Kraken temporarily restricted customer accounts after nearly 12,000 unsolicited cryptocurrency transfers reached addresses linked to the exchange between Aug. 17 and Aug. 24, according to a Bloomberg report published on Aug. 25.
Most of the transfers were extremely small, worth only a few cents or several dollars. Yet their limited value did not make them insignificant. Kraken described the activity as a dust attack apparently designed to distribute funds connected to sanctioned wallets across unrelated accounts, forcing exchanges to investigate customers who may never have requested or authorized the deposits.
Blockchain intelligence firm Arkham reportedly linked the sending wallet to HTX using addresses previously associated with the exchange through proof-of-reserves disclosures. HTX denied initiating the transfers and said it was investigating whether the attribution resulted from labeling errors, operational misunderstandings or malicious activity by a third party.
The episode raises a difficult compliance question for centralized crypto platforms: how should an exchange react when a customer receives funds from a sanctioned or high-risk address without having any ability to stop the transfer?
Kraken Restricted Accounts While Reviewing the Transfers
Kraken temporarily placed restrictions on affected customer accounts after the small transfers reached exchange-linked addresses.
The platform later restored access once its reviews were completed.
However, Kraken continued to hold the disputed funds separately because of their reported connection to sanctioned wallets.
That distinction is important. The exchange did not treat every affected customer as responsible for initiating the transaction, but it also could not simply release assets that might fall under sanctions restrictions.
Kraken did not disclose how many customer accounts were affected, how long each review lasted or the combined value of the retained funds.
Its public status page also did not show a platform-wide outage tied to the incident.
Crypto Users Cannot Prevent Someone From Sending Tokens to a Public Address
One reason the incident is difficult for compliance teams is the basic structure of blockchain transactions.
A public crypto address can receive funds without the recipient approving the transfer.
If an unknown sender knows an address, it can usually send assets to it directly.
That means a user can become exposed to funds associated with a sanctioned wallet even if the user never interacted with the sender and had no reason to expect the payment.
An exchange can screen the incoming transaction once it arrives, but the recipient typically cannot stop the transaction from being broadcast in the first place.
This creates a significant difference between receiving funds and intentionally participating in a prohibited transaction.
Kraken Characterized the Activity as a Dust Attack
Traditional dust attacks usually involve sending tiny amounts of cryptocurrency to numerous wallets in an attempt to identify or trace users.
The Kraken incident appears to have a different objective.
A spokesperson said recent dust attacks from wallets associated with HTX appeared designed to spread funds subject to U.K. and EU sanctions to other platforms.
Kraken also acknowledged that it could not determine who actually initiated the transfers.
Because the transfers may have been intended to contaminate unrelated accounts from a compliance perspective, the activity more closely resembles what can be described as compliance poisoning.
The sender does not need to steal funds or compromise an account. Simply sending tiny amounts from a high-risk wallet can force the recipient platform to trigger sanctions screening and potentially restrict customer access.
Compliance Poisoning Can Exploit Automated Controls
Centralized exchanges generally use blockchain analytics and automated screening systems to detect exposure to sanctioned or illicit addresses.
These systems are essential, but they can create a vulnerability when direct wallet exposure is treated without enough context.
If thousands of tiny deposits arrive from a sanctioned address, automated systems may flag each recipient even when the customers had no relationship with the sender.
That can create a large number of compliance reviews at once.
The challenge is therefore not simply identifying sanctioned funds. Exchanges also need to determine whether the recipient intentionally engaged with the source.
Transaction value, timing, wallet ownership and customer behavior all become relevant.
Arkham Linked the Wallet to HTX, but Attribution Is Not Proof of Control
Arkham Intelligence reportedly identified the sending wallet as being connected to HTX.
The attribution was based on addresses previously associated with HTX through the exchange’s proof-of-reserves disclosures.
That evidence can establish a connection between the wallet and the broader HTX ecosystem.
It does not establish who controlled the wallet at the exact moment when every transfer was sent.
It also does not prove that HTX management ordered or approved the transactions.
This distinction is central to the dispute.
HTX Denied Sending the Transfers
HTX said it “absolutely did not engage in such behaviour.”
The exchange said it was examining several possible explanations, including incorrect wallet labeling, operational misunderstandings and malicious activity by an outside party.
HTX also stated that an internal review found no official accounts or testing systems responsible for the transfers.
However, the denial does not resolve the ownership issue.
The exchange has not published a complete list of relevant wallets or a transaction-level analysis demonstrating who controlled the address.
As a result, the factual question of who initiated the transfers remains unresolved.
Similar Transfers Reportedly Reached Other Major Exchanges
The Kraken incident may not have been isolated.
Small transfers had reportedly reached addresses associated with Coinbase, Binance and other exchanges before the Kraken disclosure.
That pattern increases the possibility that the transactions were intended to affect multiple platforms rather than individual customers.
If so, the objective may have been to create broad compliance complications across centralized exchanges serving regulated jurisdictions.
No verified evidence in the report established the identity of the sender or confirmed a coordinated attack.
Sanctions Made the Transfers More Sensitive
The compliance implications became more serious because of sanctions involving Huobi Global S.A.
The United Kingdom designated Huobi Global S.A. on May 26 under its Russia sanctions regime.
The measures included an asset freeze and restrictions on processing payments involving the designated entity.
HTX disputed how broadly those sanctions applied, arguing that Huobi Global S.A. is legally separate from its operating exchange.
The European Union later added HTX, identified as Huobi Global S.A., to a transaction ban affecting crypto service providers.
That decision took effect on Aug. 23.
Timing Around the EU Restriction Increased Compliance Pressure
The reported transfers occurred between Aug. 17 and Aug. 24.
That means some arrived shortly before the EU restriction took effect and others may have arrived after it became active.
For exchanges serving customers in the U.K. or European Union, that timing could significantly change how the funds need to be handled.
Platforms must identify transactions that may fall under sanctions rules and prevent prohibited assets from being made available when required.
Even very small transfers can therefore carry substantial regulatory importance.
The value of the transaction is not necessarily the main issue. The identity and legal status of the source can matter much more.
HTX Had Already Faced Scrutiny Over Wallet Changes
Blockchain research firm TRM Labs had previously reported that HTX repeatedly changed wallets after the U.K. designation.
HTX described those changes as routine security practices rather than efforts to avoid sanctions.
Wallet rotation is not inherently suspicious.
Crypto exchanges routinely move funds for operational and security purposes.
However, when sanctions are involved, frequent wallet changes can make attribution and transaction screening more complicated.
That complexity becomes especially relevant when third-party analytics firms use historical address associations to label new transactions.
Exchanges Need to Separate Unwanted Receipt From Intentional Exposure
The central compliance lesson from the Kraken case is that blockchain exposure alone may not demonstrate user intent.
A customer who voluntarily sends funds to a sanctioned entity is in a very different position from a customer who receives a few cents without asking for them.
Yet both transactions can create a direct on-chain connection.
This means exchanges need controls that distinguish passive receipt from active participation.
A robust review may need to consider transaction value, frequency, prior behavior, counterparty history and whether the customer took any action after receiving the funds.
Treating every unsolicited deposit as proof of intentional sanctions evasion would create obvious opportunities for abuse.
Stablecoin Issuers Can Sometimes Intervene at the Token Level
Some centralized stablecoin issuers have tools that exchanges themselves do not possess.
They can freeze tokens at the smart-contract level when addresses are identified as prohibited or connected to enforcement actions.
Tether, for example, froze more than $500 million across 370 addresses during one 30-day period, according to the source material.
That ability can stop certain stablecoins from moving further.
But it does not solve the broader problem for all blockchain assets.
Many cryptocurrencies cannot be frozen by an issuer, and decentralized transfers can continue regardless of whether the recipient wants them.
The Incident Highlights a New Form of Operational Risk
Crypto compliance systems were largely designed to detect users attempting to move illicit or sanctioned funds.
The Kraken episode demonstrates the reverse problem.
A hostile or unknown sender may be able to deliberately create compliance exposure for unrelated customers.
That creates operational costs for exchanges.
Accounts may need manual review.
Funds may need to be segregated.
Legal teams may need to determine which jurisdictional restrictions apply.
Customer support must explain why access has been limited even though the user did not initiate the transaction.
When thousands of transfers occur at once, those costs can escalate quickly.
No Joint Investigation Has Been Announced
Kraken and HTX have not announced a joint investigation into the incident.
They also have not provided a deadline for publishing further findings.
The next significant development would likely require more detailed wallet-level evidence identifying the actual sender, additional disclosures from either exchange or action from U.K. or EU sanctions authorities.
Until then, the link to HTX remains based on blockchain attribution that HTX disputes.
Conclusion
Kraken’s response to nearly 12,000 unsolicited transfers illustrates a difficult compliance problem created by public blockchain infrastructure.
Customers can receive funds without consent, but exchanges still have legal obligations to review deposits connected to sanctioned addresses.
Kraken temporarily restricted affected accounts, later restoring customer access while separately retaining the disputed funds. Arkham linked the sending wallet to HTX, but HTX denied responsibility and said the attribution may be incorrect or connected to third-party activity.
Final Takeaway
The most important issue in the Kraken dust-transfer incident is not the monetary value of the deposits but the compliance exposure they created. Public blockchains allow anyone to send funds to an address, which means sanctions screening cannot rely on direct wallet contact alone. Exchanges increasingly need systems capable of distinguishing intentional prohibited activity from unsolicited transfers designed to trigger reviews or disrupt regulated platforms.





