Dusting Attack
A dusting attack is the practice of sending tiny amounts of cryptocurrency — "dust" — to a large number of wallets, typically to later track which addresses interact with or combine that dust in future transactions, deanonymizing the wallet owner's broader holdings.
Dusting Attack
A dusting attack is the practice of sending tiny amounts of cryptocurrency — "dust" — to a large number of wallets, typically to later track which addresses interact with or combine that dust in future transactions, deanonymizing the wallet owner's broader holdings.
What it means
The tracking mechanism relies on how wallets often handle UTXOs or token balances: if a victim later spends funds from an address that includes the dust, and that spend combines inputs from multiple addresses in one transaction, the attacker can infer those addresses are controlled by the same entity, chipping away at the anonymity a fresh address would otherwise provide.
Dusting is also used as a delivery mechanism for address-poisoning attacks specifically, and separately as a low-cost reconnaissance step by analytics firms and researchers doing entity clustering for entirely legitimate purposes — the technique itself is not inherently malicious, only its typical application often is.
Real-world example
Large-scale dusting campaigns have sent tiny amounts of Bitcoin or Litecoin to tens of thousands of addresses simultaneously, with researchers later observing which recipients combined the dust with other funds, revealing wallet clusters the attacker could not have identified otherwise.
Related terms
In FreezeRadar
A FreezeRadar scan flags unexplained dust deposits in a wallet's history as a low-severity but worth-noting finding, distinct from genuine incoming payments.
By FreezeRadar Team
Research and product team behind FreezeRadar.
Related reading
Continue exploring FreezeRadar knowledge content.