Kraken Locks 12,000 Accounts After Dust Attack Tied to HTX Wallets
Kraken restricted approximately 12,000 customer accounts this week after its platform received unsolicited cryptocurrency transfers identified as a dust attack. Blockchain intelligence firm Arkham linked the sending wallets to HTX, the exchange formerly known as Huobi Global.
Kraken Locks 12,000 Accounts After Dust Attack Tied to HTX Wallets
Kraken restricted approximately 12,000 customer accounts this week after its platform received unsolicited cryptocurrency transfers that the exchange identified as a dust attack. Blockchain intelligence firm Arkham linked the sending wallets to HTX, the exchange formerly known as Huobi Global. HTX denied any involvement.
The transfers arrived between August 17 and 24, 2026. Kraken moved to restrict affected accounts as a precautionary measure, citing the hallmarks of a coordinated dust attack: small, uninvited token amounts sent to a large number of addresses with the intent to spread malware or embed phishing links.
Dust attacks work by sending trace amounts of cryptocurrency, sometimes fractions of a cent, to thousands of wallet addresses simultaneously. The dust itself is rarely the threat. The danger lies in what accompanies it: malicious smart contract interactions, phishing links in transaction memos, or attempts to de-anonymize wallets by tracking how the dust moves. For exchange customers, the risk is compounded because any follow-up phishing attempt can be tailored to look like legitimate platform communications.
Arkham's on-chain analysis pointing to HTX-linked wallets raises two possibilities. Either HTX was a direct participant, which the exchange flatly denies, or wallets associated with HTX were themselves compromised and used as a launchpad. HTX has faced persistent operational and regulatory headwinds since rebranding from Huobi in 2022, including reported liquidity concerns and staff departures, making the second scenario plausible without requiring coordination from the exchange itself. A compromised or dormant wallet connected to a major exchange is a credible attack vector, and attribution in on-chain forensics rarely settles cleanly into a single conclusion.
Kraken's decision to lock 12,000 accounts simultaneously is notable for its scale. The move protects users from potential follow-on phishing, but it also creates friction for a significant number of legitimate customers who received the dust passively and had no interaction with it. That tension sits at the center of exchange security responses: acting fast enough to contain a threat while avoiding collateral disruption to users who did nothing wrong. Kraken has not publicly disclosed how long the restrictions will remain in place or what the account restoration process looks like.
The incident fits a broader pattern of infrastructure-level attacks targeting exchange customers rather than exchange hot wallets directly. Attackers have increasingly shifted toward social engineering and phishing campaigns that use on-chain activity as the entry point, precisely because perimeter defenses at major exchanges have hardened. Sending dust to thousands of verified exchange addresses is, in effect, building a targeted mailing list of confirmed crypto holders.
For affected Kraken users, the immediate guidance is straightforward: do not interact with any unexpected tokens that appeared in your wallet between August 17 and 24, do not click links in transaction memos, and contact Kraken support directly through official channels rather than responding to any outreach that references the restriction. The dust itself carries no inherent risk if left untouched.
HTX has not provided detail on whether it is investigating how wallets linked to its infrastructure may have been used in the attack. That question matters. If the sending wallets were genuinely HTX-associated, the exchange has an obligation to its own users to determine whether those wallets were active, dormant, or externally controlled at the time of the transfers.






