A dusting attack is the practice of sending tiny amounts of cryptocurrency — or unsolicited tokens — to your public address to force a link or a reaction. Analysts use the trail to cluster addresses they believe are yours; scammers use the 'balance' to bait a claim page. Doing nothing defeats both goals completely.
L4 News publishes information, not investment advice, and nothing here is a reason to move any asset. Dusting is a privacy and manipulation topic, and the defensive advice is mostly about restraint rather than action.
What is 'dust,' exactly?
Dust is an amount too small to be worth spending — often far below the transaction fee of moving it. The term came from Bitcoin, where outputs below a threshold are called dust and treated as uneconomical. In an attack, the value is irrelevant; what matters is that the transfer exists and is visible on the public chain.
The Bitcoin definition is technical: a transaction output so small it couldn't pay the fee of spending itself. The everyday meaning drifted to cover any trivial amount, and then to the tokens that aren't even worth their own display slot. The attack borrowed the name because it works the same way — the payload is not the value, it's the record.
And records are the native product of a blockchain. Every transfer, however small, lands in an address's public history, where anyone can read it. That is the entire attack surface: you cannot refuse an incoming transfer, and you cannot delete its trace.
How does dusting attack your privacy?
By association. Public chains show no names, so analysts group addresses by behavior instead — and the strongest signal is co-spending. If dust sent to address A later moves together with funds from address B, the tools conclude one owner controls both. You write the conclusion yourself, the first time you sweep the dust in with the rest.
Think of it as junk mail confirming that someone lives at an address — the analogy breaks down at the mailbox: junk mail can be thrown away unread, while a blockchain 'mailbox' accepts everything and displays it. The sender isn't guessing whether you exist; they're building evidence about which addresses belong to the same you.
Who actually does this? Blockchain-analytics firms map flows as a product; exchanges run similar clustering for compliance; researchers do it for papers; hostile parties do it for targeting. The sender's intent doesn't change the mechanism, and you usually can't tell which one you're dealing with. The defense is identical regardless: don't create the co-spending link.
How does the scam version of dusting work?
With tokens as the envelope. Unknown tokens appear in your wallet — often with a dollar value the interface invents — and somewhere in their details sits a link: a website where you can 'claim,' 'unlock,' or 'swap' the windfall. The token is the flyer on your windshield; the website is the payload.
The mechanics at that website are standard wallet-drainer machinery: connect, then approve. The signature you're coaxed into gives a hostile contract standing permission over a token you actually hold — the advertised token was never worth anything, but the approval touches real balances. Some variants skip contracts entirely and simply ask for a 'network fee' or your recovery phrase, which finishes the job faster.
So the two versions of dusting share a shape: something unsolicited arrives, curiosity is the trigger, and any interaction is the loss. The tiny deposit is the only free part of the entire exchange.
What should I actually do when unknown tokens appear?
Nothing. Don't claim, swap, 'activate,' or visit any site the token's details link to; most wallet interfaces let you hide tokens you don't recognize. Unsolicited tokens can't move your other assets by existing — they need your signature for that. If the sight of them bothers you, that's the attack working on you.
A few clarifications make the calm easier to hold.
- You don't owe anyone a reaction. The token sitting there is inert. It grants no rights, executes nothing, and reports nothing beyond its own existence.
- You can't send it back usefully. 'Returning' is interacting — it costs fees, may fail on a contract designed to misbehave, and confirms for the sender that a human is home.
- Hide it and move on. Most wallets offer a hide or dismiss option per token. Out of sight genuinely helps: the bait works through repeated exposure.
- Keep big and experimental activity apart. A wallet you use for trying things will collect dust; a wallet you use only for storage mostly won't attract attention worth the attacker's fees.
What about Bitcoin dust, with no tokens involved?
Same attack, different plumbing. Bitcoin has no tokens, so dust is plain satoshis sent to your addresses — and the co-spending rule applies literally: when you later build a transaction, wallet software often sweeps small inputs together, mixing the dusty UTXO with your real ones and writing the linkage into a public transaction.
Some Bitcoin wallets expose coin control, letting you choose which inputs to spend — spend around the dust, never with it. For most people this is more machinery than the threat justifies; the honest assessment is that Bitcoin dusting mostly matters for users with real privacy requirements, and everyone else can file it under 'known, ignored.'
Can I refuse, block, or delete the dust?
No — there is no refusal mechanism to invoke. Public chains accept any properly signed transfer to any address, and your consent is not part of that design. The only votes you control are downstream: whether to interact, and which addresses share a future with which. The attack's whole budget buys it exactly one line in your history; every further line, you write.
If a dusting campaign comes wrapped in something that escalates — threats, targeted messages, or a website that knows your balances — that is worth reporting in the United States to the FTC's fraud portal, and to the FBI's Internet Crime Complaint Center at ic3.gov. The dust itself still needs nothing from you. Attention is the only currency a dusting attack can pay out in, and withholding it is free.
For more context, read How airdrop scams work.
For more context, read compromised crypto wallet.
For more context, read How to spot a crypto drainer before it takes your wallet.




