← Bitcoin Encyclopedia

Dust Attack

🌳 Advanced

💡 The Plain-English Definition

A dust attack is a privacy assault where someone sends tiny, unsolicited amounts of bitcoin — “dust” — to many addresses, hoping to track those addresses when the dust is later spent and link them to a real identity.

🤔 But Why Though?

Most Bitcoin privacy tools focus on stopping your own transactions from leaking information. A dust attack flips that around — the attacker sends you something tiny to plant a trap. Here’s how it works. The attacker sends a small amount — often exactly 546 satoshis, the dust limit, the smallest amount the network will relay — to thousands of Bitcoin addresses. Some of those addresses may have kept good privacy habits until now: no address reuse, no mixed inputs. But each one now holds an unsolicited UTXO, a discrete chunk of bitcoin, in this case a tiny one.

If the owner later spends bitcoin and their wallet automatically includes this dust UTXO as one of the inputs — which many wallets do when combining funds — then the common-input-ownership heuristic kicks in. That’s the chain-analysis assumption that all the inputs in one transaction share an owner, and it links the dust address to every other address in that same transaction. The attacker now knows those addresses belong to the same wallet. And if any one of them was ever tied to a real identity — through a KYC exchange that verified your identity, or some other route — the whole cluster becomes identifiable.

Dust attacks are carried out mainly by chain-analysis firms testing and expanding their address-clustering databases, by researchers studying network behaviour, and occasionally by bad actors tracking specific high-value targets.

🌍 The Real-World Analogy

Imagine someone slipping a tiny tracking tag into the pocket of every coat on a shop rail. You buy one and wear it, and the tag broadcasts your location. You never chose to carry it — it was planted. A dust attack is the same: the attacker plants a tiny marker in your wallet and follows where it goes.

⚡ So What?

For casual users, dust attacks are a background concern rather than a daily threat. They matter most to people actively working on their privacy. The defence is simple: use a wallet that supports coin control — the ability to choose exactly which UTXOs a transaction includes — learn to spot unexpected tiny incoming transactions from unknown sources, and mark them “do not spend.” If you never spend the dust, the trap never springs.

📩 The Daily Bit · free

Get one plain-English Bitcoin email each morning.

The Daily Bit — free, two minutes, unsubscribe anytime.

The Bitcoin EncyclopediaPrefer a book? The Bitcoin Encyclopedia