Definition
A dusting attack is a privacy attack involving very small transfers, often called dust, to many blockchain addresses. The sender then analyzes subsequent activity to infer relationships between addresses or associate them with an identity. The classic explanation concerns UTXO-based systems such as Bitcoin, where spending several outputs together can reveal useful linkage signals. Small unsolicited transfers can also be spam, advertising, or mistakes, so their presence alone does not establish an attack.
How It Works
If a wallet later combines a suspicious output with other funds in one transaction, an observer may infer common control. Such analysis produces evidence or probabilities rather than a universal proof of ownership. Shared services, collaborative transactions, and other patterns can complicate the conclusion. Receiving dust does not reveal a private key or automatically permit the sender to spend the recipient’s balance.
Key Considerations
Where supported, coin control and marking suspicious outputs as non-spendable can help avoid unintended consolidation. Review privacy implications before combining funds, and avoid publishing unnecessary links between addresses and personal accounts. Token-based unsolicited transfers may instead direct users toward phishing pages; do not follow embedded links or sign permissions to claim supposed rewards. Dusting should be distinguished from address poisoning, which aims to trick a user into choosing a lookalike destination. Neither a tiny transfer nor a matching address fragment proves that the sender is legitimate.