Kraken recently processed a wave of low-value blockchain transfers. CoinDesk, citing Arkham Intelligence data, reported nearly 12,000 transactions from wallets labelled as linked to HTX reaching Kraken-related addresses between 17 and 24 August. Kraken said the activity appeared designed to spread sanctioned funds and trigger restrictions on customer accounts.
Some customers briefly lost access at the start of the incident. Kraken said access was restored while the relevant funds remained isolated and the exchange worked with authorities. HTX said an internal review found no official accounts responsible and that it was examining possible wallet misidentification or third-party activity.
The sender and motive have not been conclusively established. “HTX-linked” is an attribution label, not proof of direct control, and Kraken’s attack assessment remains the platform’s view.
Why dust can become an operational weapon
Public blockchains allow anyone to send assets to a known address without the recipient’s consent. Distributing tiny amounts across many wallets can create on-chain links, trigger sanctions or anti-money-laundering checks and overload compliance operations. If a platform equates an unsolicited receipt with an intentional transaction, its controls can be turned against customers.
Kraken’s support guidance lists HTX (Huobi Global SA) among platforms subject to an EU transaction prohibition from 23 August 2026. Yet address attribution is probabilistic: exchanges rotate wallets, customers initiate withdrawals from shared infrastructure and third parties can send assets to public deposit addresses.
Better controls for exchanges
Screening should consider amount, frequency, timing, customer history, attribution confidence and whether the customer initiated the interaction. Suspicious funds can be isolated from the rest of an account where legally possible. Platforms also need fast appeals, understandable explanations and batch-incident handling when one source sends tiny amounts to many unrelated users.
Customers should preserve transaction hashes, notices and support records. They should not return or consolidate unfamiliar dust before receiving official guidance, because doing so may create additional on-chain links.
TraderVote view
Compliance systems can themselves become an attack surface. Static blacklists and one-hop rules may confuse passive receipt with intentional dealings. Mature controls need risk tiers, attribution confidence, attack-pattern detection, human review and prompt customer remediation while still preserving sanctions controls.
Sources
Kraken support guidance, “EU Sanctions and Certain Crypto-Asset Services”, accessed 29 August 2026: https://support.kraken.com/ca/articles/information-about-eu-sanctions-and-certain-crypto-asset-services
CoinDesk, “Kraken users were briefly locked out after a flood of sanctioned crypto transactions”, 28 August 2026: https://www.coindesk.com/business/2026/08/28/kraken-users-briefly-locked-out-after-a-flood-of-sanctioned-crypto-transactions
Bitcoin Magazine, “Kraken Says ‘Dust Attack’ From Sanctioned HTX Wallet Locked Out Customers”, 25 August 2026: https://bitcoinmagazine.com/news/kraken-says-users-were-dust-attacked
Bloomberg News via Bloomberg Law, “Dust Attack on Kraken Shows Challenge of Policing Crypto Flows”, 25 August 2026: https://news.bloomberglaw.com/crypto/dust-attack-on-kraken-shows-challenge-of-policing-crypto-flows
Written independently by Hengyuan from platform guidance and corroborating reports verifiable on 29 August 2026. Wallet attribution, sender identity and motive remain unconfirmed. This article is not investment or legal advice.

Discussion
Comments (0)
Sign in to join the discussion.
Sign inNo published comments yet. Start the discussion.