Glossary
2 min readPublished April 24, 2026

Dusting Attack

A dusting attack is the practice of sending tiny amounts of cryptocurrency — "dust" — to a large number of wallets, typically to later track which addresses interact with or combine that dust in future transactions, deanonymizing the wallet owner's broader holdings.

Analysis Patterns
#on-chain-analysis
#monitoring

Dusting Attack

A dusting attack is the practice of sending tiny amounts of cryptocurrency — "dust" — to a large number of wallets, typically to later track which addresses interact with or combine that dust in future transactions, deanonymizing the wallet owner's broader holdings.

What it means

The tracking mechanism relies on how wallets often handle UTXOs or token balances: if a victim later spends funds from an address that includes the dust, and that spend combines inputs from multiple addresses in one transaction, the attacker can infer those addresses are controlled by the same entity, chipping away at the anonymity a fresh address would otherwise provide.

Dusting is also used as a delivery mechanism for address-poisoning attacks specifically, and separately as a low-cost reconnaissance step by analytics firms and researchers doing entity clustering for entirely legitimate purposes — the technique itself is not inherently malicious, only its typical application often is.

Real-world example

Large-scale dusting campaigns have sent tiny amounts of Bitcoin or Litecoin to tens of thousands of addresses simultaneously, with researchers later observing which recipients combined the dust with other funds, revealing wallet clusters the attacker could not have identified otherwise.

In FreezeRadar

A FreezeRadar scan flags unexplained dust deposits in a wallet's history as a low-severity but worth-noting finding, distinct from genuine incoming payments.

Check a wallet now

By FreezeRadar Team

Research and product team behind FreezeRadar.

Related reading

Continue exploring FreezeRadar knowledge content.