Home

Dusting Attacks: How to Protect Your Crypto Wallets in 2023

General

Dusting Attacks: How to Protect Your Crypto Wallets in 2023

Dust transactions now make up an estimated 10% to 15% of all Ethereum transactions, up from 3% to 5% a year earlier, according to Coin Metrics, and blockchain security firm Blockaid has flagged more than 65.4 million address-poisoning transactions since January 2025, averaging over 160,000 per day.

What began as a niche privacy attack has become one of the most industrialized scams in crypto. A single attacker recently sent around 3 million dust transfers to over a million addresses for just over $5,000.

A dusting attack is a technique where attackers send a tiny amount of cryptocurrency, called dust, to a large number of addresses. By tracking that dust, they aim to de-anonymize wallet holders or set them up for a follow-on scam.

This guide explains how dusting attacks work, how they now power dangerous address-poisoning scams, and the concrete steps to protect your wallet in 2026.


Key Takeaways

  • A dusting attack sends tiny amounts of crypto to many wallets to track or target holders.

  • Dusting now fuels address poisoning, where lookalike addresses trick users into sending funds.

  • Never interact with, spend, or copy addresses from unsolicited dust transactions.

  • Solana's low fees make dusting and spam-token attacks especially cheap to run.

  • Legitimate airdrops are claimed through verified portals, unlike dust pushed to your wallet.


What Is a Dusting Attack?

A dusting attack is a tactic where hackers send a small amount of cryptocurrency, or dust, to many personal wallets. The attackers then trace those transactions to break users' privacy and enable further malicious activity.

The dust itself is usually worth a fraction of a cent, sometimes less than the fee required to move it. That negligible value is the point, since it lets attackers reach enormous numbers of wallets cheaply.


How Does a Dusting Attack Work?

The core aim is to link dusted addresses together and unmask the person or entity behind them. Once anonymity is broken, attackers can launch targeted phishing or other attacks.

  • Sending dust: A malicious actor sends tiny amounts of crypto to many addresses at once.

  • Deanonymization: By tracking how that dust later moves, attackers cluster and link addresses to reveal ownership.

  • Identifying targets: They focus on addresses with weak privacy or ties to specific people or organizations.

  • Intent: The end goal ranges from phishing and spam to profiling targets for larger future attacks.

Because the amounts are so small, they often go unnoticed, which is exactly what lets the attacker trace patterns quietly.


Dusting vs Address Poisoning

Modern dusting has evolved into address poisoning, the more dangerous and financially devastating form. Instead of only tracking you, the attacker sends dust from a lookalike address that matches the first and last characters of one you use, planting it in your transaction history.

The trap springs when you later copy an address from your history and paste the poisoned one by mistake. In December 2025, a trader lost nearly $50 million in USDT this exact way, and Etherscan data covering 2022 to 2024 tied roughly 17 million poisoning attempts to over $79 million in confirmed losses.

The single most important defense is simple: never copy a wallet address from your transaction history, and always verify the full address before sending.


Dusting on Solana

Solana's speed and near-zero fees, while great for legitimate use, also make dusting and spam extremely cheap to run. Account dusting on Solana often arrives as tiny amounts of SOL or unsolicited spam SPL tokens and NFTs sent to huge numbers of wallets.

Attackers also use Solana-specific tricks, such as generating addresses that share the same last characters as real system programs to appear legitimate, or attaching phishing links in transaction memos. A November 2024 Solana address-poisoning case cost one user $2.91 million, underscoring that no chain is exempt.


A Brief History of Dusting Attacks

Dusting traces back to the early days of Bitcoin, where the blockchain's inherent transparency made transaction tracing possible. The original targets were large holders, or whales, but over time average holders became targets too.

The scale has since exploded. After Ethereum's Fusaka upgrade on December 3, 2025 cut fees by roughly six times, monthly poisoning attempts jumped from around 628,000 in November 2025 to 3.4 million in January 2026, a surge driven entirely by cheaper transactions.


Who Performs Dusting Attacks?

Dusting is typically carried out by cybercriminals with a solid understanding of blockchain analysis. Their objectives range from extortion and targeted phishing campaigns to simply unmasking the identities behind wallets.

Increasingly, these are organized operations rather than lone actors, running automated campaigns across millions of addresses because the cost per target is so low.


How to Avoid Dusting Attacks

You cannot stop dust from arriving, but you can neutralize it by following a few habits.

  • Do not interact: Never spend, move, or click anything tied to unsolicited dust.

  • Never copy from history: Verify full addresses from a trusted source, not your transaction log.

  • Use multiple addresses: Distributing holdings can obscure transaction patterns.

  • Use a wallet with scam detection: Many modern wallets flag poisoning and hide spam tokens.

  • Keep wallets updated: Updates bring the latest security protections and filters.


What to Do If You Receive Dust

If you suspect a dusting attack, the guiding principle is to leave the dust untouched.

  • General steps: Do not move the dust, review and strengthen your wallet security, and stay informed on current threats.

  • Account-based addresses: Report the transaction to your wallet provider, consider using a fresh address going forward, and monitor your history for anomalies.

  • UTXO-based addresses: Ensure the dust UTXO is never spent, and use coin control, where available, to choose which UTXOs you spend.


Legitimate Airdrops vs Malicious Dust

Not every unexpected token is an attack, so it helps to know the difference. A legitimate airdrop is something you claim through a verified portal, whereas malicious dust is pushed into your wallet unsolicited to track or trick you.

Platforms built for real distribution make that line clear. Streamflow's airdrops run through verified claim portals with eligibility checks and on-chain proof, so recipients act on a trusted interface rather than random tokens appearing in their wallet.

Its utility tools also help you stay clean and safe, including a wallet cleaner and dust collector for removing spam tokens and a sybil checker for verifying airdrop eligibility, all available in the Streamflow app.


Conclusion

Dusting attacks have grown from a quiet privacy nuisance into the delivery mechanism for multimillion-dollar address-poisoning scams, supercharged by cheap transactions. The defenses, though, remain refreshingly simple: never interact with dust, never copy addresses from your history, and verify every transfer in full.

Knowing how to tell a real distribution from malicious dust is part of that same discipline.

If your project runs airdrops or token distribution, book a demo to see how Streamflow delivers tokens through verified, on-chain claim portals on Solana.


Read Next:


FAQs:


1. What exactly is a dusting attack in the context of crypto wallets?

A dusting attack involves sending tiny amounts of cryptocurrency to many wallet addresses to trace transactions and break user privacy. Increasingly, it is also the first step in address poisoning, where attackers plant lookalike addresses to trick users into sending funds to them.


2. How can I recognize if I have been targeted by a dusting attack?

Watch for tiny, unexpected crypto deposits or unfamiliar spam tokens appearing in your wallet. Unsolicited micro-deposits, especially from addresses resembling ones you use, are a common sign of dusting or an address-poisoning setup.


3. Are certain types of crypto wallets more vulnerable to dusting attacks?

All wallets can receive dust, since anyone can send to a public address. However, wallets lacking privacy features, spam filtering, or scam detection, or those linked to public personal profiles, carry more risk.


4. What steps should I take immediately if I suspect a dusting attack?

Do not move or interact with the received dust, and strengthen your wallet's security settings. Consider using a fresh address for future transactions, and never copy an address from your transaction history when sending funds.


5. Is it dangerous to simply hold dust in my wallet?

Holding dust is not dangerous on its own, since the risk comes from interacting with it or copying its address. Leave it untouched, hide or clean spam tokens with a trusted tool, and avoid clicking any links attached to the transaction.