A decent chunk of the messages I get about wallet security start with a screenshot. Somebody opens their transaction history, finds a deposit worth a few cents from an address they have never seen, or an outgoing transfer to a wallet they swear they never touched, and assumes their keys are compromised. Usually they are fine. What they are looking at is one of two attacks that cost almost nothing to run at scale, and both work best on people who never learned why they exist. They also quietly wreck naive on-chain analysis, which is the part I care about day to day.
The two get lumped together because they both show up as junk in your history, but they are after different things. Dusting wants information out of you. Address poisoning wants money out of you. It is worth walking through both, because the correct response to each is different and the wrong response to either can cost you.
Dusting is a tracking tool, mostly
A dusting attack is someone spraying tiny amounts of coin, a few hundred satoshis or a fraction of a cent, across thousands of addresses at once. On a UTXO chain like Bitcoin the point is what happens later. Wallets build transactions by combining unspent outputs, so if you ever spend that dust alongside your real coins, you have just told the attacker that every input in that transaction belongs to the same owner. That is the common-input-ownership heuristic, the workhorse of chain surveillance, and one carelessly spent dust output can link an address you thought was fresh to your whole cluster, including addresses tied to an exchange account with your legal name on it.
Who bothers? Analytics firms have used dust to map wallet clusters. Scammers use it to find wallets worth phishing, since dust that later moves tells them which addresses are alive and how the owner consolidates. On account-based chains like Ethereum the same idea mutates into spam tokens, worthless ERC-20s airdropped to your address, often with a token name that is literally a URL. The token does nothing sitting in your wallet. The danger is the website it advertises, where claiming or swapping the thing walks you into signing a malicious approval. I have also seen dust used as plain advertising, which is annoying and harmless.
The safe response to dust is boring. On Bitcoin, use a wallet with coin control, mark the dusted UTXO as do-not-spend, and forget it exists. On Ethereum and similar chains, do nothing at all. Do not send it back, do not try to sell the spam token, and do not visit whatever site the token name points to. Tokens you did not ask for cannot hurt you until you interact with them.
Address poisoning is a theft tool
Poisoning is nastier because it targets a habit almost everyone has, which is copying addresses out of transaction history instead of from a verified source. The attacker watches the chain for active wallets, sees who you send to regularly, then generates a vanity address matching the first few and last few characters of that real counterparty. Grinding out a match on eight characters takes commodity hardware very little time. They plant the lookalike in your history either by sending you dust from it or, on Ethereum, by abusing the fact that a zero-value transferFrom call needs no allowance. That trick lets a stranger emit a transfer event showing you sent zero tokens to their lookalike address, and plenty of wallet UIs render it in your outgoing history like any legitimate send.
Weeks or months later you want to pay that regular counterparty, you scroll your history, you copy what looks like the right address because the ends match, and the funds are gone the moment the transaction confirms. No malware, no stolen keys, no signature you should have refused. The whole exploit is that humans verify the ends of an address while wallet UIs truncate the middle. Some of the largest single-wallet thefts I am aware of worked exactly this way, and the victims included people who had been in the industry for years, because the attack gets stronger the more routine your sending habits are.
The habits that neutralize both
- Never copy an address out of your transaction history. Use the wallet's address book, a name service entry you verified before, or a fresh copy from the counterparty over a second channel.
- When you verify an address, check a chunk from the middle, and check more than eight characters total. The ends are precisely what the attacker paid to fake.
- For any transfer large enough to hurt, send a small test amount first and confirm receipt out-of-band before sending the rest. The extra fee is cheap insurance.
- On UTXO chains, freeze dust with coin control rather than spending or consolidating it.
- Treat unsolicited tokens as inert garbage. Hide them in the UI if your wallet allows it, and never call approve, claim, or swap on anything you did not knowingly acquire.
What this does to on-chain analysis
Here is the part that matters if you track wallets rather than just hold one. Dust and poison are, by design, indistinguishable from real activity if you only read raw transfer lists. A whale wallet that appears to have three hundred counterparties may have thirty real ones and a long tail of dust, spam tokens, and zero-value transfers it never asked for. I have watched people build a smart-money accumulation thesis on top of transfer events that were airdropped spam the wallet owner never touched.
So filter before concluding anything. Drop transfers below a dust threshold, and accept that the threshold is a judgment call, roughly anything worth less than the gas it took to move is suspect. Drop zero-value token transfers entirely, they carry no economic information and are overwhelmingly poison. Ignore inbound transfers of tokens with no liquidity or no known contract history. Most importantly, weight actions the owner actually signed far above anything inbound, because inbound is free for an attacker to fabricate while outbound costs them a private key. The wallet-tracking feeds we run at Blockcircle only stay usable because filters like these run before a human ever sees the data, and the raw stream underneath is genuinely full of this stuff.
Most of the defense, for holders and analysts alike, comes down to internalizing that a wallet history is a public wall and strangers can write on it for pennies. Once that sinks in, dust becomes ignorable, lookalike addresses become a known trap with a known workaround, and other people's transaction lists become something you read the way you read an inbox, with the spam folder in mind.