Between August 17 and 24, a wallet linked to HTX sent nearly 12,000 micro-transfers to Kraken users, with most valued at only a few cents. The activity triggered Kraken’s automated compliance systems, which temporarily locked affected accounts. Kraken later restored the accounts but held the flagged funds. The incident exposed the risks of taint-based monitoring, as Kraken flagged an “intentional taint spread,” while HTX denied the claim and cited misattribution. The attack underscores the need for more sophisticated risk-scoring models rather than simple blacklist-based monitoring.
Kraken users experienced temporary account limitations after a coordinated dust attack involving micro-transfers from an HTX-linked wallet. The exchange locked the affected accounts for compliance reasons but later reopened them while holding the flagged funds.
Between August 17 and 24, a wallet flagged by Arkham Intelligence as tied to HTX made nearly 12,000 tiny transfers to Kraken users. Kraken stated that such activity is typically associated with spreading sanctioned funds to trigger automatic compliance systems.
The incident highlights the limitations of exchange compliance systems that block addresses as a preventive measure against money laundering. The situation points to the importance of deeper risk scoring rather than a simple division of addresses into blacklisted and non-blacklisted categories.
Under OFAC guidance and global travel rule implementation, regulators are closely examining how exchanges handle crypto data to prevent money laundering and terrorist financing. This dust attack stands out due to its cross-exchange impact and sophistication, marking an evolution from earlier dust attacks.
Companies like Chainalysis, Arkham, and TRM Labs are leading providers of technology and data that help exchanges comply with their legal obligations. The attack demonstrates the need for more advanced monitoring tools that can distinguish between malicious taint spread and legitimate transactions.
