The largest cryptocurrency exchange Kraken has faced a massive "dust attack," resulting in the temporary restriction of some user accounts. The incident occurred between August 17 and 24, when approximately 12,000 transactions, each ranging from a few cents to a couple of dollars, were sent to the exchange's addresses.

In my assessment, such micro-transfers are a classic destabilization tool, aimed not at stealing funds but at triggering compliance procedures. In this case, the sender allegedly attempted to distribute assets linked to the sanctioned HTX (formerly Huobi Global SA) across various platforms, intending to trigger automatic checks and subsequent account freezes for recipients.

The calculation was based on the assumption that crediting funds from a sanctioned source would lead to a full account freeze. At the first stage, this worked—client access was temporarily restricted. However, Kraken's compliance team later restored functionality, although the assets themselves subject to restrictions remain blocked. The exchange also notified relevant regulatory authorities of the incident.

HTX denies involvement

Representatives of HTX stated that an internal review found no involvement of the exchange's official accounts in these micro-transfers. The company is currently investigating whether the wallet's association with the exchange was erroneous or whether an external attacker, attempting to discredit the platform, is behind the operations.

It is important to note the context: on May 26, the United Kingdom imposed sanctions against Huobi Global SA, and in July, the European Union followed suit, adding HTX to the list of organizations with which transactions are prohibited. For the exchange, this ban took effect on August 23—just one day before the series of suspicious transfers ended.

This is not the first case of "dust attacks" in the industry. In 2022, an unknown user sent 0.1 ETH from addresses linked to Tornado Cash to wallets of prominent crypto figures, including Coinbase CEO Brian Armstrong and Tron founder Justin Sun. At that time, Aave temporarily blocked Sun's wallet, and TRM Labs analysts warned that such attacks were becoming a serious challenge for compliance with sanctions requirements.

My comment: The current incident highlights the vulnerability of centralized exchanges to "dust attacks"—a tool that can be used both to test security systems and to inflict targeted reputational damage. In the long term, this will increase pressure on platforms to adopt more flexible monitoring mechanisms capable of distinguishing real sanctions risks from provocative micro-transfers.