Key Insights:
- If there is a connection on the chain that is not desired by the recipient, this can be done with unsolicited funds.
- Transaction patterns and address clustering are important to establish ownership, which can cause blockchain labels to misidentify it.
- Exchanges can apply different standards when reviewing exposure to restricted counterparties.
HTX dust attack reports have raised concerns after crypto users received unsolicited USDT transfers from exchange-linked addresses. HTX denied initiating the transfers on August 18 and opened an internal investigation into their source.
Exchange investigates disputed USDT transfers
Crypto users reported small USDT deposits from addresses that blockchain services associated with HTX, formerly Huobi. Some recipients feared the transfers could create unwanted exposure to an exchange facing European and British restrictions. One reported case involved roughly 7.5 USDT arriving in a Coinbase account. The recipient said Coinbase requested information explaining the funds’ origin.
孙哥是不是在报复社会。。
htx疯狂的往外转小额,污染其他地址。。
我的coinbase收到孙哥的7.5u投毒。。
目前coinbase说不解释清楚,就关户。。。 pic.twitter.com/Qz49RxTGOL
— 紫夜 (@0xZiye) August 18, 2026
However, Coinbase has not publicly confirmed a permanent account freeze linked to that transaction. Other reports pointed to transfers from an address labelled HTX 48. Meanwhile, an HTX-related token contract reportedly interacted with thousands of wallets on BNB Smart Chain. These reports have increased scrutiny of how blockchain analytics services identify exchange-controlled addresses.
HTX market representative Liu Ye said the company immediately reviewed the allegations. The exchange found no official transfers or internal testing that could explain the activity. HTX is now examining transaction origins and possible errors involving blockchain address labels. It has not released transaction hashes, sending addresses, or a verified recipient count. Consequently, independent analysts cannot yet confirm a coordinated HTX dust attack or identify who controlled the sending wallets.
Sanctions raise the compliance stakes
The controversy carries added significance because regulators have imposed restrictions involving Huobi Global S.A. Britain designated the company on May 26 under its Russia sanctions framework. The measures included an asset freeze and restrictions involving correspondent banking and payment processing.
The European Union later added HTX to restrictive measures through Regulation 2026/1848. The transaction prohibition takes effect on August 23, according to information accompanying the measure. However, those restrictions do not automatically establish wrongdoing by recipients of unsolicited cryptocurrency. The distinction matters because blockchain transactions can reach wallets without their owners requesting them.
Wallets are commonly analyzed for compliance purposes using transaction history and wallet clustering. So even for passive transfers, it’s possible to trigger automated alerts or further customer checks. Some exchanges might also have varying risk thresholds.
One platform may ask for information, and another may freeze transactions for the time being during the review.
Together, these issues make the HTX dust attack allegations particularly sensitive for traders who regularly move assets between platforms.
Poisoning allegations remain unproven
Some community members described the transfers as address poisoning. Yet conventional address poisoning usually follows a different pattern. The planted address is now listed in the victim’s transaction history. Users are subsequently expected to copy that address and send vital assets to the wrong location. Attackers hope users later copy that address and mistakenly send valuable assets there.
No public evidence currently shows recipients of the disputed HTX-linked transfers sent assets to lookalike addresses. No confirmed losses have emerged from the reported transactions either. Small unsolicited deposits alone cannot establish a conventional poisoning attack.
The activity could instead resemble compliance poisoning if someone intentionally targeted wallets to trigger sanctions screening. However, that motive also remains unverified. HTX denies intentionally distributing the funds, while no independent blockchain security company has publicly identified an operator. Thus, the term “established” coordinated campaign for the HTX dust attack would not be warranted by the evidence available.
Wider implications for wallet screening
The immediate risk could be non-compliance, not necessarily cryptocurrency theft. Investigators can use automated monitoring tools to alert on transactions prior to determining the origin of the funds to the address. That poses a problem for the honest users who cannot stop others from transferring assets to addresses on the public blockchain that are not known to them.
The user should keep the trading platform’s compliance notices and transaction hashes. They should also steer clear of unprompted money transfers unless instructed by the concerned platform. Also, users of wallets should double-check full wallet addresses rather than copying from their transaction history. Saved address books and allowlists can reduce exposure to conventional poisoning attempts.
The episode also tests how heavily exchanges rely on third-party blockchain labels. While the presence of an attribution system can be a useful compliance indicator, a presence label alone doesn’t necessarily mean wallet ownership. More layers can be added to the attribution process, such as deposit addresses, payment processors, consolidation wallets, and intermediary services.
Conclusion
HTX dust attack controversy is still unresolved and HTX is investigating the transfers and their possible relationship with its addresses. The exchange will give them more details once they confirm their origin and circumstances. Until transaction hashes and ownership evidence emerge, conclusions about a deliberate campaign remain premature.
Nevertheless, the incident serves as a glimpse into the increasing challenge of crypto compliance. Permissionless blockchains can provide anyone the ability to transact with another address, and automated screening systems can use transaction histories as risk indicators. There is the possibility that regulators, exchanges and analytics firms will be pushed to make a distinction between what is a legitimate trade and what is not.









