Dusting attack linking your crypto wallet to real identity
A dusting attack is a method of surveillance, not theft. An attacker sends a tiny, nearly worthless amount of cryptocurrency - often called "dust" - to thousands of wallet addresses. The goal is not to steal funds. The goal is to track where that dust moves next.
How it works. The attacker monitors the blockchain for the dust tokens they distributed. When you spend or transfer any of your cryptocurrency, you may inadvertently move the dust along with it. The attacker sees this movement. They can then link multiple wallet addresses that belong to the same person. This process is called cluster analysis.
Once the attacker has identified a cluster of wallets, the real target emerges. Many crypto exchanges require Know Your Customer (KYC) verification - government ID, proof of address, sometimes a selfie. If any wallet in the cluster deposits to or withdraws from a KYC'd exchange account, the attacker can connect that real-world identity to every wallet in the cluster. Your pseudonymous wallet becomes a known identity.
Dusting is distinct from address poisoning, which is covered elsewhere on this site. Address poisoning sends dust to trick users into copying a fraudulent address from their transaction history. The intent is deception - get you to send funds to the wrong wallet. Dusting's intent is purely surveillance. The attacker wants information, not a single mistaken transaction.
You can block dusting by never touching the dust. If you never move the dust tokens, the attacker gains nothing from sending them. In MetaMask and Phantom wallet, you can hide these tokens. In MetaMask, click the token, tap "Hide," and confirm. In Phantom, find the token in your token list, click the three dots, and select "Hide." Both wallets will no longer display the dust. It is still on-chain. You can ignore it.
A more aggressive option is to burn the dust by sending it to a burn address - a wallet that no one controls and from which funds cannot be recovered. Common burn addresses include 0x000000000000000000000000000000000000dEaD on Ethereum-compatible chains and 111111111111111111111111111111111111111111 on Solana. Sending dust to such addresses removes it from circulation and prevents any future cluster analysis using those tokens. Be careful. Sending any token to a burn address is irreversible. Do not send valuable tokens.
Most dust attacks target high-value wallets - large holders, frequent traders, or people who have interacted with sensitive protocols. If your wallet holds modest amounts or you rarely transact, you are a less interesting target. Still, the precaution is simple. Hide the dust. Do not interact with it. Do not click any links in the transaction memo or contact the sender.
Phantom and MetaMask do not automatically flag dust tokens. You must inspect your token list manually. If you see a token with no name, no logo, or a suspiciously low value that you did not purchase, treat it as dust.
No wallet is immune. Dusting works across Ethereum, Solana, BNB Chain, Polygon, and most blockchains that support token standards like ERC-20, BEP-20, or SPL. The method is the same. The surveillance is the same.
Dusting is not a theft. It is a reconnaissance technique. Recognizing it for what it is - a data-gathering operation - lets you defend against it without panic. Hide the tokens. Move on.
Not financial advice. watifsol.xyz publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.