The largest American crypto exchange Kraken has faced an unconventional challenge for its compliance system. Between August 17 and 24, approximately 12,000 microtransactions were sent to the platform—amounts ranged from a few cents to a couple of dollars. These actions, classified as a classic "dust attack," were directed at the exchange's addresses from wallets that, according to the analytics service Arkham Intelligence, may belong to the sanctioned HTX (formerly Huobi).

The mechanics of the attack appear deliberate and cynical. The attacker likely sought to distribute funds from a sanctioned source across numerous Kraken addresses to trigger automated verification checks. The logic is simple: if assets linked to a sanctioned organization arrive in a client's account, the security system is obligated to freeze the account. That is exactly what happened in the first stage—some users temporarily lost access to their funds.

Exchange representatives emphasize that they do not know who exactly is behind the attack, but the compliance team has already restored access for most affected clients. Nevertheless, assets that fell under restrictions remain blocked, and Kraken has notified regulatory authorities about the incident.

HTX denies involvement, but the shadow of sanctions looms

HTX stated that an internal review found no involvement of the exchange's official accounts in these microtransactions. The company is now determining whether the wallet's linkage to the exchange was erroneous, or whether an external attacker attempting to discredit the platform is behind the transfers. Notably, the incident occurred amid tightening regulatory pressure: in May, the UK imposed sanctions on Huobi Global SA, and in July, the EU added HTX to the list of organizations with which transactions are prohibited—the ban took effect on August 23.

This attack is not the first of its kind. In 2022, a similar case occurred with Tornado Cash, when an unknown party sent 0.1 ETH to the wallets of prominent crypto influencers, including Coinbase CEO Brian Armstrong. At that time, Aave temporarily blocked Justin Sun's account, and TRM Labs analysts warned that "dust attacks" would become a serious problem for compliance with sanctions requirements.

My analysis: This case clearly demonstrates the vulnerability of automated compliance systems. Exchanges balance between the need to strictly enforce the sanctions regime and protecting users from manipulation. Attackers use this dilemma as a weapon, turning regulatory requirements into a tool for destabilizing platform operations. In the long term, the industry will need a more flexible methodology for analyzing transaction chains to distinguish real violations from deliberate provocations.