A crypto dust attack explained simply is an attempt to send a tiny amount of cryptocurrency or a token to your wallet so the sender can observe what you do next. The deposit usually cannot access your private keys, but spending or combining it can connect your wallet to an address associated with scams, sanctions, or other suspicious activity.
This week, reports linked unsolicited deposits received by some Kraken customers to a wallet described as sanctioned and associated with HTX. The incident matters for self-custody users because a transaction you did not request can still become part of your wallet’s public history. The safest response is usually to leave the funds untouched, record the transaction details, and ask the relevant wallet or exchange compliance team for instructions.
What changed this week
On August 26, 2026, reports said Kraken users were affected by a dust attack involving small deposits traced to a wallet linked to a sanctioned entity or address. Bitcoin Magazine reported on August 26, 2026 that Kraken said affected customers were locked out while the exchange handled the matter. A separate August 26 market-news report described the same development.
The precise status of an address can depend on the blockchain, jurisdiction, and screening provider. A report that funds came from a sanctioned wallet is not the same as a finding that every recipient violated sanctions. Receiving an unsolicited transfer does not prove that a recipient knew the sender, controlled the source, or intended to support a prohibited activity.
What changed this week is the practical visibility of a known risk: a tiny deposit can trigger automated monitoring even when the recipient did nothing to request it. For someone holding their own crypto, that means keeping a clean transaction record and separating suspicious funds can be as important as protecting a seed phrase.
What is a dust attack?
“Dust” is a very small amount of crypto. The term originally became common in connection with Bitcoin’s UTXO model, where each unspent transaction output is a discrete piece of value. Dust can also describe tiny transfers of tokens on account-based networks such as Ethereum, Tron, or Solana.
A dust attack uses that small transfer as a tracking or attribution tool. The attacker may watch whether the recipient later moves the dust together with other funds. If that happens, blockchain analysts can form a stronger connection between the recipient address and the sender’s address.
A dust transfer is not automatically an attack. Exchanges, faucets, refunds, airdrops, spam campaigns, and ordinary user errors can all create small unexpected deposits. The warning signs are the combination of an unsolicited transfer, an unfamiliar source, an unusual token or memo, and a request to interact with the asset.
Bitcoin-style UTXO dust
Bitcoin and similar networks use UTXOs. When you spend several UTXOs in one transaction, observers often use the common-input heuristic to infer that the inputs may belong to the same wallet or owner.
Suppose your wallet contains five normal UTXOs and one tiny output from a suspicious address. If your wallet software selects all six as inputs for a later payment, the transaction may publicly associate the suspicious output with the five normal ones. The blockchain does not label that connection as legally conclusive, but exchanges and analytics companies may treat it as a risk signal.
Coin selection can reduce unnecessary linkage, but it cannot erase a transaction already confirmed on-chain. This is one reason to understand how your wallet handles small outputs before spending them.
Token dust on account-based networks
On account-based chains, a wallet balance is generally represented by an account state rather than a collection of independent UTXOs. A token transfer can appear in the wallet’s history without being something you chose to receive.
Simply receiving a token does not normally give the sender control of your wallet. The danger can arise when you approve a contract, sign a message, visit a linked website, or transfer the token. Some unsolicited tokens are designed to lure users into phishing sites or malicious approval flows rather than to perform classic transaction tracing.
Why privacy and compliance can overlap
Public blockchains make transaction histories visible. Analytics providers cluster addresses using transaction patterns, exchange deposits, known service addresses, timing, and other heuristics. A tiny transfer can therefore become a breadcrumb even if its value is economically insignificant.
The compliance concern is not that every address touched by suspicious funds becomes permanently “tainted.” Blockchain screening is risk-based and contextual. Investigators may examine the source, amount, timing, wallet behavior, intermediary services, and whether the recipient voluntarily moved or interacted with the funds.
The U.S. Treasury’s Office of Foreign Assets Control virtual-currency guidance, published in October 2021, explains that digital-asset businesses should use a risk-based sanctions compliance program and consider sanctions screening, transaction monitoring, and reporting procedures. That guidance is directed primarily at relevant businesses and does not mean an accidental recipient automatically committed a violation.
For a self-custody holder, the practical consequence is more limited but still important: an exchange may pause a deposit, request information, or review a wallet relationship. You may need to show that the transfer was unsolicited and that you did not move or use it.
The FATF red-flag indicators for virtual assets, published in September 2020, also describe transaction patterns and contextual signals that can warrant further investigation. These indicators are not proof of wrongdoing; they help compliance teams decide when to ask questions.
How to identify suspicious dust
No single amount defines dust. A tiny deposit can be suspicious, but a larger unexpected transfer can be suspicious too. Review the transaction in your wallet and, where necessary, in a reputable block explorer.
Look for these signals:
- You did not share the address for the transfer and do not recognize the sender.
- The amount is unusually small, repeatedly rounded, or sent to many unrelated addresses.
- The sender is associated with a sanctioned service, exploit, mixer, scam, or other high-risk activity according to a reputable screening source.
- The transaction includes an unfamiliar token, NFT, memo, URL, or message telling you to claim or recover funds.
- A website or social-media account asks you to connect your wallet, sign a message, approve a contract, or send the funds back.
- An exchange later asks about a deposit that appears to connect to the unsolicited transfer.
Treat labels from explorers as clues, not final legal conclusions. Different analytics providers can produce different results, and a wallet address can be used by more than one person or service over time.
What to do after receiving dust
1. Do not interact with it
Do not spend, swap, consolidate, approve, bridge, stake, or send back suspicious funds simply because the amount is small. On a UTXO chain, spending the output can link it to your other inputs. On a token network, interacting with a token or its website can expose you to phishing or malicious contract permissions.
Receiving an unsolicited asset does not require you to click a link or respond to the sender. Ignore claims that you must pay a fee, connect a wallet, or sign a transaction to “unlock” or “remove” dust.
2. Record the evidence
Save the transaction ID, network, asset contract or token identifier, amount, timestamp, sender address, and recipient address. Take screenshots of the wallet display and explorer page, but never share your seed phrase, private key, recovery file, or wallet password.
Keep the record with your ordinary transaction history. A clear note such as unsolicited deposit received on August 27, 2026 can help explain why the asset remains untouched.
3. Isolate it where possible
If your wallet supports separate addresses or accounts, keep suspicious assets away from funds you regularly use. For UTXO-based assets, do not manually select the suspicious output as an input. For account-based tokens, hide or ignore the asset rather than opening its website or approving a contract.
Creating a new address is not a magic privacy reset. If you later move funds between addresses, the transaction may still reveal a relationship. Read our wallet threat model guide for a broader framework covering privacy, recovery, and custody decisions.
4. Contact the right provider
If an exchange deposit or withdrawal is involved, contact the exchange through its official support channel. Explain that the transfer was unsolicited and provide the transaction ID. Do not rely on a message embedded in the transfer, a social-media account, or a support contact supplied by the sender.
A self-custody wallet provider generally cannot reverse a confirmed blockchain transaction. It may be able to explain how to hide an asset, avoid selecting a UTXO, or report a phishing token, but it cannot declare that a transaction is legally safe in every jurisdiction.
5. Get specialist advice for material exposure
If the amount is substantial, your business depends on regulated exchange access, or you believe the funds may be connected to a hack or sanctioned party, consult a qualified lawyer or compliance professional in your jurisdiction. Do not attempt to “clean” or obscure the funds with mixers, rapid hops, bridges, or unnecessary transfers.
Dust attack versus other wallet threats
| Threat | Typical mechanism | Main risk | Safer first response |
|---|---|---|---|
| Dust attack | Sends a small transfer and watches later spending | Privacy linkage or compliance review | Leave it untouched and document it |
| Phishing token or NFT | Lures you to a fake site or malicious contract | Loss through approval or signed transaction | Do not visit links or sign transactions |
| Address poisoning | Creates a lookalike address in transaction history | Sending future funds to the wrong address | Verify the full destination address |
| Wallet drainer | Tricks you into approving or signing a harmful action | Direct loss of assets | Disconnect, revoke risky approvals, and secure the wallet |
A dust attack is therefore different from a wallet hack. The attacker usually does not need to compromise your device or obtain your keys. The attack relies on public transaction data and on the recipient voluntarily creating a stronger on-chain association.
How self-custody users can reduce future exposure
Use a separate address or account for activities that require public sharing, such as trading, donations, or interacting with unfamiliar applications. Keep long-term holdings separate from experimental activity, and avoid posting a full wallet address alongside personal information when it is not necessary.
Before sending funds, verify the network and complete destination address using a trusted channel. For recurring payments, maintain an address book or contact record rather than copying the most recent incoming address. These habits reduce both dust-related linkage and ordinary address-poisoning mistakes.
Review wallet permissions on smart-contract networks, but do so through a trusted tool and only when you understand what you are revoking. A received token is not a reason to connect to its advertised website. For broader compliance context, our guide to the crypto Travel Rule explains why exchanges collect transfer information even when users hold assets in self-custody.
The key takeaway
The August 26 reports show why “tiny” does not mean “irrelevant.” An unsolicited deposit may have little market value, yet spending it can add a visible link between your wallet and a risky source, while interacting with an unfamiliar token can create a separate phishing threat.
Treat unexpected funds as evidence to preserve, not money to use. Leave them alone, document the transaction, separate them where practical, and contact the relevant exchange or a qualified professional if a compliance review follows.
This article is for educational purposes and is not financial advice.



