Crypto Dusting Attacks: What to Do When You Receive Unknown Tokens

By Alexandr Kerya · · 6 min read

TL;DR - A dusting attack sends tiny amounts of crypto or unsolicited tokens to your wallet to track you or bait a click; do not interact with them, hide them, and check the sender before doing anything else.

You open your wallet and find a token you never bought, or a few cents of an asset you do not recognize. It feels like a glitch, or maybe free money. It is usually neither. Unsolicited deposits like these are the opening move of a dusting attack, and the worst thing you can do is treat them as a normal balance. This guide explains what the dust is for, why interacting with it is the real danger, and how to check whether the sender is something to worry about.

What is a crypto dusting attack?

A dusting attack is a transfer of a very small amount of cryptocurrency, called dust, sent to a large number of wallets at once. The amount is deliberately trivial, often a fraction of a cent, because the goal is not to give you value. The goal is to mark your address and watch what it does next.

On a public blockchain, every transfer is visible. By seeding many addresses with dust and tracking which of them later move funds together, an attacker can group separate addresses that belong to the same person. Analysts call this clustering. Compliance firm AnChain.AI describes the tactic as a combined analysis of different addresses to deanonymize the holder behind each wallet. Once your addresses are linked, the attacker can aim phishing, extortion, or a tailored scam at you.

How a dusting attack works, from seeding dust to linking addresses to one owner.An attacker seeds tiny dust amounts into many wallets, watches which addresses later spend together, and links those addresses to a single identity.How a dusting attack worksAttackerseeds dustMany walletsget tiny amountsWatch whichspend togetherLink them toone identityThe dust is bait for analysis, not a gift.
A dusting attack does not steal funds on contact. It marks addresses so the sender can later link them to one owner.

Why did you receive tokens you never asked for?

Not every unsolicited deposit is passive tracking dust. A second, more aggressive version sends a named token or NFT that exists only to lure you to a website. The token shows up with a ticker like a fake reward or an airdrop, sometimes with a URL written into its name. When you go to claim it, the site asks you to connect your wallet and approve a transaction. That approval is the trap.

Hardware wallet maker Trezor puts the rule plainly: if you receive any asset you were not expecting, you should assume that it is a scam. The deposit itself cannot move your money. What moves your money is the permission you grant when you interact with the token or the site it points to. This is the same mechanism behind a wallet drainer, where a single approval hands a contract the right to empty your balance.

What should you do when unknown tokens appear?

The safe response is mostly about what you do not do. The dust sitting in your wallet is harmless on its own. The damage only starts if you engage with it.

  • Do not swap, send, or approve the token. Approving it is what gives a malicious contract spending rights.
  • Do not visit any link written into the token name or transaction note. Treat those URLs as hostile.
  • Hide the token in your wallet interface instead of trying to delete it. You cannot remove an on-chain record, but you can stop it cluttering your balance.
  • Never enter your seed phrase or private key on a site a mystery token sent you to. No real claim ever needs it.

If you want to know where the dust came from, look up the sending address on a block explorer such as Etherscan. That shows the sender's history, but reading multi-hop paths by hand is slow and easy to misread.

Safe response to unknown tokens: do not touch, hide it, check the sender.Three steps. Do not swap send or approve the token. Hide it from your balance view. Screen the sender address for risk before doing anything else.Safe response to an unknown tokenDO NOT TOUCHNo swap, send, orapprove.Approval is thereal trap.HIDE ITKeep it out of yourbalance view.You cannot erasean on-chain record.CHECK THE SENDERScreen the sourceaddress for risk.Sanctions, mixer,stolen funds.
Treat any unexpected asset as a prompt to do nothing, hide it, and verify the sender, in that order.

Does receiving dust hurt your wallet's AML risk score?

This is the question that worries people most, and the short answer is reassuring. Receiving an unsolicited transfer does not, by itself, make your wallet guilty. You cannot stop anyone from sending to a public address, and screening tools are built to weigh that reality. Receiving dust does not inherently flag a wallet as high-risk.

The nuance is the source. If the dust came from a sanctioned address, a mixer, or a cluster tied to stolen funds, that inbound link can register as exposure even though you never asked for it. Most of the time the weight is small and fades with distance, but it is worth knowing what landed in your history. Rather than tracing the sender by hand, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six EVM chains at once, with no signup and no keys. You can also run a focused crypto scam check on the sending address.

How do you tell harmless dust from a wallet drainer?

The line is whether the deposit needs you to act. Pure tracking dust is passive. It sits in your wallet, costs you nothing, and only helps the attacker if you later merge it with your real funds in one transaction. The defence is simply to leave it alone.

A drainer token is active. It is built to make you click, connect, and approve. The closely related address poisoning scam works the same way, planting a lookalike address in your history so you copy the wrong one later. In each case the protection is identical: an unexpected asset is a prompt to do nothing, verify the sender, and move on. When in doubt, screen the source before you let it shape a single decision.

FAQ

Can a dusting attack steal my crypto directly?

No. Receiving dust cannot move your funds. The risk only appears if you interact with the token, approve a transaction it requests, or visit a site it links to and connect your wallet there. Left untouched, dust is harmless.

Should I send the dust back to whoever sent it?

No. Sending it back still spends from your wallet and can merge the dust with your real funds, which is exactly the link the attacker wants. Ignore it and hide it instead.

Will an exchange freeze my account because of dust I received?

Receiving dust alone is very unlikely to freeze an account. A problem arises only if the dust traces to a sanctioned or stolen-funds source and you then move it to the exchange. Screening the sender first tells you whether that is a concern.

How do I check who sent the unknown tokens?

Look up the sending address on a block explorer for its raw history, or run it through a wallet screening tool that checks the address against sanctions lists, known mixers, and stolen-funds clusters in one pass.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

Address Poisoning: The Lookalike Address in Your HistoryWhat Is a Crypto Wallet Drainer? How to Tell If Your Wallet Was DrainedWhat Is Crypto Wallet Screening? A Plain-English GuideCrypto Donation Checklist: 7 Checks Before Your Nonprofit Says Yes