Technical Definition

Dust Attack

A dust attack is the deliberate sending of tiny token amounts ("dust") to many wallet addresses, typically used to deanonymize users, link addresses, or trick them into interacting with malicious contracts when they try to "clean up" or move the dust.

By Crypto University Editorial
On-Chain DataPhishing

Key Insight

For traders who manage multiple addresses for privacy, capital segregation, or operational security, a dust attack can silently link wallets that were supposed to be unconnected. Some dust also delivers phishing payloads via token names or links embedded in metadata.

Common Misconceptions

Moving, swapping, or even approving unknown dust tokens.

Clicking links inside token names or NFT metadata.

Assuming a fresh address remains anonymous after touching dust.

Detailed Explanation

How It Works: The attacker sends fractional amounts of a token to thousands of addresses. They then watch the blockchain: when those addresses combine the dust with other inputs in a transaction, they reveal common ownership. Other variants use scam token names or transferFrom approvals to lure users into signing harmful transactions.

FAQs:

  • Should I just hide the dust? Yes — most block explorers and wallets let you hide rather than interact.

Can I get rid of dust safely? In most cases, simply leaving it is safest.

In Practice

A trader receives 0.000001 of an unknown token in three of their "separate" addresses. They consolidate it without thinking; an analyst now confidently links all three to one identity.

Dig Deeper