All
Filter by:
How do I deposit cash into my account?
I need help with account verification
Why can't I access my account?
Are there any crypto withdrawal fees?
I need help signing into my account
"Dust" is a tiny amount of crypto, usually worth less than the network fee needed to spend it. A dusting attack is when someone sends dust to thousands of addresses at once, then watches the blockchain to see what those addresses do next.
Receiving dust does not give anyone access to your funds. The risk comes from what you do afterwards.
Blockchains are public, so anyone can see that an address received dust. On their own, addresses are pseudonymous and not tied to a name.
The link is made when you spend. If a later transaction draws on the dust at the same time as your own funds — known as input consolidation — that transaction is public proof the same person controls both. The attacker can then cluster your addresses and estimate your total holdings. If any address in that cluster has touched a verified exchange account or a merchant, the cluster can be tied to a real identity.
This is clearest on Bitcoin and other chains that use unspent transaction outputs (UTXOs), but the same pattern-analysis applies to account-based chains such as Ethereum.
To de-anonymize you. Once a wallet is linked to a person and shown to hold a large balance, that person becomes a target for spear-phishing, extortion, or in high-risk regions, physical threats.
To advertise a scam. Dust often arrives as an unknown token with a name, image or memo pointing to a website — "claim your reward", "you have won". The site asks you to connect your wallet and approve a transaction that hands the attacker permission to move your real assets.
To poison your transaction history. The attacker generates an address whose first and last characters match one you have already used, then sends a tiny or zero-value transfer from it. The look-alike address now sits in your history. If you later copy an address from your history rather than from the original source, your funds go to the attacker. This variant, known as address poisoning, causes the largest losses.
Not all dust is hostile. Law enforcement and tax agencies use dusting in investigations, blockchain analytics firms use it for research, and developers use it to stress-test or spam networks. Dust is also used to carry advertising messages. You cannot tell which is which from the transaction alone, so treat all of it the same way.
Crypto held on Kraken sits in Kraken's custody. Dust sent to a Kraken deposit address does not put your account, your balance or your credentials at risk.
Self-custody is where dusting matters, because you control the addresses and you sign the transactions.
For most people, dust is a nuisance rather than a threat. De-anonymization is mainly a risk if you hold a large balance in self-custody, or live somewhere personal safety or political instability is a concern.
Address poisoning is different. It does not depend on the size of your balance, and it works on anyone who copies an address from their transaction history. Verify the full address on every send.
Receiving crypto gives the sender no control over your wallet. Nobody can move your funds by sending you a transaction. Losses happen only when you sign something, approve a token allowance, or send funds to an address you did not verify.