Received a Crypto Dust Attack? First Identify What Was Actually Sent
An unexpected tiny crypto deposit does not automatically mean your wallet was hacked. But 'dust attack' is used for several different attacks, and the safest response depends on which one happened. On Bitcoin and other UTXO networks, dust can be used to link coins and addresses when you later spend it. On Ethereum, Solana and other account-based networks, unsolicited tokens and tiny transfers are more often interaction bait or address-poisoning noise. Do not move the deposit until you classify it.
Most faucet rewards are tiny. FaucetPay can help you collect small payouts from supported faucets, PTC sites and reward platforms in one microwallet before withdrawing later.
Set up FaucetPay to collect small rewards →The safest immediate action is usually no action
Do not click a link, visit a domain embedded in token metadata, approve a contract, sign a message, swap an unfamiliar token or deliberately combine a suspicious Bitcoin UTXO with other coins. First inspect only public blockchain data: network, transaction, sender, amount and asset type. Receiving a transaction by itself does not reveal your seed phrase or grant the sender signing authority.
Run the Dust Incident Triage
Classify the deposit before deciding what to protect.
- UTXO privacy dust — a tiny Bitcoin, Litecoin or similar UTXO arrives and becomes a separate spendable input. Main risk: address and coin clustering if it is later combined with other UTXOs.
- Interaction-bait token or transfer — an unsolicited asset, NFT, memo, URL or token name appears on an account-based chain. Main risk: the user visits, signs, approves or swaps through a malicious route.
- Address poisoning — a tiny or zero-value transfer places a lookalike sender or recipient address into transaction history. Main risk: copying the attacker's address during a future send.
Do not call every tiny deposit a privacy dust attack
The classic dusting attack is most meaningful on UTXO-based systems because later spending can combine multiple transaction outputs as inputs. Binance and Ledger currently describe this as a blockchain-analysis technique used to correlate addresses. A random ERC-20 token with a suspicious URL can be dangerous too, but its mechanism is different. Correct classification prevents advice designed for Bitcoin coin selection from being applied blindly to Ethereum or Solana.
Branch A: Bitcoin or another UTXO-based coin
If the unexpected deposit created a separate UTXO, preserve that fact. Do not sweep or consolidate the wallet merely because the amount is annoying. A later transaction that spends the suspicious UTXO together with previously unrelated UTXOs can give an observer additional evidence that those inputs belong to the same wallet or owner.
Why spending Bitcoin dust can weaken privacy
Bitcoin transactions can use several UTXOs as inputs. The Bitcoin white paper notes that multi-input transactions necessarily reveal a common ownership relationship between their inputs, while Bitcoin.org warns that transaction history is public and traceable. A dust attacker tries to exploit this public structure by watching where the unsolicited output travels when you later spend it.
The dust does not need to identify you immediately to be useful
A dust deposit can begin as a pseudonymous observation. The attack becomes more valuable if later transactions connect the address cluster to another wallet, a reused public address or an identifiable service. Binance's current explanation describes phishing, extortion and targeted scams as possible follow-on uses once blockchain activity helps an attacker infer who controls related addresses.
Use coin control if your Bitcoin wallet actually supports it
The practical goal is to stop the suspicious UTXO from being selected automatically. Sparrow currently provides explicit coin control through its UTXOs screen and its software includes dust-attack detection and the ability to freeze flagged UTXOs. Other wallets expose similar controls under labels such as coin control, freeze coin, freeze UTXO or do not spend. Verify your own wallet's current documentation before relying on a label.
Do not export private keys just to isolate a few satoshis
Some wallets do not expose individual UTXO control. That does not mean the next step should be copying a private key into unfamiliar software. Exodus currently warns that isolating UTXO dust through another wallet is an advanced process involving private-key handling. If the privacy value at stake justifies migration, use a well-understood, verified wallet workflow and protect the recovery phrase throughout.
Moving the whole Bitcoin wallet can accidentally complete the attack
A 'send everything to a new address' reaction can consolidate the suspicious UTXO with the wallet's other coins. That is exactly the kind of common-input link a privacy dust attack may be waiting for. Review coin selection first. A new destination address does not undo information revealed by the inputs used to fund the transaction.
A fresh receiving address helps future privacy, not past history
Bitcoin.org recommends using a new address for each payment because public address reuse makes activity easier to connect. Generating a fresh address is good hygiene for future receipts, but it does not erase the dust transaction or remove it from blockchain history. Treat address rotation as prevention, not deletion.
Branch B: an unexpected token or tiny transfer on an account-based network
Ethereum, Base, BNB Chain, Solana, TRON and similar account-based environments do not use Bitcoin-style UTXO coin selection for ordinary account balances. If an unfamiliar token or tiny transfer appears there, the more immediate question is whether it is bait for an action: a URL, claim, approval, swap, support message or other prompt.
Receiving an unsolicited token is not the same as approving it
A sender can transfer an asset to a public address without your permission. That arrival alone does not authorize the sender to spend other assets from your wallet. Coinbase currently tells users who receive unexpected dust to leave it alone, while Exodus recommends avoiding links and interaction with suspicious account-based deposits. The risk changes when the wallet owner signs or approves something.
If the asset contains a URL, treat the URL as hostile
A token name, NFT description or transaction memo can be advertising rather than trusted wallet data. Coinbase specifically notes that dust or spam tokens can place URLs in asset names to lure recipients to malicious sites. Do not type that URL manually, search for a redemption page or connect the wallet to 'remove' or 'claim' the asset.
Do not approve, swap or burn a suspicious token just to make it disappear
An unsolicited asset does not need an on-chain cleanup transaction to be safe. Hiding or reporting it in the interface is different from signing a contract interaction. If your wallet supports a local hide or spam function, that can reduce clutter without granting new authority. The dedicated random-token guide owns deeper contract quarantine if the unsolicited object is a token rather than simple dust.
Branch C: check for address poisoning before your next send
Address poisoning uses transaction history as the attack surface. MetaMask currently describes attackers generating a lookalike address, then sending a negligible or zero-value transaction so that the fake address appears beside legitimate history. The attacker does not need wallet access; the hoped-for loss happens later when the victim copies the wrong destination.
Compare the entire address, especially the middle
A poisoned address is designed to survive casual checking of the first and last characters. MetaMask now warns users to pay attention to the middle characters as well and recommends avoiding copy-and-paste from transaction history. For important recurring destinations, obtain the address again from the recipient or use a previously verified address-book entry.
A tiny transfer that resembles your own recent transfer is a stronger poisoning signal
Look at context rather than value alone. If the suspicious transaction appears soon after a genuine transfer and the sender or recipient address visually resembles the real counterparty, address poisoning becomes more plausible. Save both addresses and compare them character by character. Do not use the suspicious history entry as a shortcut for the next payment.
One incoming dust transaction is not proof that your private key leaked
Public blockchain addresses are designed to receive transactions from people who know them or discover them on-chain. An unsolicited deposit proves that someone knew or selected the address; it does not prove they know the private key. A key-compromise incident requires different evidence such as an unauthorized outgoing transaction, an exposed recovery phrase or a signature you did not intend to grant.
But a dust incident can justify a privacy review
If the targeted address is publicly tied to your name, reused widely or connected to KYC services, the attacker may already have more contextual information than a random spammer. Review where you published the address, whether you reuse it and whether several identities or wallets are being mixed together. The goal is to limit future linkability, not to pretend the existing public transaction can be erased.
Do not answer unsolicited 'support' that appears after the dust
A dust or spam transaction can be followed by phishing messages claiming the wallet must be validated, cleaned or synchronized. No legitimate remediation requires giving someone the seed phrase or private key. If you need wallet support, navigate independently to the wallet vendor's official support channel rather than replying to a message or link attached to the incident.
When should you actually move the rest of your funds?
Dust alone is not a reason for an emergency sweep. Move funds urgently when there is separate evidence that spending authority is compromised—for example, an unauthorized outgoing transaction, a disclosed seed phrase/private key or a malicious authorization that genuinely affects assets you hold. If the issue is only Bitcoin privacy dust, preserve coin-control information before moving. If it is only an account-based spam token, non-interaction is normally safer than a cleanup transaction.
If you already spent suspicious Bitcoin dust
You cannot reverse the confirmed transaction or restore the privacy relationship it may have revealed. Stop making the cluster larger. Record which UTXOs and addresses were combined, avoid unnecessary future consolidation, use fresh receiving addresses and consider a privacy-focused wallet that exposes coin labels and coin control. Do not send funds through an unknown 'privacy recovery' service promising to erase blockchain history.
If you already clicked the token's website but signed nothing
Close the site and remove the wallet connection if one was created. Merely viewing a page is different from granting an on-chain approval or signing a malicious message. Review the wallet activity and permissions rather than assuming the seed is compromised. If you did sign or approve something, move to the connected-to-suspicious-site incident workflow because the risk is no longer just dust.
If you already signed, classify the signature before moving assets
A connection request, message signature, permit, token approval and transaction can grant very different authority. Preserve the transaction hash or signature request and inspect what was authorized. Do not revoke random contracts from links sent by strangers. Use the wallet's official permission tools or reputable explorer interfaces, and treat any exposed seed phrase or private key as a separate high-severity compromise.
Use the minimum-action response
The safest fix is the smallest action that neutralizes the identified mechanism.
- UTXO privacy dust: label or freeze the suspicious UTXO when supported and keep it out of ordinary coin selection.
- Spam token or account-based dust: do not interact; hide or report locally if the wallet supports it.
- Address poisoning: never copy the lookalike address; verify the complete destination from an independent trusted source.
- No unauthorized outgoing activity: do not rotate keys solely because someone sent you funds.
- Actual key or approval compromise: leave the dust workflow and use the relevant compromise-recovery procedure.
A 90-second incident record prevents later mistakes
Before hiding anything, save public evidence that does not expose wallet secrets.
- Blockchain/network and exact receiving address
- Transaction hash and timestamp
- Amount or token identifier
- Whether the network is UTXO-based or account-based
- Whether a URL, memo, NFT or suspicious token name is attached
- Whether the sender address resembles a legitimate recent counterparty
- Whether you clicked, connected, signed, approved, swapped or sent anything afterward
- Any unauthorized outgoing transaction
Use a four-verdict conclusion
End the investigation with one clear verdict instead of the vague label dust attack.
- PRIVACY DUST — isolate the UTXO and protect future coin selection.
- INTERACTION BAIT — leave the unsolicited account-based asset alone and avoid its links or approvals.
- ADDRESS POISONING — protect future destination selection and stop copying from history.
- REAL COMPROMISE EVIDENCE — an unauthorized outgoing action or exposed authority exists; escalate beyond dust handling.
Why this page is separate from the random-token guide
A random token is one subtype of unsolicited wallet content and its main danger is malicious interaction with a token contract or associated website. A classic Bitcoin dust attack is instead a privacy and clustering problem involving UTXOs. Address poisoning is a third mechanism that targets future copy-and-paste behavior. Combining all three under one response would make the advice less safe.
What can change after August 7, 2026
Wallet interfaces can add dust filters, spam reporting, address-poisoning warnings and different coin-control controls. The durable distinction is the attack mechanism: UTXO linkage, interaction bait or destination deception. Identify that mechanism before using any wallet-specific feature.
Sources checked on August 7, 2026
Current wallet-provider guidance and Bitcoin privacy documentation were prioritized, with a recent Bitcoin proposal used only as context for the continuing dust-management problem.
- Binance Academy — What Is a Dusting Attack? — https://academy.binance.com/en/articles/what-is-a-dusting-attack
- Ledger Academy — Dusting Attack — https://www.ledger.com/academy/glossary/dusting-attack
- Coinbase Help — Dusting attacks — https://help.coinbase.com/en/coinbase/privacy-and-security/avoid-scams/dusting-attacks
- Exodus — What is crypto dust, and how is it used in attacks? — https://www.exodus.com/support/en/articles/8611285-what-is-crypto-dust-and-how-is-it-used-in-attacks
- MetaMask — Address poisoning scams — https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/address-poisoning-scams/
- Bitcoin.org — Protect your privacy — https://bitcoin.org/en/protect-your-privacy
- Sparrow Wallet — Spending Privately and coin control — https://sparrowwallet.com/docs/spending-privately.html
- BIP 451 — Dust UTXO Disposal Protocol proposal — https://bips.dev/451/
Be careful with websites that promise unrealistic rewards, ask for deposits before withdrawal, or require suspicious wallet connections. Small reward sites should never need your seed phrase.
FAQ
Can a dust attack steal crypto just by sending something to my wallet?
No. Receiving an unsolicited transaction does not by itself give the sender your private key or signing authority. The main risk depends on the mechanism: Bitcoin UTXO linkage, interaction with a malicious token or site, or accidentally copying a poisoned address later.
Should I send crypto dust back to the sender?
Usually no. On a UTXO network, spending it can create the privacy link the attacker wanted. On an account-based network, interacting with an unfamiliar asset can create unnecessary risk. Classify the deposit first.
Should I move all my Bitcoin to a new wallet after a dust attack?
Not automatically. A sweep can combine the suspicious UTXO with other coins and reveal more common ownership. Use coin control or a wallet-specific privacy workflow before moving funds.
Is a random token in MetaMask the same as a Bitcoin dust attack?
Not technically. Bitcoin dust attacks typically exploit UTXO spending and address clustering. A random EVM token is more often spam or interaction bait, although both may be described casually as dusting.
What is the difference between dusting and address poisoning?
Classic dusting tries to learn from what you later spend. Address poisoning tries to place a lookalike address in your history so you copy the wrong destination during a future payment.
Can I hide dust without deleting it from the blockchain?
Yes, if the wallet provides a local hide, spam or freeze function. Hiding does not remove the public transaction; on a Bitcoin wallet, freezing a UTXO can keep it out of coin selection when the wallet supports that feature.
When should I treat the wallet as actually compromised?
Escalate when you have separate evidence of spending authority loss, such as an unauthorized outgoing transaction, an exposed seed phrase or private key, or a malicious approval or signature with real authority. An incoming dust deposit alone is not that evidence.