Loading data...

Dusting Attack

Security

Sending tiny amounts to deanonymize or trick users.

A dusting attack sends tiny amounts of cryptocurrency or unsolicited tokens to wallet addresses so an attacker can analyze behavior or lure recipients into unsafe interactions. The dust itself normally cannot steal assets or reveal a private key. Risk arises from later spending patterns, phishing links, malicious approvals, or confusion in transaction history.

On Bitcoin-style UTXO networks, an attacker distributes small outputs and watches where they move. If a wallet later combines one of those outputs with funds from other addresses in the same transaction, blockchain analysis may infer common ownership. Additional exchange deposits, public payment addresses, or reused identity information can help connect the cluster to a person.

On Ethereum and similar networks, “dusting attack” also describes spam token transfers. Token names, symbols, or metadata may display a website promising a claim or sale. The site then requests a seed phrase, malicious signature, or unlimited approval. Some zero-value or tiny transfers instead support address poisoning by placing a lookalike destination in the victim's history.

These attacks matter because public blockchains preserve transaction records. A small action can weaken privacy long after it occurs, and wallet interfaces make unsolicited tokens look legitimate. Companies, donors, and individuals separating addresses for privacy should consider how later consolidation, gas funding, and exchange withdrawals reconnect them.

Receiving dust does not mean the wallet is hacked. Avoid panic and do not interact merely to remove it. Hide unknown assets, ignore embedded links, and never copy a payment address from recent history. On UTXO wallets, coin-control features can prevent a suspicious output from being spent, though privacy tools require careful use and network-specific guidance.

Wallet providers should label spam, show full addresses, and avoid turning token metadata into clickable trust signals. Users should verify domains and contracts through independent official sources. If an unknown token has already been approved, review and revoke permissions through a reputable tool, then monitor activity. Moving valuable funds may be appropriate after a malicious signature, but simple dust receipt alone does not require abandoning an otherwise secure wallet.

Teams investigating targeted dust should preserve transaction hashes and review related address activity without interacting. Privacy specialists or blockchain analysts can help assess exposure when sensitive identities or treasury accounts are involved.

Frequently asked questions

  • An attacker sends tiny amounts to many public addresses and watches later blockchain activity. On UTXO networks, spending the dust with other outputs can help cluster addresses under common control. On smart contract chains, spam tokens may advertise phishing sites or provoke an approval. The technique analyzes public behavior rather than directly extracting a private key.
  • Do not visit links embedded in unknown token names, metadata, transaction notes, or direct messages. Hide spam assets and avoid transferring, selling, approving, or burning them through unfamiliar contracts. Use wallet coin-control features where appropriate and avoid combining identity-separated funds. Obtain software and support only through verified sources, and inspect every signature before approval.
  • Some known assets can be transferred, consolidated, or sent to a valid burn mechanism, but action may cost more than the balance and reveal information. Unknown tokens are usually safest left untouched and hidden in the interface. Removing a display does not change blockchain history. Never use a website that requests a seed phrase or broad permission to clean a wallet.