On this page
Where the mask actually slips: how addresses get tied to people
On-chain heuristics are powerful, but the real linkage usually happens off-chain:
- Exchange KYC: when you deposit or withdraw from a regulated exchange, it knows your address and your identity — and shares it on request.
- IP / timing metadata: the node that first broadcasts a transaction leaks network metadata; timing correlation is a strong signal.
- Reused addresses / payment labels link activity directly.
- — an attacker sends tiny amounts to many addresses so that a later spend merges them via the common-input heuristic (unpacked below).
- Attribution datasets: known wallets of exchanges, services, ransomware gangs, and sanctioned entities seed the graph.
Dusting: the trace that comes to you
Most of the leaks above are passive — someone waits for you to slip. is the active version: an attacker sends an unsolicited, near-worthless deposit to your address — often to tens of thousands of addresses at once. The amounts are tiny by design, typically a few hundred satoshis (around Bitcoin’s 546-satoshi “dust” threshold), and easy to miss among real activity. Receiving it costs you nothing. The attack plays out later, when the dust is spent.
Why people do it
- To cluster your wallet: if your wallet later sweeps the dust together with your other funds in one spend, the common-input heuristic proves all those inputs share one owner. The attacker watching the chain now sees addresses that looked unrelated collapse into a single cluster — yours.
- To work out who you are: once the cluster is mapped, any point where it touches the off-chain world — a deposit to a KYC’d exchange, an address pasted on a website or donation page — can attach a real identity to it. A confirmed crypto holder is a high-value target for theft, extortion, and targeted phishing.
- To deliver a scam: sometimes the dust is the lure. A memo field or token name carries a message (“claim your reward at…”) pointing to a phishing or wallet-drainer site. At minimum, dusting confirms which addresses are actively held, so scammers know exactly who to follow up with.
- To advertise: on-chain spam is cheap — one transaction can carry thousands of tiny outputs, each landing in a real wallet’s history. Some dusting waves have promoted exchanges; others push outright scam sites. The dust is just the delivery vehicle.
- To taint on purpose: the nastiest variant deliberately sends funds with a criminal or sanctioned history to your address. It can’t steal anything, but it can get your next deposit to a regulated exchange flagged — forced “exposure” (covered below).
How dust clusters a wallet
Mass dusting is routine, not theoretical. In 2019 one widely reported campaign dusted hundreds of thousands of Bitcoin addresses in a single day, and wallet vendors and analytics firms still publish alerts when new waves are detected.
Receiving dust does nothing by itself — the harm only starts if you spend it together with your other funds or click a link in its memo. Practical defenses: use a wallet with coin control so you can freeze or ignore the dusty coins, don’t visit links embedded in memos or token names, and let the dust sit rather than sweeping it. If it came from a clearly illicit source, document it — a screenshot and a short note matter far more to an exchange’s compliance team than the dust itself.