A crypto dusting attack is one of those threats most investors never consider until it's too late. The attacker sends a tiny amount of cryptocurrency, sometimes a fraction of a cent's worth, to hundreds of thousands of wallets at once. The coin is real. The purpose is surveillance.
Dusting attacks exploit a basic fact about most public blockchains: every transaction is recorded permanently, and wallet addresses are visible to anyone. If you later spend the "dust" by combining it with your other funds in a transaction, the attacker can link your various wallet addresses together. That narrows down who you are.
How dusting attacks actually work
The term "dust" refers to an amount of cryptocurrency so small it falls below the minimum threshold for a normal transaction. On Bitcoin, that's typically around 546 satoshis (roughly AU$0.05 at mid-2026 prices). On other chains, it varies.
Here's the sequence. An attacker sends dust to a target wallet. The wallet owner notices a small, unexplained deposit and, out of curiosity or habit, they do nothing special about it. Later, when that owner sends a larger transaction, their wallet software automatically consolidates inputs, which means it combines the dust with their other funds into a single outgoing transaction. That consolidation is visible on-chain. The attacker now knows those addresses belong to the same person.
From here, the attacker can use blockchain analytics to build a profile: which exchanges you've used, roughly how much you hold, how frequently you trade. In the worst cases, that profile is used for targeted phishing, extortion, or even physical theft.
Dusting isn't exclusive to Bitcoin. Litecoin, Dogecoin, and several other UTXO-based chains are common targets. Some EVM-compatible chains have seen dusting campaigns too, though the mechanics differ slightly.
Who runs these attacks and why
The motivations are more varied than most people expect.
- Cybercriminals use dusting to identify high-value targets for phishing or ransomware.
- Blockchain analytics firms have occasionally used dust-like probes to map wallet clusters for law enforcement or commercial clients.
- Scammers send dust to promote a token in wallet histories, knowing some recipients will investigate and potentially interact with a malicious contract.
That third category is especially relevant in 2026. On EVM chains like Ethereum and BNB Smart Chain, attackers send a tiny amount of an unknown token to your wallet. When you visit a block explorer and see it, curiosity leads some users to the token's website or a connected DApp. Those sites often contain wallet-draining contracts designed to steal approvals.
What Australian investors should do
The good news: a dusting attack can only succeed if you move the dust. If you never consolidate it with your other funds, the attacker learns almost nothing beyond the fact that you hold the wallet. The practical steps are straightforward.
Don't touch unexplained deposits. If you see a tiny, unsolicited amount of any coin arrive in your wallet, leave it. Most modern wallets let you mark UTXOs as "do not spend," a feature sometimes called coin control. Electrum, Sparrow, and several other Bitcoin wallets support this natively.
Use a coin control feature. UTXO management lets you choose exactly which inputs go into any outgoing transaction. By excluding the dusted UTXO, you prevent consolidation even if you forget about the attack later.
Consider address rotation. Generating a new receiving address for every transaction (which most HD wallets do automatically) limits the damage. Each address holds less transactional history, so linking them is harder.
Use a privacy-focused wallet or mixer, cautiously. CoinJoin implementations and similar privacy tools exist, but Australian investors should be aware of ATO guidance before using them. The ATO treats crypto as a CGT asset, and using a mixing service doesn't erase your tax obligations. It just makes the chain harder to follow. AUSTRAC has flagged mixing services as a compliance concern for exchanges, so understand the risk before going down that path.
Never interact with tokens you didn't request. On EVM chains, don't visit websites linked from unsolicited token deposits, and don't connect your wallet to any DApp you found through an unsolicited airdrop. The risk isn't the token itself; it's the smart contract permissions you might inadvertently grant.
How this intersects with Australian tax and regulation
Dusting raises a quietly awkward question for ATO compliance: is unsolicited dust taxable? The ATO's position is that received cryptocurrency is assessable income at the time of receipt if it has a determinable value. In practice, dust amounts are so small the tax exposure is negligible. But if you receive a larger unsolicited token drop, especially from a promotional airdrop, the ATO expects you to record it at its fair market value in AUD at the date of receipt. Understanding your crypto tax obligations, including what counts as an income event versus a capital event, is essential before you make any decisions about disposing of unsolicited coins.
The ATO's data matching program also means exchanges can see your transaction history. If you've been dusted and then accidentally consolidated those funds through an AUSTRAC-registered exchange, there's an on-chain trail. Keeping clean records of your wallet activity, and noting explicitly when you received unsolicited deposits, is a reasonable practice. A tool like a crypto cost basis tracker helps document these events accurately and keeps your CGT calculations defensible if the ATO comes asking.
A word on self-custody and vigilance
Hardware wallets don't protect you from dusting. A Ledger or Trezor secures your private keys brilliantly, but it doesn't stop an attacker from sending dust to your public address. The public address is, by definition, public.
What hardware wallets do help with is the other half of the equation: they prevent you from accidentally signing a malicious transaction if you're careful about what you approve. When a dusting attack escalates into a phishing attempt, a hardware wallet forces you to physically confirm the transaction on the device. That extra step catches a lot of social engineering.
The broader lesson from dusting attacks is that privacy on a public blockchain requires deliberate effort. Simply holding crypto in a wallet doesn't expose you. Moving it carelessly does. Coin control, address hygiene, and a healthy scepticism about unsolicited deposits are the practical defences available to every Australian investor right now, regardless of portfolio size.
Dusting isn't the most dramatic threat in crypto, but it's persistent, low-cost for attackers, and largely invisible to victims until the damage is done. Knowing how it works puts you well ahead of the curve.

