
Kraken has successfully restored access to customer accounts that were temporarily restricted due to a coordinated 'dust attack' involving approximately 12,000 unsolicited crypto transfers. According to reports from Bloomberg, the exchange described the activity as a 'dust attack' coming from HTX-linked wallets, where thousands of small transfers worth between a few cents and several dollars reached Kraken-linked addresses between August 17 and 24, 2026. The transfers were specifically designed to spread sanctioned funds to other platforms and undermine confidence in compliance systems. Bloomberg reports that the exchange's problem was not a hack in the usual sense, but rather a sophisticated campaign that exploited the inherent vulnerability of public blockchain systems where recipients have no practical way to refuse incoming transactions. As a Kraken spokesperson explained, the recent dust attack originating from HTX-owned wallets appears to be an attempt to spread funds sanctioned by the U.K. and the European Union across other platforms and undermine trust across the industry. The exchange has since restored access to affected accounts but continues to hold onto the sanctioned funds separately.
HTX has categorically rejected suggestions that the transfers were part of an official campaign, with the exchange's representative stating that HTX had examined its internal accounts and found no evidence of company responsibility for the activities. As reported by Bloomberg, an HTX spokesperson said the exchange's internal review found no evidence that it sent the transfers and raised the possibility of wrong wallet attribution or a malicious third party. Justin Sun, the TRON founder closely associated with HTX, also rejected the claims publicly on August 18, with ETHNews reporting that he called the reports fabricated while HTX's head of markets, Liu Ye, said an internal investigation was under way. However, there was no evidence showing a direct link between these users and the 12,000 transfers, and the $4.2 million claim has not been independently confirmed. Blockchain analytics firm Arkham Intelligence classifies the wallet as HTX-linked based on an address HTX disclosed during its proof-of-reserves process, while BlockSec CEO Andy Zhou described the incident as akin to poisoning a user's transaction history, noting that attackers can deliberately manipulate transaction flows at very low cost because anyone can send assets on a blockchain without permission. HTX's denial does not resolve ownership of the sending wallet, as the exchange has not published a complete address list or transaction analysis supporting its explanation.
The transfers occurred during a period of heightened regulatory scrutiny, with the European Union adding HTX to Annex XLV of Council Regulation (EU) 2026/1848 on July 23, 2026, with the transaction ban taking effect on August 23, 2026. According to Bloomberg, the EU's 21st Russia sanctions package bans 14 crypto exchanges including HTX from transacting with EU entities, while the United Kingdom had already sanctioned Huobi Global S.A. on May 26, 2026. The U.K. sanctioned HTX operator Huobi Global SA in May, stating it was part of infrastructure that helped Russia evade sanctions. Since then, major exchanges including Bybit, OKX and Binance have restricted or reviewed HTX-related transactions. The timing meant that small transfers sent shortly before and after the EU restriction became active could attract heightened scrutiny, as exchanges serving U.K. or EU customers must identify prohibited transactions and prevent restricted funds from being released. Blockchain researcher TRM Labs had previously reported that HTX repeatedly changed wallets following the U.K. designation, with HTX describing those rotations as routine security practices rather than sanctions avoidance.
The incident highlights the operational challenges exchanges face when dealing with dusting attacks, which can create significant operational headaches as each transaction requires review under anti-money laundering and sanctions screening protocols. As reported by BitcoinWorld, Kraken's decision to freeze accounts indicates that the deposits triggered automated alerts, which is a standard response to unusual transaction patterns, though the quick restoration of access suggests the exchange determined the deposits did not warrant prolonged freezes. The recent dust attack on Kraken has drawn significant attention in the crypto space, with affected customers experiencing temporary account locks while the exchange conducted compliance reviews. For the broader crypto industry, this event serves as a reminder that exchanges are prime targets for malicious actors seeking to exploit vulnerabilities or create chaos, with dusting attacks, while not financially damaging, potentially disrupting operations and tarnishing reputations. The incident also raises questions about the effectiveness of current compliance tools, which may generate false positives that burden both exchanges and users. The weakness in compliance systems that rely heavily on direct wallet exposure is exposed, as a customer can receive funds from a sanctioned address without requesting, approving or controlling the transaction.