Attacks
Tiny unrequested amounts sent to your wallet so somebody can follow what you do next. A dusting attack sends a trivial amount of a token to thousands of wallets at once. On its own the dust cannot hurt you and it cannot move your funds. The point is what happens if you spend it: on chains where spending combines inputs, moving the dust links your addresses together and de anonymises the set. The other version is bait, where the dust is a token whose name is a website address, and the website is a drainer.
What it is
A dusting attack sends a trivial amount of a token to thousands of wallets at once. On its own the dust cannot hurt you and it cannot move your funds. The point is what happens if you spend it: on chains where spending combines inputs, moving the dust links your addresses together and de anonymises the set. The other version is bait, where the dust is a token whose name is a website address, and the website is a drainer.
How it plays out
Dust arrives unannounced
A fraction of a cent of a token you never bought, often across many of your addresses at once.
The token is named to be clicked
Names like "claim 5000 USDT at some-site.com" or a token that copies a real project. The name field is the payload.
Spending it links your wallets
On Bitcoin and other UTXO chains, spending dust alongside your real coins tells a chain analyst that both addresses belong to one person.
Or you visit the site
And the site asks for a wallet connection and a signature, which is where the actual loss happens.
What gives it away
- Tokens appearing that you did not buy, especially with a URL in the name.
- The same tiny amount arriving at several of your addresses.
- A token with a real project’s name but a contract address that does not match.
- Anything promising a claim, a reward or a refund.
How to not be caught by it
- Leave it alone. Dust that is never spent and never clicked does nothing.
- Hide or mark the token as spam in your wallet rather than interacting with it.
- Never visit a domain that arrives inside a token name.
- On Bitcoin, use a wallet with coin control and freeze the dust so it can never be spent by accident.
- Keep addresses separated by purpose, so a link between two of them reveals less.
If it already happened
- Do nothing, in most cases. Receiving dust is not a compromise.
- Do not try to send it back. That costs gas and confirms the address is live.
- If you already visited the site and connected, revoke approvals and move funds to a fresh wallet.
- If you already spent the dust, treat those addresses as publicly linked from now on.
Common questions
How common is wallet dusting?
Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.
Can the money be recovered?
Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.
Does a hardware wallet stop this?
It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.
Where to go next
Check your setup before you need to
An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.