Kraken Users Locked Out After Sanctioned HTX Wallet Sends “Dust” to Their Accounts

TL;DR
The short version
- 1In the periods of August 17-24, almost 12,000 small, unsolicited crypto transfers landed in Kraken-linked wallets, coming from an address attached to sanctioned exchange HTX (formerly known as Huobi).
- 2Kraken’s automated compliance systems restricted some incoming funds and briefly locked targeted customer accounts, despite these customers never having requested or deliberately accepted the transfers.
- 3The tactic is commonly referred to as “dust attack”; Kraken is in the belief that the purpose was to spread sanctioned funds over other platforms and trigger disruptive compliance freezes industry-wide.
- 4HTX has proceeded to deny any participation in this and says it’s investigating if the wallet was misapplied or exploited by a third party; the sending wallet was only attached to HTX via an earlier proof-of-reserves disclosure, not confirmed real-time control.
- 5Kraken restored access for impacted users but rendered the disputed sanctioned funds frozen separately. This incident occurs just days after EU sanctions against HTX officially took place on August 23.
The Happenings
On an 8-day window between August 17 and August 24, a wallet attached to HTX sent almost 12,000 separate crypto transfers to addresses linked to Kraken. Most deposits were quite small; only a few cents to a couple of dollars, however the volume was different from routine blockchain occurrences: approximately 1,500 unsolicited deposits daily for 7 days straight.
Kraken’s automated anti-money-laundering and sanctions-screening systems took charge and flagged any incoming funds associated with a sanctioned wallet and locked the receiving account pending review.
The big challenge here is that the customers receiving these deposits hadn’t participated in any wrong doing; they didn’t request the funds, had no idea of the sender, and had no way to decline a transfer being deposited in their wallet unsolicited.
Once Kraken’s compliance team finished its review, the exchange restored access for any affected users, however kept the particular sanctioned funds held separately instead of releasing them.
The Goal of Doing This
Kraken has depicted this incident as a “dust attack”; a special tactic where small amounts of crypto get sent to many wallet addresses, usually to track and de-anonymize owners by seeing how the dust moves.
But Kraken considers that this instance had a more disruptive goal. “We don’t know who is behind these attacks, but they likely expect that if sanctioned funds land in a client account, it triggers a full account lock, causing operational disruption for a large number of users,” a spokesperson mentioned, adding that the attacks seem to be targeted at spreading UK- and EU-sanctioned funds across other platforms “in order to discredit the broader industry.”
That’s a significant threat model than classic wallet-tracing dust attacks. If the intention was to weaponize sanctions compliance itself, the intruder doesn’t essentially need to steal anything; but to make an exchange’s own automated defenses work against its customers.
The HTX Sanctions Backdrop
The timing of this incident is not to be ignored. HTX, formerly Huobi, has been subjected to mounting sanctions pressure all through the year. The UK went on to add operator Huobi Global SA to its Russia sanctions list in May, accusing it of helping Russian groups evade war-related restrictions.
The EU followed in July, targeting crypto companies that aid in circumventing sanctions. That EU transaction restriction took effect August 23, happening right when the dust transfer occurring.
HTX has gone on to refute any wrongdoing throughout; Justin Sun acts as an adviser to the exchange. Other big exchanges, including Bybit, OKX, and Binance, have already begun limiting transactions connected to HTX.
A Familiar Playbook
This isn’t something new, even at this scale. In 2022, after the US Treasury sanctioned the mixer Tornado Cash, tiny amounts of Ether were deposited to prominent, unrelated wallets in a comparable manner; an endeavor to make innocent holders look complicit in retrospect.
The Kraken incident follows the same reasoning but at a bigger scale: leveraging the transparency of public blockchains, which allow any user to send funds to any address without their permission, against the compliance systems put in place to police that same transparency.
Who Actually Controlled the Wallet?
Arkham Intelligence determined that the sending wallet was linked to HTX, but that acknowledgement came from matching the address against wallets HTX had formerly and voluntarily revealed in its own proof-of-reserves reporting; not from confirming who managed the wallet when these particular transfers went out.
A walletthat was once linked to HTX, doesn’t translate to HTX itself, rather a third party who was able to access or spoofed activity from that address, and completed these transactions.
HTX has proceeded to deny any involvement, mentioning it “absolutely did not engage in such behaviour,” and says it’s still in the investigative process of whether the incident came from wallet mapping errors, an operational failure, or an intentional third-party misuse.
HTX was yet to reveal a detailed breakdown of the wallet’s activity as of this reporting, leaving open precisely how funds were transacted without the exchange’s own involvement.
Why This Matters Beyond Kraken
This incident showcases a structural tension every exchange is subjected to: receiving funds is barely the same as requesting them, however automated compliance systems often can’t easily determine the difference in real time.
Sanctions-screening tools mostly respond to where funds came from, and not whether the recipient took part in accepting them; a big disparity that barely matters in typical compliance instances. A dust attack particularly capitalizes on that gap.
As sanctions regimes continue to target crypto-native platforms directly, sanctioned wallets sustain full technical ability to send funds to anyone without their exclusive consent; hence forcing receiving platforms to essentially choose between disruptive precautionary freezes or looser screening that risks real infringements. Kraken’s goal; restoring access as fast as possible while still holding flagged funds separately.
Conclusion
Almost 12,000 unwanted transfers, managed to lock out a significant number of Kraken customers by being deposited in the wrong wallets at the wrong time.
Whether HTX itself organized this, lost control of a revealed wallet, or is being falsely incriminated by a third party remains unresolved; and this ambiguity is itself a narrative, since sanctions attribution on public blockchains tend to get murky in practice than the underlying technology’s transparency may suggest.
As sanctions enforcement against crypto platforms intensifies, exchanges remain at an undefined position: freeze first and investigate, or remain at a risk of becoming an unwitting conduit for funds a government has already considered off-limits.
This is a developing story. We’ll update this piece as HTX’s investigation concludes and if further attribution details emerge.

