Dusting Attack
Pronunciation: DUH-sting uh-TAK
Definition
Dusting Attack is an attack or weakness pattern that sends tiny crypto amounts to many addresses to analyze later spending patterns and infer wallet relationships or identities. For Dusting Attack, an attempted action, a detected indicator, a confirmed compromise, and a realized loss are separate states that require different evidence and response. Dusting Attack must be evaluated through its prerequisites, entry point, affected asset or trust boundary, attacker capability, observable indicators, and possible financial or operational impact.
Overview
A dusting attack distributes very small asset amounts, called dust, across many blockchain addresses. Attackers then observe whether recipients combine those outputs with other funds, creating transaction links that may support address clustering or identity analysis.
The dust usually does not compromise private keys or steal funds by itself. Risk arises from privacy loss, phishing follow-up, malicious token metadata, or user interaction with unexpected assets in wallets and explorers.
Users can avoid spending suspicious dust, use wallet coin-control and privacy features, separate identities, and ignore unsolicited token links. Wallet providers should hide deceptive assets, warn users, and prevent untrusted metadata from triggering unsafe browsing or signing.
Dusting Attack is an attack or weakness pattern that sends tiny crypto amounts to many addresses to analyze later spending patterns and infer wallet relationships or identities. Dusting attacks target transaction privacy and user behavior, not cryptographic key control, so careful output handling reduces linkability.
Assessment of Dusting Attack should trace an attack or weakness pattern that sends tiny crypto amounts to many addresses to analyze later spending patterns and infer wallet relationships or identities from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving attack, and identities should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the Dusting attack path should be tested against the architecture associated with attack, and identities.
Retesting for Dusting Attack should reproduce the Dusting attack path involving attack, and identities, examine adjacent paths, and verify the conditions for safely returning the affected service to normal operation.
Key Takeaway
Dusting attacks target transaction privacy and user behavior, not cryptographic key control, so careful output handling reduces linkability.
Sources
- NIST Documentation: Cryptographic Standards And Guidelines — NIST (2026-07-30)