Library · Crypto, word by word · Scams and security
What is a dusting attack?
A dusting attack is when someone sends tiny amounts of crypto, called dust, to many addresses, then watches the blockchain to see which of those amounts are later spent together. Spending them together reveals that the addresses share an owner, which can help identify who that owner is.
What it means for you
Unrequested dust costs you nothing while it sits there; the privacy loss comes when you spend it alongside your other coins. Some wallets let you choose which coins a payment spends, so an unexpected small amount can be left untouched. On account-based chains, unknown tiny token deposits can also be lures, with a name or link that points to a scam site.
How it works
On Bitcoin and similar chains, a wallet spends coins as separate inputs, and analysts apply the common-input-ownership heuristic: inputs signed together in one transaction are assumed to share an owner. A dusting attacker sends amounts so small they barely cover a fee to many addresses. When a user later sweeps that dust together with other coins, the transaction links the addresses, and taint analysis can trace them to one person. The same technique has non-hostile uses, such as tracking by investigators and research testing. Address poisoning is different: it plants a lookalike address for you to copy.
Sources: Summarizing and Analyzing the Privacy-Preserving Techniques in Bitcoin and other Cryptocurrencies (arXiv), ethereum.org: Security and scam prevention (airdrop scams) · checked 4 October 2026
Often confused with
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.