SardineCon SF/2026

Learn More

O que é Dusting attack?

SUBSCRIBE

A dusting attack is sending tiny, unsolicited amounts of crypto to many wallets, so that when the dust is later spent alongside other funds, the sender can use clustering to link addresses and unmask or profile the owners. It chips away at the privacy that protects legitimate users, one small deposit at a time.

What is a dusting attack, in plain English?

Dust is a trivially small amount of crypto, too little to be worth spending on its own. In a dusting attack, a sender sprays that dust to many wallets at once, unsolicited. The goal is not to give anyone money; it is to plant a marker the attacker can later follow.

The attack pays off when a recipient spends the dust along with their real funds. Because a single transaction can combine several of a user's addresses as inputs, spending the dust ties it to the rest of the wallet. Using clustering, the attacker links those addresses together and can start to profile or unmask the owner, connecting activity that was supposed to stay separate.

This matters because it attacks privacy, which is a legitimate protection for ordinary users, not just criminals. Its mechanics overlap with address poisoning, since both send tiny unsolicited amounts, but the intent differs: dusting aims to deanonymize, and it often sets up targeted phishing, extortion, or surveillance once the attacker knows who they are dealing with.

How a dusting attack works

  1. Spray — Send dust widely. The attacker sends tiny unsolicited amounts to many wallets at once.
  2. Wait — Let it sit. The dust rests in each wallet until the owner unknowingly spends it with other funds.
  3. Link — Cluster the addresses. When the dust is combined with real inputs, the attacker links the addresses to one owner.
  4. Exploit — Profile or target. With identity clues in hand, the attacker sets up phishing, extortion, or surveillance.

Who is involved?

Who

Their role

The attacker

Sprays dust to many wallets and clusters the addresses of anyone who spends it.

The wallet owner

Receives unsolicited dust and risks linking their addresses by spending it.

Wallet software

Can mark dust as do-not-spend so it never mixes with real funds.

The analyst

Distinguishes benign dust from a coordinated deanonymization campaign.

What it looks like in practice

In practice

A user notices a tiny, unexpected amount of crypto appear in their wallet, an amount too small to matter. Dozens of other wallets received the same speck around the same time. It looks harmless, so the user pays it no attention.

Later, sending a routine payment, their wallet automatically includes that dust as one of the inputs, combining it with their main balance. The attacker who sent the dust now sees it spent alongside the user's other addresses, links them into one cluster, and pieces together a profile. Not long after, the user receives an unusually well-targeted phishing message that seems to know their holdings.

Why it matters to operators

Dusting is a reminder that on-chain privacy is fragile and that the threat is not always theft. The immediate loss is zero, but the erosion of anonymity sets up later harm: precisely targeted phishing, extortion aimed at someone known to hold funds, or surveillance of a person's whole wallet history. For teams protecting users, warning about dust and helping people avoid spending it is a cheap, effective control.

The trap is subtle. A user who spends the dust by accident hands the attacker exactly the link they wanted, so the defense is behavioral: leave dust unspent or explicitly mark it do-not-spend so it never mixes with real funds. For analysts, distinguishing a genuine deanonymization campaign from harmless stray dust matters, because overreacting to every speck is noise while missing a coordinated spray misses the real threat.

What to watch in the data

  • Mass tiny unsolicited transfers. The same trivial amount landing in many wallets around the same time is the core dusting signature.
  • Dust later combined with real inputs. A transaction that spends dust alongside a user's main funds is the moment the link is made.
  • Clustering follow-up. Addresses being grouped shortly after dust is spent suggests active deanonymization.
  • Targeted phishing after dusting. Unusually well-informed scam attempts following a dust event point to a completed profile.
  • Overlap with address poisoning. Tiny sends that mimic a known counterparty are poisoning, not dusting; check the intent.

Quick questions

Does receiving dust mean I have been hacked?

No. Receiving dust is passive and harmless on its own; it cannot move your funds. The risk only materializes if you spend the dust together with your real funds, which is what lets the attacker link your addresses.

Why would someone send me free crypto?

It is not a gift. The dust is a tracking marker. The attacker wants you to spend it so they can cluster your addresses and profile you, usually to set up targeted phishing, extortion, or surveillance.

How do I protect myself?

Do not spend the dust. Many wallets let you mark it do-not-spend or freeze it so it never gets combined with your real funds. Leaving it untouched denies the attacker the link they are after.

How is dusting different from address poisoning?

Both send tiny unsolicited amounts, but the goals differ. Dusting aims to deanonymize you through clustering. Address poisoning plants a lookalike address so you later send a real payment to the attacker by mistake.

Can dusting be used against businesses?

Yes. Any wallet holder can be dusted, including exchanges and companies. Linking a business's addresses can reveal operational details or set up targeted attacks, so treating unsolicited dust cautiously applies to organizations too.

Should analysts flag every dust transaction?

Not blindly. Isolated dust is often noise. What matters is a coordinated spray across many wallets, dust later spent with real funds, and clustering or targeting that follows. Judge the pattern, not a single speck.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • OFAC, US Treasury ↗ — Administers US sanctions programs, the SDN list, and licensing.

O que saber junto com Dusting attack