Crypto Media • Analytics • Investigations
A Dust Attack on Kraken: How Microtransfers Became a Tool for Blocking
Investigations

A Dust Attack on Kraken: How Microtransfers Became a Tool for Blocking

KLJO
KLJO August 28, 2026 4-minute read

The dust attack on Kraken revealed a new way to exploit cryptocurrency micropayments against exchange users. In August 2026, some Kraken customers temporarily lost access to their accounts after receiving small amounts from a wallet linked to HTX. The exchange stated that the alleged goal was not to steal funds, but to trigger automated compliance checks by distributing sanctioned assets.

The amount of the transfer itself was almost irrelevant. What mattered was the source of the funds.

What Happened at Kraken

According to Bloomberg, small, unwanted transfers were sent to Kraken customers from a wallet that analytical systems linked to HTX. Following this, some accounts were temporarily restricted. Kraken referred to the incident as a “dust attack” and explained that such microtransfers could be used to trigger sanctions and AML checks.

HTX denies that it initiated these transactions. The company stated that it is investigating the situation and is considering, among other possibilities, erroneous address attribution or actions by a third party. Therefore, it cannot be concluded that HTX itself orchestrated the attack.

Why is HTX mentioned?

On August 23, 2026, EU restrictions against HTX (HUOBI GLOBAL SA) took effect. The platform was added to the list of crypto services and financial institutions that, according to EU documents, significantly impede the achievement of the sanctions regime’s objectives.

Since then, the origin of funds associated with such platforms has become a particularly sensitive issue for regulated cryptocurrency exchanges.

That is precisely why, for an automated compliance system, a few cents from a regular address and a few cents from an address flagged with sanctions are completely different events.

How Does This Type of Attack Work?

Centralized exchanges analyze blockchain transactions using risk-scoring systems.

They check:

  • sender's address;
  • source of funds;
  • connections to sanctions-related services;
  • stolen assets;
  • mixers;
  • ransomware;
  • darknet;
  • fake addresses.

If an incoming transaction is high-risk, the system may automatically generate an alert and flag the account for additional review.

The problem is that the owner of a public blockchain address cannot prevent someone else from sending them cryptocurrency.

The recipient does not sign or confirm anything.

But the entry still appears on the blockchain.

The result is a simple diagram:

suspicious address → micropayment → exchange customer → AML alert → temporary restriction.

The attack does not target the private key or the exchange's source code.

The logic of the compliance system is under attack.

This isn't your typical dust attack

The classic "dust attack" is typically used to analyze wallets.

An attacker sends small amounts to a large number of addresses and then tracks the subsequent movement of the funds. This can help link several addresses to a single owner.

In the case of Kraken, the mechanism was different.

Micro-translation was not used for de-anonymization, but rather as a way to create an undesirable link between a user and a sanctioned source.

Therefore, in this context, “dust” is not a surveillance tool, but rather a trigger for an AML check.

Why might such an attack be effective?

This kind of scheme has an unfortunate economic aspect.

For the sender, the cost of the attack may be minimal: small amounts plus network fees.

But every successful compliance response already incurs costs for the exchange:

alert → restriction → customer inquiry → support → manual review → compliance → restoration of access.

If the number of transactions becomes massive, the load shifts from the blockchain to the exchange's internal processes.

Essentially, this is similar to a DoS attack, except that instead of servers, the target is a financial control system.

Is it possible to block any wallet this way?

No.

Self-custody wallets such as MetaMask, Rabby, or Phantom cannot be disabled by such an incoming transfer. The private key remains with the owner.

However, a micropayment can create an unwanted on-chain link.

Problems may arise later—for example, when the owner transfers assets to a regulated exchange, a custodian, or another service that uses blockchain analytics.

In that case, the history of the funds' origin may be subject to further scrutiny.

In other words, the risk lies not in the blockchain address itself being blocked, but in how that address will be interpreted by external compliance systems.

Why This Is Especially Important for Large Wallets

The public addresses of major whales, funds, traders, and companies are often well known.

Their movements are constantly tracked by analytics services.

This makes such addresses an easy target for deliberate "contamination."

In theory, an attacker could deliberately send funds with a questionable history to known wallets in order to create additional complications when the owner interacts with regulated platforms in the future.

The wallet itself will continue to work.

However, some of its subsequent operations may require further explanation.

Conclusion KLJOMPUS

The Kraken incident highlights a new type of attack on cryptocurrency infrastructure.

In the past, the main risks were clear: stealing a seed phrase, hacking a smart contract, infecting a device, or spoofing an address.

Now, malicious actors may try to use the AML system itself as a means of exerting pressure.

This approach could be particularly dangerous when targeting the known wallets of large holders.

If a wallet address is public, assets with a questionable history can be intentionally sent to it in an attempt to create problems when those funds are later withdrawn to exchanges or custodial platforms.

That's a whole new level of attack.

The goal isn't necessarily to steal money. Sometimes it's enough to make it harder to use it.

And that is precisely what makes the Kraken story significant: the blockchain remains open, which means that any public address could potentially be linked to a source with which its owner never wanted to have anything to do.

Source: Kraken Support — EU Sanctions and Certain Crypto-Asset Services

Your reaction to the article

Leave a comment