Regulation & Policy
Share
Kraken received nearly 12,000 dust transfers linked to HTX between August 17 and 24, triggering compliance reviews and temporarily restricting customer accounts, exposing how permissionless blockchains can be used to weaponize sanctions-screening systems against legitimate users.
Kraken says it was targeted by a large-scale cryptocurrency “dust attack” involving nearly 12,000 small transfers, exposing a potential weakness at the intersection of permissionless blockchains and regulated exchanges' sanctions controls.
The transactions, which occurred between August 17 and August 24, were generally worth only a few cents to several dollars. Kraken said the campaign appeared designed to spread funds associated with sanctioned entities across other platforms, triggering compliance reviews and temporarily restricting some customer accounts.
Kraken has since restored access to affected customers while continuing to block funds subject to sanctions requirements. The exchange said it is also working with relevant authorities.
HTX has denied deliberately initiating the transfers and said it is investigating whether the activity resulted from incorrect wallet attribution or malicious actions by a third party. The identity of whoever controlled the sending wallets during the campaign remains unresolved.
The incident did not involve a breach of Kraken's systems or the theft of customer assets. Instead, it targeted something more fundamental: the fact that blockchain users cannot prevent someone else from sending funds to their wallets.
A conventional cyberattack generally requires an attacker to compromise a system, exploit a vulnerability or gain unauthorized access.
A dust attack works differently.
Because public blockchains are permissionless, anyone can send cryptocurrency to a known wallet address without the recipient's approval. An attacker can exploit that feature by sending tiny amounts of crypto from wallets associated with sanctioned or high-risk entities to otherwise legitimate addresses.
Those transfers become part of the recipient's public transaction history, potentially creating links that automated anti-money-laundering and sanctions-monitoring systems must investigate.
Kraken said the apparent goal was to distribute U.K.- and European Union-sanctioned funds across other platforms and undermine trust in the cryptocurrency ecosystem.
The potential disruption is significant. If a transfer from a flagged address automatically triggers restrictions on the receiving account, an attacker could manufacture suspicious blockchain connections involving thousands of unrelated users at very little cost.
The incident highlights a challenge that traditional financial systems largely avoid.
Banks can generally reject or stop an incoming transfer before it reaches a customer's account. On a public blockchain, however, the recipient has no equivalent ability to refuse an unsolicited transaction.
That creates an important distinction for compliance teams: receiving funds is not necessarily the same as choosing to interact with the sender.
Automatically treating every recipient of sanctioned dust as a willing counterparty could allow malicious actors to weaponize sanctions-screening systems against legitimate users.
Blockchain analytics firm Arkham Intelligence identified the sending wallet as HTX-linked, partly based on an address previously disclosed through HTX's proof-of-reserves information. However, the connection does not independently establish who controlled the wallet when the transfers occurred.
HTX has therefore disputed responsibility.
The latest campaign follows earlier disputed microtransactions involving addresses linked to HTX.
On August 20, HTX denied authorizing unsolicited transfers that had already caused compliance problems for users at other exchanges. The company said an internal review found no official activity responsible for those transactions.
An earlier cluster involved 166 small USDT transfers from an HTX-associated hot wallet. Fifteen receiving addresses were subsequently identified as Kraken-related, while around $4.2 million in associated funds became frozen during compliance reviews.
The incidents have become particularly sensitive because of sanctions-related restrictions affecting HTX in Europe.
For now, however, the evidence does not establish whether HTX itself initiated the transfers, whether the wallet attribution was incorrect, or whether another party was responsible.
Attribution remains the central unanswered question.
Kraken's response points to how exchanges may need to adapt their compliance systems to permissionless networks.
The exchange restored access to affected customers while continuing to isolate funds subject to sanctions requirements. That approach distinguishes between holding unsolicited funds linked to a sanctioned address and intentionally engaging with a sanctioned entity.
The distinction could become increasingly important as blockchain compliance systems become more automated.
The nearly 12,000-transfer campaign shows how cheaply an attacker can potentially create suspicious connections across public blockchains. In this case, no Kraken systems were hacked and no customer assets were reported stolen.
Instead, the attack appears to have targeted the compliance infrastructure surrounding blockchain transactions.
Regardless of who ultimately sent the transfers, the incident demonstrates that sanctions controls can themselves become an attack surface. When anyone can send funds to anyone else, malicious actors may be able to manufacture suspicious transaction histories and force regulated platforms to investigate innocent recipients.
The challenge for exchanges will be separating a transaction's technical connection on-chain from evidence of a user's intentional relationship with a sanctioned counterparty.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks

The Missing Orchestration Layer Holding Back Institutional Digital Assets
Julian Sawyer
Aug 18, 2026
5 min

Beyond Crypto Access: How ARP Digital Is Building the UAE’s Digital Capital Infrastructure
Anna K.
Aug 17, 2026
8 min

Exclusive: Flipster GM Benjamin Grolimund Discusses Full VARA License and UAE Growth
Anna K.
Aug 4, 2026
4 min
Read More Articles
In the Same Space

U.S. Accounting Board Proposes Treating Some Stablecoins as Cash Equivalents
News Desk
Aug 19, 2026
2 min

UK Gives Bank of England Mandate to Support Stablecoin Innovation
News Desk
Aug 27, 2026
4 min

SEC Revives Crypto Custody Rules With a Different Regulatory Approach
News Desk
Aug 27, 2026
4 min

Chainalysis vs TRM Labs: The $94.6M US Crypto Intelligence Fight
Ola Rajeh
Aug 26, 2026
7 min


