Kraken says it was targeted by a large-scale cryptocurrency “dust attack” involving nearly 12,000 small transfers from wallets associated with HTX, forcing the exchange to conduct compliance reviews and temporarily restrict some customer accounts.
The transactions occurred between August 17 and August 24 and were generally worth only a few cents to several dollars each, according to Bloomberg reporting cited by multiple outlets. Kraken said the pattern appeared intended to distribute funds associated with sanctioned entities across other platforms. Kraken has since restored access to affected customers while continuing to block funds subject to sanctions requirements. The exchange said it is also working with relevant authorities. HTX denies deliberately initiating the transactions and says it is investigating whether the activity resulted from incorrect wallet attribution or malicious actions by a third party. The identity of whoever initiated the transfers therefore remains unresolved.
Dust Transfers Exploit a Compliance Weakness
Unlike a conventional cyberattack, the incident did not require attackers to compromise Kraken’s systems or steal customer credentials. Public blockchains generally allow anyone to send cryptocurrency to a known address without obtaining permission from its owner. That feature can be weaponized by sending tiny amounts from addresses associated with sanctioned or high-risk entities to otherwise legitimate wallets. Those transactions can subsequently trigger automated anti-money-laundering and sanctions-monitoring systems.
Kraken described the campaign as an attempt to spread U.K.- and European Union-sanctioned funds to other platforms and undermine trust across the cryptocurrency industry. The apparent strategy was that once sanctioned assets reached customer deposit addresses, exchanges might restrict entire accounts while conducting investigations. BlockSec CEO Andy Zhou compared the technique to poisoning a user’s transaction history: an attacker can cheaply add unwanted blockchain connections that the recipient cannot prevent. Blockchain analytics firm Arkham Intelligence identified the sending wallet as HTX-linked based partly on an address previously disclosed through HTX’s proof-of-reserves information. That association, however, does not independently establish who controlled the wallet when the transfers were made.
HTX Denies Responsibility as Sanctions Complicate Transfers
The episode follows earlier disputed transfers involving HTX-linked addresses. On August 20, HTX denied authorizing unsolicited microtransactions that had already caused compliance problems for users of other exchanges. It said an internal review found no official activity responsible for the transfers. One earlier cluster involved 166 small USDT transfers from an HTX-associated hot wallet. Fifteen receiving addresses were subsequently identified as Kraken-related, while approximately $4.2 million in associated funds became frozen amid compliance reviews. The incidents have become particularly sensitive because HTX faces sanctions-related restrictions in Europe.
Kraken’s challenge illustrates a broader problem for cryptocurrency compliance systems. Traditional financial institutions can generally reject or prevent transfers before they enter an account. Blockchain users often cannot stop an unknown address from sending tokens to them. Automatically treating every recipient of sanctioned “dust” as a willing counterparty could therefore allow malicious actors to deliberately disrupt thousands of unrelated accounts at minimal cost. Kraken’s decision to restore customer access while continuing to isolate the disputed assets suggests exchanges may increasingly need to distinguish between possession of unsolicited sanctioned funds and intentional interaction with sanctioned entities.
The nearly 12,000-transfer campaign provides an unusually large test of that distinction. No evidence currently indicates that Kraken itself was hacked, and the exchange has not reported theft of customer assets from the incident. Instead, the attack targeted the intersection between permissionless blockchain transfers and regulated exchanges’ obligation to screen potentially sanctioned funds. With HTX denying responsibility, attribution remains the key unanswered question. But regardless of who sent the transfers, the incident demonstrates that cryptocurrency sanctions controls themselves can become an attack surface when outsiders can cheaply manufacture suspicious connections between innocent users and flagged wallets.







