Crypto Dusting Attacks 101: What They Are and How to Detect Them Before It's Too Late

Many Bitcoin holders have had a “mysterious” tiny amount of Bitcoin in their wallets (for example, 0.00000001 BTC) that they never bought. Rather than dismissing this as a gift from the tech gods or a simple mistake, there’s something you should be aware of. Dusting is an attack by hackers to find your identity.

What are Dusting Attacks?

Dusting attacks are relatively new, but they have been growing in popularity for a couple of years now. Dust is essentially insignificant amounts of cryptocurrency. For Bitcoin, it can be something as small as 1 satoshi or 0.00000001 BTC. Other types of cryptocurrencies can be “dust” as well. The amounts of “dust” that are sent are generally too small to even cover the transaction fees whether it is on the sending or receiving end.

A dusting attack works by sending very small amounts of cryptocurrency to thousands of Bitcoin wallets at once. While the dust has no value, it can be used to track the activity of the person(s) that have received the dust and eventually trace them back to the real person that owns the wallet (and the cryptocurrency).

If you think about a dusting attack like someone throwing a grain of sand with a tracking device in your pocket, it would work in the same way. The grain of sand doesn’t have any value to you, but as you move around during the day, someone is able to track your location, where you go, what you spend money on, etc. The dust becomes a source of privacy invasion for you.

The way that dusting attacks are executed technically is not difficult. Hackers will send between 1 and 10 satoshi to tens of thousands of Bitcoin wallets. After that, they will watch for the moment when you combine that dust with your legitimate funds during a transaction. At this point, a company using blockchain analytical tools will begin connecting your dust address to all of your other Bitcoin wallets, allowing them to create a complete map of your entire cryptocurrency holdings and spending patterns.

Why would hackers go through the trouble of a dusting attack? 

There are several reasons:

Privacy invasion: People are drawn to cryptocurrency for its anonymity. Dusting attacks proof of multiple wallet addresses that can be connected to one person, thus removing the anonymity of everyone.

Wallet Linkage: Unfortunately, many people believe they are not connected with their cryptocurrencies by using different wallets or addresses, but the dust from a dusting attack proves otherwise.

Phishing Campaigns: After identifying the identity of someone and determining approximately how much cryptocurrency they currently hold makes them far more susceptible to targeted phishing attacks.

Behavioral Surveillance: Large-scale attackers create a database of spending and trading patterns and track the movement of your assets.

In 2018, one of the first high-profile dusting attacks was reported in the Bitcoin community where many Bitcoin holders received quantities of satoshi from an unknown source. The subsequent blockchain analysis showed that a number of wallets were targeted and linked to high-value wallets. Similarly, in 2019, the Litecoin community experienced a large-scale dusting attack with warnings issued to customers from some wallet providers (Exodus, etc.) regarding the attack.

So keep this in mind when you receive any stray satoshi in your wallets. Dusting attacks do not normally result in the theft of your Bitcoin; therefore, it does not comprise a threat to your overall financial security. However, if you receive a dusting attack, it serves to rob you of your identity and your financial privacy, both of which are far more valuable than your Bitcoin.

In summary, dusting attacks enable hackers to create a valid link between multiple wallets by following the money through the blockchain.

How Dusting Attacks Work

In order to better defend against and recognize dusting attacks, familiarity with how these types of attacks function can provide you with valuable insight. Dusting attacks occur through 6 distinct stages: 

Step 1: Token Generation: The individuals behind dusting attacks create and/or purchase very small amounts of cryptocurrency, which are generally the blockchain's smallest denomination (for example, for Bitcoin, this would be 1 satoshi, while in other types of blockchains, it may be even smaller).

Step 2: Mass Distribution: Automated scripts (otherwise known as bots) send dust-like cryptocurrency to thousands to hundreds of thousands of wallet addresses. 

Step 3: Dust: The dust simply lies on wallets with no immediate purpose (attackers know that most users will either ignore the dust or eventually send it through a transaction that includes the user's normal funds mixed in; hence, patience is the primary strategic weapon attackers hope to leverage). 

Step 4: Transaction Monitoring: When you execute a transaction that involves the amount of dust that you received, blockchain analytic tools will capture that transaction, and because every transaction is recorded permanently on the blockchain, the dust will show up in an analytical tool, giving the attacker insight into where it was spent and which other wallet addresses received that dust.

Step 5: Pattern Analysis: This is where UTXO-type architecture becomes critical for bitcoin and other similar crypto currencies, as bitcoin does not have traditional account balancing. Instead the transaction architecture tracks every transaction output as an Unspent Transaction Output (UTXO), meaning that whenever you make any payment or send any funds, you create a combination of multiple UTXOs that you have previously used as inputs, and if you use dust from a dusting attack as part of your combination of inputs, that means all of those other wallet addresses are now associated with you.

Step 6: Identity Linking: Attackers use powerful blockchain analysis tools to analyze transactional patterns, amounts transmitted, timing, and address relationships to finally determine who you are. They will then cross-reference that data with data on exchanges that were released in past KYC-type breaches or from social media posts, and this information will destroy your anonymity. 

An illustration of this is to think of a piece of candy that was given to you, but that candy has a unique barcode on it. As long as that candy remains in your pocket, no one knows who you are. However, once you have used it to purchase something at a store and the cashier scans your candy's barcode, the cashier will not only know where you made your purchase but will likely also have information on where you like to live, work, and your general spending habits. 

The brilliance (and danger) of dusting attacks comes from utilizing the transparency of blockchains against their users. When you conduct a transaction using cryptocurrency in a blockchain, a permanent public record is created, and typically this helps assure the validity of a blockchain; however, when used in conjunction with dusting through a blockchain, this transparency will allow for surveillance on the user. 

There are various companies such as Chainanalysis and Elliptic that have documented many dusting attack patterns on a variety of blockchains. While they both use similar analytical techniques to trace out suspicious activity on a blockchain, the same technology will be abused by the malicious individual in a dusting attack, thereby presenting a direct threat to the user's privacy.

The important thing to remember about dusting attacks is that they are extremely damaging in terms of long-term privacy, as opposed to immediate direct financial threat. Your funds are not at risk of being stolen from you directly; rather, your anonymity as a user has been compromised.

Why Dusting Attacks Are Dangerous

It initially may seem like receiving small, insignificant satoshi is harmless and maybe even fun. However, as time draws on this method of attack eventually reveals itself as a significant threat by chaining together numerous privacy breaches.

 

The exposure of your identity from a dusting attack is arguably one of the greatest risks posed by this attack method. Since cryptocurrencies are pseudonymous, your wallet address does not necessarily disclose your real name and location, nor does it provide any personal information about you. However, by using dusting, hackers can correlate data to join multiple wallet addresses together, track transaction patterns, and ultimately, associate them with your real-world identity (e.g. where you live).

 

By analysing this transaction data and the transaction patterns associated with it, hackers can create a profile that gives them insight into you and your dealings in the crypto market. This includes information regarding what types of crypto assets you buy and when you typically buy them, whether you trade crypto assets, and how many assets you possess in total across multiple wallets. This information can be used to facilitate targeted attacks against you.

 

Once a hacker has established that you have a large number of crypto assets held within one or more wallets, it becomes much easier for them to pursue you with phishing-type attacks using personalized messages that reference your real transaction history rather than using generic scam-type messages.

 

Dusting attacks also undermine one of the more fundamental privacy features of the crypto world - namely the use of multiple wallets for different purposes (for instance, different wallets for long-term holdings versus trading versus daily transactions). Dusting enables a hacker to identify the owner of multiple wallets that have been kept separate for legitimate reasons.

 

For institutional investors and "crypto whales", the ramifications are more severe, as dusting attacks could reveal the existence of and assets held within the hot and cold storage of cryptocurrency exchanges, potentially exposing how exchanges maintain their operations securely.

 

To illustrate the potential damage dusting can cause, consider the case of someone who buys coffee with cryptocurrency every Monday at the same café and pays rent from a specific address. The hacker looking to steal this information has the ability to see this pattern and know where you live, work, the amount of money you could potentially have, and your spending habits. Once this information has been obtained by a hacker, they have acquired enough information to design a subsequent scam or phishing attack to defraud you.

 

Professional criminals have leveraged the use of dusting attacks as a means of identifying viable targets for receiving higher-level attack strategies. Dust can also serve as reconnaissance to discover which members of the crypto community are the most profitable victims.

 

In closing, the most significant implication of a dusting attack is not necessarily financial loss but the permanent loss of anonymity associated with your cryptocurrency transactions. Because your wallet address is always the same and will never be removed from the blockchain, it is impossible to reverse the loss of privacy from a dusting attack.

Real-World Dusting Attack Examples

Dusting attacks are not just a theoretical threat described in whitepapers written by cybersecurity professionals. They occur frequently across numerous blockchain networks and engage with millions of users worldwide. 

The Bitcoin Dusting Campaign of 2018 is one of the most fully documented cases to date, in which thousands of Bitcoin wallet holders suddenly received small deposits of anywhere from 1 to 5 Satoshi. Many users were confused and asked for help on internet forums regarding these mysterious deposits. 

Blockchain analysis companies conducted an investigation into this activity and concluded that this was a coordinated attack to find people who own wallets that have large balances. It is very likely that the attackers collected a list of addresses from block explorers and public forums and then systematically performed successive dusting attacks against any address they could find in order to create additional data points in the Bitcoin ecosystem. 

In 2019, the Litecoin community received a very real warning from the Litecoin Wake-up Call as many users suffered waves of dusting attacks directed at many active Litecoin wallets. The Exodus wallet, one of many multi-coin wallets, publicly warned its Litecoin user base to not spend this dusting. This incident increased public knowledge about dusting attacks; however, many did not understand the privacy implications of the attacks. 

With the greater adoption of Decentralized Finance (DeFi) and Token Trading on Avalanche's BNB Smart Chain over the last two years, the number of attacks on Avalanche and Exchanges have continued to increase. These attackers are taking advantage of the lower cost of BNB Smart Chain transactions to dust the wallets of users involved in yield farming, NFT Trading, and Token Swapping. 

It is also important to denote that Exchanges and other Crypto Service Type Companies are being attacked and becoming victims of operations to attempt to map out their complete wallet infrastructures. In most cases, even though exchanges maintain extensive security protocols, they are still the victims of these attempts to gather private data about users. 

The pattern established over time is that dusting is not solely an experimental occurrence in 2018; however, it continues to be used as a method of attack against many different blockchains and new networks as their user bases grow. Hence, attackers will continue to develop new means of conducting these types of attacks across new blockchains and continue to collect the data needed to identify high-value users. 

The frequency with which dusting attacks occur may vary by network. For example, Bitcoin dusting is generally conducted sporadically; however, due to the high volume and demand for BTC, assaults on wallets containing BTC occur in large amounts. Ethereum dusting attacks are less frequent than those on Bitcoin because of the higher costs associated with Ethereum transactions, which makes mass dusting on Ethereum cost prohibitive. Newer, lower-cost blockchains like the BNB Smart Chain, Polygon, and various Layer 2 solutions have been subjected to routine dusting assaults because of their lower cost barrier in obtaining user dusting data. 

For cryptocurrency users, the only takeaway is that dusting happens regularly, not very rarely. If you frequently use cryptocurrencies, it is likely that, at some time or another, your wallets have been subjected to dusting attacks. The key remaining question is not whether these types of attacks occur, but rather whether you are capable of identifying and preventing these types of attacks from being conducted against you.

How to Identify a Dusting Attack

Identifying the warning signs of dust in your wallet is your first line of defence. With some basic knowledge, the telltale signs of dust transactions are often very straightforward to spot.

The most obvious sign of a dust transaction is the unexpected small amount of funds deposited into your wallet. If you received a small amount of cryptocurrency that you did not purchase, earn or request, be suspicious of it. There is no legitimate reason why someone would send you 0.00000001 BTC out of the goodness of their heart.

The other common characteristic of dust amounts is pattern. Dusting attacks typically use the least valuable amounts of crypto: 1 satoshi for Bitcoin and other currencies in a similar way. Occasionally, the attacker will use slightly larger dust amounts such as 5 or 10 satoshi, but the most prevalent identifying feature of dust is that the amount is too low to be considered a legitimate transaction, but is high enough to be displayed in your wallet.

Unfamiliar wallet addresses that have not had any transaction history between you and the wallet owner are another sign of a dust transaction. If you receive funds from a wallet that you have never done business with, and you have no way to verify the source of those funds, there is a good chance that it is a dust transaction.

The ability to identify dust transactions across multiple wallets can indicate organized or coordinated dust attacks. If you manage multiple wallet addresses, and you receive identical small amounts of cryptocurrency in your wallets at approximately the same time, you can almost be certain that you are being targeted by dust attacks.

The following are several practical examples of transactions that have been identified as being sent with the intent to track or monitor a user’s cryptocurrency movement:

Professional end-user example: You have five distinct Bitcoin addresses for which you have control over; however, these addresses are unlinked at present from each other. An attacker may send 5 satoshi to each of those addresses within a 24-hour period. This creates an environment in which the attacker can observe whether or not the user is utilizing all five addresses for one particular purchase by monitoring how these different addresses may consolidate their transaction inputs when making purchases/redeeming tokens from exchanges.

Beginner example: You open your wallet application and receive a notification stating that you received 0.00000001 BTC; this has not occurred through your normal means of acquiring Bitcoin so you should consider it as “dusting”. If you receive this notification and do not recognize the receiving address, then it is the same as receiving an anonymous check for 3 cents from someone whom you do not know.

Visual identification: Many wallet applications display small amount transactions by using multiple decimal points on the transaction history screen; therefore, if you notice a transaction that shows a small number of very small amounts (for example, 0.00000001 or 0.000001) that were not acquired through everyday means, then that is classified as “dust”.

Blockchain explorer analysis: Some experienced users will utilize what is called a blockchain explorer to check transaction graphs of their address to determine if there are any transactions that occurred shortly after one another with identical amounts sent to many different addresses. If there are hundreds or thousands of addresses that have identical transactions that came from the same source, most likely you are looking at a dusting operation.

The most important point is that any small amount of cryptocurrency received that you did not expect should not be considered “good luck” or “a nice surprise,” but instead should be viewed as an attempt to track your behavior, and thus could present a privacy threat.

How to Protect Yourself from Dusting Attacks

Avoiding dusting attacks is based on one key principle: Do not use dust. You should not move dust. Do not even handle dust; just leave it alone, and it will stay there indefinitely.

The first rule of thumb is: once dust enters your wallet you should treat it as if it was radioactive. Dusting UTXOs cannot be transacted with legitimate funds because when combined, you've created a connection to the addresses. Dust moves = loss of privacy.

The best way of defending against dust is to separate your addresses. Different wallets for different purposes:

A cold wallet will be used for long-term storage that rarely has transactions come from it. Since it will have very few interactions with the blockchain, it will not touch dust.

A hot wallet will be used for your active trading and for daily transactions. Therefore, if your hot wallet gets dusted, the privacy impact is limited to that one wallet.

Use designated receiving addresses for each purpose. Do not reuse addresses among purposes. If you do so and one of the addresses becomes dusted, the rest of your portfolio is still protected.

Use wallets that can filter dust. Some of the latest wallets have features that can automatically mark tiny suspicious transactions as dust and block them from being part of outgoing transactions. For example, Exodus, following the 2019 Litecoin event, added an anti-dusting feature. Check with the provider you use if they provide similar protection.

For those who are experienced, Coin Control (UTXO Control) is a good way to help you get around dusting. Coin Control is available in several of the wallets mentioned (for example, Bitcoin Core and Electrum). When you make a payment, Coin Control allows you to manually select which specific outputs you want to include. Instead of letting the wallet combine your UTXOs, select only the clean ones and leave the dust UTXOs as unused.

Here's how Coin Control works in practice: you open your wallet and see you have three UTXOs: one worth 0.5 BTC from a legitimate transaction, one worth 0.3 BTC from another legitimate source, and one worth 0.00000001 BTC from dusting. You want to send 0.6 BTC to someone. Instead of letting the wallet automatically select inputs, you manually choose just the 0.5 and 0.3 BTC UTXOs, leaving the dust untouched. The dust remains in your wallet forever, unused and harmless.

There are several ways for individuals serious about anonymity to have their privacy maintained.

1. CoinJoin services such as allow many individuals to combine their transactions. With this type of service, it is impossible to trace the inputs to specific outputs or understand where the funds came from, or who sent them. By breaking the Chain Analysis system, these types of services greatly minimize and/or eliminate risks associated with a dusting attack.

2. Mixing services allow multiple users to contribute funds into one pool and redistribute them. This process obscures the transaction history associated with the original sender. Be careful with these services. In many jurisdictions, mixing services are "legal gray areas" and you will want to ensure that you understand the local laws and regulations before using such things.

3. Generate new receiving addresses continuously. Do not reuse your previous receiving addresses. With every transaction, create a new address. Creating multiple new addresses limits the potential for damage if a single address is dusted.

In a sense, think of dust on clothes. The dust does not hurt you. It simply stays there, until you integrate it into your clothing. As long as you leave the dust alone and do not integrate it with your clothing, you will be safe.

 

Simply put, if you receive an unexplainable tiny amount of currency in your wallet, write down the transaction ID and forget about the transaction. If your wallet allows, configure it so that you will never interact with that tiny amount in the future. If it does not, just remember to not spend from that UTXO.

The goal of quarantine is not to remove the dust, as blockchains are permanent. Instead, quarantining dust means that it could never mix with your transactions that are clean and verifiable.

What Traders Should Do

Cryptocurrency traders have unique needs due to their high transaction volume and complexity in wallet management, so dusting attacks should be approached differently than retail exchanges that only deal with less than a dozen customers at any one time.

Layered wallet management for cryptocurrency trading is recommended. Layered wallet structure includes three tiers of wallets:

Deep Cold Storage is a secure location to store most long-term holdings in cryptocurrency. The majority of these assets should rarely be transferred, keeping dusting exposure low.

Medium-Term Storage is designed for holding the asset for weeks or months and has lower volatility so it is likely to experience price fluctuations. Therefore, Medium-term Storage will be used for transferring a small amount of the asset to an active exchange, when necessary.

Active Trading Wallets are used for daily transactions on exchanges. It is a good idea to assume that these wallets will be targeted by dusting attacks in the future. To minimise the possibility of exposure, exchange accounts should not contain personal identifiable information such as name, email address, or address.

Do not publicly disclose your main trading addresses. Avoid posting wallet addresses on social media, refrain from using the same address for public donations and payments, and do not provide links between your main trading wallet and your real identity anywhere on the internet; the greater the number of connections made between your wallet and your identity, the easier it will become to de-anonymize you.

Monitor your wallet activity regularly. You can set alerts for incoming transactions using your wallet software or a blockchain explorer. Keep an eye out for dust, if you see dust, you can tag it as "do not touch" immediately, so you do not accidentally spend it weeks later.

Use address rotation to your advantage. When withdrawing from an exchange, use a new receiving address each time. Likewise, when depositing to an exchange, consider using different sending addresses with each deposit. Using address rotation will compartmentalize your transaction history having multiple deposits to and withdraws from an exchange enabling you to keep your trading activity more difficult to link together for attackers.

The threat landscape for traders who utilize a centralized exchange like tradewill will differ. Please read the following to understand:

Custodial exchange wallet holders are not susceptible to dusting attacks like non-custodial wallets. An individual will not control any UTXOs (Unspent Transaction Outputs) after depositing into an exchange's wallet; deposits are simply recorded in the exchange's database of wallets. There will also be no attack “dusting” your wallet on an exchange due to the lack of a single address representing your funds. The exchange manages a pool of wallets and, from a purview standpoint, you have only created an entry in the exchanges' internal database so, therefore, cannot provide attackers with an address to target.

On a centralized trading platform, such as Tradewill, a trader's identity is not visible to any of the on-chain transactions conducted using that platform. Therefore, all of the trader's transactions occur internally within the exchange and not broadcast through public blockchain nodes. The only visible transactions to the public blockchain are the initial deposits and ultimate withdrawals from the exchange's custody.

Unfortunately, the cost of privacy associated with trading on a centralized exchange such as Tradewill is the trade-off between your own ability to ensure your personal privacy using on-chain technology versus the security provided by the exchange itself. However, the majority of traders make this trust-based decision due to the high levels of infrastructure spent on security by exchanges, which eliminates the risk for dusting attacks that personal wallets face.

The following are the recommended methods for exchange traders to consider:

- When possible, rotate the address used for your deposits to the exchanges you trade with as many allow for the periodic generation of new deposit addresses.

- Avoid withdrawing your funds to the same personal wallet address. Vary where you withdraw to in order to reduce the appearance of having an "obvious" withdrawal pattern.

- The only time you should have a significant amount of your holdings kept on an exchange is if you have faith in their ability to secure your funds. If you plan to hold your assets for a long period of time, you should transfer your assets to a cold wallet that you have full control over, but you need to follow good practices for dusting with respect to those wallets.

- To summarise: dusting attacks are mostly a risk to your on-chain privacy and not to the account you hold with an exchange. Therefore, if you keep the majority of your holdings with a reputable and secure exchange, you have already mitigated a substantial part of the risk associated with dusting; however, once you make transfers to your personal wallets for safekeeping or for use in DeFi activities, you need to continue following the anti-dusting best practices.

- Most professional traders operate under a hybrid model: there is no risk of dusting associated with their day-to-day trading on exchanges and therefore they trade actively on those exchanges, while the long-term holdings of their portfolios are transferred to cold wallets that they manage very carefully with strict UTXO management and address hygiene.

Trade Securely Without the Dusting Threat

Dusting is one of the many subtle yet significant threats to privacy posed by crypto. While the goal of dusting isn't to directly steal your money, it takes away the main thing that gives cryptocurrency its value - anonymity. Dusting allows attackers to send tiny amounts of cryptocurrency (dust) to your wallet and wait until you spend it so they can link other addresses to your wallet, create a complete map of your cryptocurrency holdings, and potentially expose your true identity.

The mechanics of dusting are simple: you receive dust unexpectedly; you combine that dust with other legitimate funds in a transaction; and through blockchain analysis, you can see all the links between those transactions. What makes dusting so dangerous is that it leverages the very thing that makes blockchain technology reliable - transparency.

In order to protect yourself from dusting, you need to be aware of it and act accordingly. When dust arrives in your wallet, do not spend it. Use wallet features (such as Coin Control) to isolate and quarantine any suspicious UTXOs. Implement strategies to use multiple addresses for your transactions. Lastly, understand that once you've been dusted, leaving that dust untouched forever is the only safe course of action.

Traders must pay close attention to where they store their assets. With a self-custodial wallet, a trader has to maintain a focus on managing dust (small amounts of bitcoin) properly and also on UTXOs (unspent transaction outputs). However, if you trade on a centralized trading platform, the problem of dusting goes away; the balance of your account on the exchange is not exposed to dusting attacks because it does not exist within the public, immutable-set structure of the UTXO model of the bitcoin network.

If you'd like to trade without having to wipe every transaction you make from a dust trail, then get started with Tradewill.com.

It allows you to trade securely without being exposed to blockchain snooping of your trading transactions, and it allows you to access the global markets for digital assets, using the same security that large financial institutions have employed to guard their assets.





Disclaimer: The content of the blog does not represent any position of Trade W, does not serve as any trading-related decision advice, and does not endorse any third-party.