A dust attack is a privacy break that sends tiny amounts of crypto, dust, to many addresses, then watches how those outputs get spent to link wallets to one owner. Wallet software often combines small inputs when you spend. If it mixes the attacker's dust with coins from other addresses, the attacker learns those addresses belong together.
Users who thought their wallets were separate get deanonymized.
The dust itself is nearly worthless, a few satoshis on Bitcoin or fractions of a cent in tokens. The tracking value is high for surveillance, targeting, or mapping users. Analytics firms and agencies use related techniques. Defenses are limited. Never spending the dust is cleanest, but wallets often auto-combine inputs. Some wallets flag tiny deposits.
Privacy-focused users can consolidate through mixing or CoinJoin. UTXO chains such as Bitcoin are more exposed than account chains such as Ethereum. Dust attacks still work on any transparent ledger. The name comes from the tiny amounts involved.
A dust attack is a privacy-breaking technique where attackers send tiny amounts of cryptocurrency ('dust') to thousands of addresses, then monitor the blockchain to trace how these dust amounts are spent, potentially linking multiple wallets to the same owner. When a user spends funds, their wallet typically combines multiple inputs to construct the transaction.
Tiny "dust" outputs can mark your addresses so an observer links them later. Many wallets refuse dust or isolate it.
Dust Attack Privacy Breach
Watch how attackers send tiny amounts of cryptocurrency to trace wallet connections and break user privacy