{"id":223,"date":"2026-08-13T11:58:35","date_gmt":"2026-08-13T15:58:35","guid":{"rendered":"https:\/\/dolanduck.io\/blog\/?p=223"},"modified":"2026-08-13T11:58:35","modified_gmt":"2026-08-13T15:58:35","slug":"dust-attack-crypto-explained","status":"publish","type":"post","link":"https:\/\/dolanduck.io\/blog\/dust-attack-crypto-explained\/","title":{"rendered":"Dust Attacks Explained: Why Random Tokens Appear in Wallets"},"content":{"rendered":"\n<p>A dust attack is an unsolicited transfer of a tiny amount to a large number of wallets, sent either to track how those wallets move funds or to plant something the owner will interact with. On Solana the second motive dominates: the &#8220;dust&#8221; is usually a worthless token with an enticing name and an image pointing at a phishing site, delivered to thousands of addresses for a few dollars in fees. The token itself cannot harm you sitting in your wallet. Everything dangerous about it starts the moment you try to do something with it.<\/p>\n\n\n<!--more-->\n\n\n<h2 class=\"wp-block-heading\">Key Facts<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Dusting on Solana is cheap because base fees are a fraction of a cent per transfer.<\/li><li>The sender pays the rent for the token account they open in your wallet, not you.<\/li><li>Receiving a token is entirely passive \u2014 nothing executes in your wallet on arrival.<\/li><li>The payload is in the token&#8217;s name, image or metadata URL, pointing somewhere hostile.<\/li><li>Selling or swapping unknown dust is where the trap fires, not receiving it.<\/li><li>Token-2022 transfer hooks mean some tokens can run creator code when you move them.<\/li><li>Closing a dust token account returns its rent deposit to you, not to the sender.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Why Anyone Bothers<\/h2>\n\n\n\n<p>Two motives, with different histories. The original dusting attack was analytical: send tiny amounts to many addresses, then watch which ones later consolidate those amounts together, revealing that one entity controls several wallets. That technique matters most on UTXO chains like Bitcoin and is largely irrelevant on Solana, where account balances are already explicit.<\/p>\n\n\n\n<p>The Solana version is marketing and phishing. A worthless token arrives named after something plausible, its image reads &#8220;Claim 500 USDC at [domain]&#8221;, and a percentage of recipients will visit the domain and connect a wallet. Sending to fifty thousand addresses costs the attacker perhaps a few hundred dollars including rent deposits, which is trivially profitable if even a handful of people connect. It is the same economics behind <a href=\"\/blog\/memecoin-ticker-collision-fake-tokens\/\">ticker collisions and lookalike tokens<\/a>, applied by push instead of by search.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Dust Can and Cannot Do<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Action<\/th><th>Risk<\/th><th>Why<\/th><\/tr><\/thead><tbody><tr><td>Receiving the token<\/td><td>None<\/td><td>Arrival is passive; no code runs in your wallet<\/td><\/tr><tr><td>Looking at it in your wallet<\/td><td>None<\/td><td>Displaying metadata does not execute anything<\/td><\/tr><tr><td>Visiting the URL in its name or image<\/td><td>High<\/td><td>That is the entire point of the delivery<\/td><\/tr><tr><td>Swapping or selling it<\/td><td>Moderate to high<\/td><td>Token-2022 hooks can run creator code on transfer<\/td><\/tr><tr><td>Approving a transaction to &#8220;claim&#8221; something<\/td><td>Severe<\/td><td>The signature is the attack<\/td><\/tr><tr><td>Closing the account and ignoring it<\/td><td>None<\/td><td>Returns the rent and removes the clutter<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Row four deserves attention because the instinct to &#8220;just sell it in case it&#8217;s worth something&#8221; feels harmless. Under Token-2022, a mint can carry a transfer hook that executes creator-supplied code on every transfer, so moving an unknown token is not the neutral act it was under the original token program. Checking which token program a mint belongs to before touching it takes seconds on an explorer and is worth doing first.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Rent Detail Nobody Expects<\/h2>\n\n\n\n<p>When someone sends you a token you have never held, an associated token account has to be created, and whoever sends the transaction pays the roughly 0.002 SOL rent deposit for it. That deposit now sits attached to an account in your wallet \u2014 and when you close that account, the SOL comes to you, not back to the sender.<\/p>\n\n\n\n<p>So a wallet dusted a hundred times is holding around 0.2 SOL of reclaimable deposits that somebody else paid for. Closing those accounts is the correct response for both reasons: it removes the clutter and it recovers real SOL. The mechanics are the same as any other cleanup described in <a href=\"\/blog\/solana-rent-explained\/\">how rent works on Solana<\/a>, and most wallets provide a one-transaction sweep for zero-balance accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Handling It Correctly<\/h2>\n\n\n\n<p>Do not click the URL, do not search for the project, do not swap the token to &#8220;see what it is worth&#8221;. Check the mint on <a href=\"https:\/\/solscan.io\" rel=\"nofollow\">Solscan<\/a> if you are curious about where it came from, and check whether it has any pool at all on <a href=\"https:\/\/dexscreener.com\" rel=\"nofollow\">DEXScreener<\/a> \u2014 dust almost never does, which answers the question about value immediately. Then hide it in your wallet interface and close the account when you next do a cleanup sweep. Genuine airdrops from projects you actually used exist, but they announce themselves through channels you already follow rather than arriving unannounced with a domain in the name.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Real Distribution Looks Different<\/h2>\n\n\n\n<p>DOLAN Duck ($DOLAN) reached roughly 10,700 holders through a fair launch where people bought on the open market, which is the structural opposite of a dusted holder count \u2014 every one of those accounts was opened by someone deciding to buy, paying their own rent deposit to do it. That distinction is worth knowing as a reader of holder numbers generally: a token can manufacture thousands of &#8220;holders&#8221; by dusting them, and the tell is that those accounts hold identical tiny amounts and never traded. When you check a token&#8217;s distribution, look at whether balances vary and whether accounts have transaction history, not just at the headline count. The full routine for that sits in <a href=\"\/blog\/how-to-keep-solana-memecoins-safe-2026\/\">keeping a Solana position safe<\/a>.<\/p>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1754644001\"><strong class=\"schema-faq-question\">What is a dust attack?<\/strong> <p class=\"schema-faq-answer\">A dust attack is an unsolicited transfer of a tiny amount to many wallets, used either to trace how those wallets move funds or, more commonly on Solana, to deliver a phishing lure through the token&#8217;s name and image.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754644002\"><strong class=\"schema-faq-question\">Is it dangerous to receive an unknown token?<\/strong> <p class=\"schema-faq-answer\">No. Receiving a token is entirely passive and nothing executes in your wallet on arrival. The risk begins only if you visit the URL it advertises, swap it, or sign a transaction to claim something.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754644003\"><strong class=\"schema-faq-question\">Why do I get so many random tokens on Solana?<\/strong> <p class=\"schema-faq-answer\">Because Solana fees are a fraction of a cent, so reaching tens of thousands of wallets costs a few hundred dollars including rent deposits. Even a handful of victims makes that profitable.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754644004\"><strong class=\"schema-faq-question\">Should I sell dust tokens to get rid of them?<\/strong> <p class=\"schema-faq-answer\">Preferably not. Under Token-2022, a mint can carry a transfer hook that runs creator code whenever the token moves, so swapping an unknown token is no longer a neutral action.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754644005\"><strong class=\"schema-faq-question\">Who pays the rent for a dust token account?<\/strong> <p class=\"schema-faq-answer\">The sender pays the roughly 0.002 SOL deposit to open the account in your wallet. When you close that account, the deposit goes to you, so cleaning up dust actually recovers SOL.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754644006\"><strong class=\"schema-faq-question\">How do I get rid of dust tokens?<\/strong> <p class=\"schema-faq-answer\">Hide it in your wallet, then close the account during a cleanup sweep to reclaim the rent. Do not visit any URL in its name or image, and do not attempt to claim anything.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1754644007\"><strong class=\"schema-faq-question\">How do I tell dust from a real airdrop?<\/strong> <p class=\"schema-faq-answer\">Genuine airdrops come from projects you already used and are announced through channels you follow. Dust arrives unannounced, usually with a domain or claim instruction embedded in the token name.<\/p> <\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A dust attack is an unsolicited transfer of a tiny amount to a large number of wallets, sent either to track how those wallets move&#8230;<\/p>\n","protected":false},"author":2,"featured_media":331,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-223","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain"],"_links":{"self":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts\/223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/comments?post=223"}],"version-history":[{"count":1,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts\/223\/revisions"}],"predecessor-version":[{"id":401,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/posts\/223\/revisions\/401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/media\/331"}],"wp:attachment":[{"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/media?parent=223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/categories?post=223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dolanduck.io\/blog\/wp-json\/wp\/v2\/tags?post=223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}