The cryptocurrency exchange Kraken has faced an unusual challenge for its compliance system: a series of microtransactions linked to a sanctioned address led to the temporary blocking of some user accounts. This concerns the so-called "dust attack," which has become a serious headache for the industry in recent years.

From August 17 to 24, approximately 12,000 transfers were received on Kraken wallets, with amounts ranging from a few cents to a couple of dollars. My analysis shows that this is a classic "clogging" scheme: an attacker or a group of individuals attempted to distribute funds, presumably belonging to the sanctioned exchange HTX, across numerous addresses to trigger automated checks and freeze accounts.

The logic of the attack is simple: if assets from a sanctioned source land in a client's account, compliance algorithms are obliged to react. In this case, it worked—access to accounts was temporarily restricted. However, as exchange representatives emphasized, they do not know who exactly is behind this operation. The compliance team has already restored access for most affected users, but the funds themselves, which fell under restrictions, remain blocked pending clarification of the circumstances. Kraken has also notified regulatory authorities.

HTX's Position: Denial and Versions

HTX, in turn, stated that an internal review did not reveal the involvement of the exchange's official accounts in these microtransactions. The company is now trying to determine whether the wallet's linkage to HTX was erroneous, or whether an external attacker is behind the transfers, using the exchange's reputation to destabilize the market.

It is important to note the context: the UK imposed sanctions against Huobi Global SA (HTX's parent structure) back in May, and the European Union joined in July. The ban on transactions for the exchange took effect on August 23—literally one day before the end of the series of suspicious transfers. This looks not like a coincidence, but like a well-planned provocation aimed at undermining trust in Kraken and creating chaos in compliance procedures.

Similar incidents have occurred before: in 2022, an unknown party sent 0.1 ETH from addresses linked to Tornado Cash to the wallets of top industry executives, including the head of Coinbase and the founder of Tron. At that time, Aave temporarily blocked Justin Sun's account. Analysts at TRM Labs warned that "dust attacks" would become a serious challenge for meeting sanctions requirements, and this case confirms their forecast.

My comment: This incident demonstrates the fragility of current transaction monitoring systems. Exchanges are forced to balance between strict compliance with sanctions and protecting clients from false positives. In the long term, this will push the industry toward developing smarter algorithms capable of distinguishing malicious microtransactions from real attempts to launder funds. Otherwise, we will see a rise in such attacks aimed at paralyzing the operations of major platforms.