babybitcoin.space

What is a dust attack in Bitcoin, and how can you avoid it?

A dust attack is a privacy-eroding technique in which an attacker sends tiny amounts of bitcoin - called "dust" - to many wallet addresses in order to trace their activity and potentially identify the owners. You avoid it by using a wallet that marks or ignores these small inputs, or by not spending dust outputs together with your other funds.


What counts as dust

In Bitcoin, "dust" has no official definition, but it generally refers to an amount so small that it costs more in transaction fees to spend than the value it holds. For example, if network fees are 20 sat/vbyte and the output is 300 satoshis, spending it would cost more in fees than the output is worth. Most wallets define dust internally - commonly any UTXO below 500 to 1000 satoshis (around $0.10 - $0.30 at typical prices). Attackers exploit this by sending amounts just above that threshold, so the dust can be spent, but is still small enough to be ignored or treated as noise.


How a dust attack works

The attacker sends a small payment to a large number of addresses. They do not need to control those addresses - they simply broadcast a transaction from their own wallet to many recipients. The goal is not to steal funds, but to gather information.

Here is the typical sequence:

  1. The attacker collects a list of Bitcoin addresses - possibly from a public blockchain explorer, a previous data breach, or a service that leaked user addresses.
  2. They send a small amount (e.g., 546 satoshis, the minimum allowed by some nodes) to each address in one or a few transactions.
  3. The attacker monitors the blockchain. When a recipient later spends their main funds, the dust output may be included in the same transaction.
  4. Because the attacker controls the dust they sent, they can see the transaction that spends it. That transaction likely also contains the user’s larger UTXOs, revealing the full set of addresses the user controls.

The attacker’s aim is to link addresses to a single wallet or person. This information can be sold, used for targeted phishing, or used to de-anonymize activity on the network.


Why dust attacks are not a theft risk

Dust attacks do not steal bitcoin. They do not compromise private keys, and they do not allow the attacker to spend your funds. The risk is entirely about privacy. If you keep your bitcoin in a wallet that never spends dust outputs alongside your other coins, the attack fails.


How to avoid or mitigate dust attacks

Use a wallet that marks dust

Many modern Bitcoin wallets - especially those that follow Bitcoin Improvement Proposal (BIP) 69 or that implement "dust control" - automatically label small inputs as dust and prevent them from being spent in transactions that also use your larger UTXOs. Check your wallet’s settings or documentation for a "dust threshold" or "avoid dust" option.

Spend dust separately

If your wallet does not automatically filter dust, you can manually create a transaction that spends only the dust output to yourself - but only if the dust amount plus the fee is still worth doing. In most cases, the dust is economically unspendable, and trying to move it will cost you more than it is worth.

Use a full node with coin control

Running your own Bitcoin full node and a wallet that offers coin control (such as Bitcoin Core) gives you full visibility over every UTXO. You can see which inputs are dust and deliberately exclude them from any transaction you make.

Consolidate dust only when it is cheap

If you accumulate many tiny UTXOs from legitimate activity (e.g., small payments or faucets), you can consolidate them into a single larger output during a period of low transaction fees. But do so in a dedicated consolidation transaction that does not also spend your main wallet funds.

Do not reuse addresses

Address reuse makes dust attacks more effective because it is easier for an attacker to link a dust payment to a specific user. Using a new address for every payment (as HD wallets do automatically) reduces the attack surface.


Dust attacks in practice

Dust attacks have been documented since at least 2018. They are not common against individuals, but have been observed targeting exchanges, large holders, and services that publish deposit addresses. Most well-designed wallets now include dust protection by default, so the average user is unlikely to notice or be harmed by them.

If you receive a tiny unexpected transaction, you can safely ignore it. Do not spend it with your other funds, and do not click any links or messages that might accompany it (some dust attacks include a note in the transaction’s OP_RETURN data, such as a URL or contact address - these are phishing attempts, not legitimate communication).


Summary

Not financial advice. babybitcoin.space publishes market data and general information about babybitcoin. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.

Back to bitcoin