CWE-61: UNIX Symbolic Link (Symlink) Following in anthropics claude-code
LowCVE-2026-1337: CWE-117 Improper Output Neutralization for Logs in neo4j Enterprise Edition
LowActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.