Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


A crypto dusting attack sends a very small amount of cryptocurrency to one or more public addresses, often to observe whether recipients later combine that dust with other funds. The resulting transaction relationships can support address clustering and, when combined with off-chain data, identity inference. On smart-contract networks, unsolicited tokens may instead be interaction lures; not every tiny balance is malicious.
Key Takeaways
- Dust is a small amount; intent determines whether it is ordinary change, spam, a privacy probe, or a scam lure.
- On UTXO networks, spending dust together with other inputs can reveal a probable common-control relationship.
- An unsolicited token does not prove that a wallet or private key was compromised.
- Do not follow links, approve contracts, or sign messages merely to sell, claim, hide, or “clean” an unknown asset.
- Response depends on the network and wallet: coin control may isolate a UTXO, while an unknown token may simply be hidden.
On a UTXO network such as Bitcoin, a wallet balance consists of separate unspent transaction outputs. An attacker distributes tiny outputs to many addresses. If a recipient later selects one of those outputs together with other UTXOs as inputs to a transaction, an observer may infer that the inputs are controlled by the same wallet or person. Ledger describes dusting as a privacy attack that relies on tracking subsequent movement.[2]
The inference is not mathematical proof of identity. Wallet construction, collaborative transactions, exchanges, payment processors, and other behavior can make simple heuristics wrong. But clustering can become more informative when combined with exchange records, merchant data, reused addresses, public donation pages, social posts, IP logs, or timing patterns.
Bitcoin's white paper explains that transactions are publicly announced and recommends using a new key pair for each transaction to limit linkage, while acknowledging that multi-input transactions can reveal common ownership.[3] Dusting exploits this public graph rather than breaking signatures or decrypting a wallet.
| Event | Likely category | Main risk | Safer response |
|---|---|---|---|
| Small remainder from your own payment | Ordinary change | Routine fee and privacy considerations | Label it and manage normally |
| Tiny unknown UTXO sent to an address | Possible dust probe | Later input clustering | Freeze or exclude with coin control if supported |
| Unknown token with a website in its name | Scam-token lure | Malicious approval or signature | Do not visit or interact; hide it |
| Zero-value look-alike history event | Address poisoning | Copying a fake destination | Verify a fresh full address |
| Legitimate promotional airdrop | Marketing distribution | Tax, privacy, and contract risk vary | Verify issuer and terms independently |
“Dust” can mean an output whose value is uneconomical to spend because the fee would be comparable to or greater than the amount. Wallets may create small change outputs during ordinary payments. Services may send tiny verification deposits. Networks and software use different economic thresholds, so there is no universal amount that proves malicious intent.
On account-based chains, a tiny native-coin transfer does not behave like a Bitcoin UTXO, because balances are not selected as separate inputs in the same way. A random token can still create a visible balance or activity row, but the primary trap may be a URL, fake price, or contract interaction rather than input clustering.
Do not diagnose solely from the amount. Consider whether you recognize the sender, whether the asset is genuine, whether the event contains promotional text, whether many addresses received the same transfer, and whether the wallet warns that it is spam.
Address poisoning uses a look-alike address in history to induce a mistaken future payment. A dusting attack in the narrower privacy sense tries to learn relationships from later spending. One transaction can potentially serve both goals, but the defenses differ: full destination verification defeats the copying trap, while UTXO isolation limits clustering.
Scam tokens often display an enticing name, supposed value, claim instruction, or website. Their goal may be to make the holder connect to a malicious dapp, approve spending, reveal information, or sign a transaction. Trezor advises users not to interact with suspicious airdrop or dust tokens and describes hiding them in the wallet interface.[1]
The wallet address poisoning guide explains the look-alike pattern. Neither a poisoned row nor an unknown token should be used as the source for a receiving address.
First, label the unknown output and preserve its transaction ID for your own records. If the wallet supports coin control, freeze or exclude that UTXO so automatic input selection does not combine it with other funds. Confirm what “freeze” means in that wallet; it is usually a local selection rule, not an on-chain change.
Do not consolidate the suspicious output merely to make the balance look clean. Consolidation can create the exact link the observer wants. Likewise, moving every asset to a new address in one transaction can expose more relationships rather than fewer.
If your wallet lacks coin control, consult its official documentation before spending. Importing the seed into an unfamiliar wallet to gain a feature may create a much greater key-exposure risk. For meaningful privacy needs, obtain advice that accounts for the specific network, wallet implementation, transaction graph, and legal context.
Do not click a URL in the token name, symbol, NFT image, memo, or explorer comment. Do not call an unknown contract to “burn,” “return,” “unlock,” “verify,” or sell the asset. Do not sign a gasless message without understanding its typed data; a signature can authorize a permit or marketplace action.
Hide or mark the asset as spam if the wallet offers that local control. Hiding changes the display, not the blockchain, and generally does not require a transaction. Verify any real airdrop through a project's known domain and independently documented contract address.
If you already interacted, review the transaction and any approvals on the correct chain. Unexpected outgoing transfers or signatures belong in the crypto hacks incident guide, not a cosmetic cleanup workflow.
Avoid address reuse where the network and operational context support fresh receive addresses. Label your own UTXOs so you understand their origin. Use coin control deliberately rather than automatically combining funds from unrelated contexts. Remember that sending through a centralized service can add identity records even if it changes the visible on-chain path.
Do not assume one privacy tool solves every layer. The Bitcoin anonymity guide explains how public-ledger, exchange, and network metadata can reinforce one another. The self-custody comparison explains who controls signing and account records, while the online security guide provides a broader risk checklist.
Keep local labels for source, purpose, and sensitivity before balances become complicated. Labels do not make transactions private, but they help prevent automatic coin selection from mixing unrelated identities. Check whether wallet metadata syncs to a cloud service before placing personal details in a label.
Record the expected sender and purpose when you issue a receive address, without placing sensitive identity details in public notes. That context helps distinguish ordinary change, a legitimate verification payment, and an unexplained deposit later. Treat wallet metadata backups and cloud synchronization as separate privacy boundaries.
AethoVPN can reduce local-network exposure of traffic and your source IP to destination services, but it cannot stop public on-chain clustering, erase transaction history, isolate a dust UTXO, or make an unknown token safe to interact with.
A crypto dusting attack uses a tiny transfer as a signal or lure. On UTXO networks, the danger is often that later co-spending reveals probable common control. On smart-contract networks, an unsolicited asset may instead tempt the user into a malicious site, approval, or signature. Identify the network model, avoid unnecessary interaction, use trusted wallet controls, and do not create a larger privacy leak merely to remove a small visible balance.
No. Public addresses can normally receive transfers from anyone. Key compromise requires separate evidence such as unauthorized signing or outgoing transactions.
Ordinary receipt does not authorize spending. Risk arises from later clustering or from signing a malicious interaction prompted by a scam asset.
Usually not. Sending it can link activity, cost fees, or interact with an attacker-controlled contract.
Not automatically. A careless consolidation can reveal more links. Choose a response based on the network and wallet controls.
Coin control lets a user select or exclude individual UTXOs when building a transaction. Availability and behavior vary by wallet.
No. It may be spam, marketing, a scam lure, or an accidental transfer. Treat it as untrusted until independently verified.
No. You may be able to hide it locally or exclude an output, but confirmed public history remains.
No. A VPN does not control who can send to a public address or how blockchain analysts cluster public transactions.
Disclaimer: This article provides general security and privacy information, not legal, tax, financial, investment, or transaction advice.
Sources checked 8 September 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





