12,000 Tiny Transfers Put Kraken's Compliance Controls to the Test

Wednesday, 26/08/2026 | 15:55 GMT by Tanya Chepkova
  • A few cents of crypto sent from HTX-linked wallets triggered compliance checks and forced Kraken to lock users' accounts.
  • HTX has denied involvement in the transfers; the actors behind the potential dust attack and their motives remain unknown.
Kraken (shutterstock)

A wallet linked to sanctioned exchange HTX flooded Kraken-linked addresses with thousands of near-worthless transfers, showing how a few cents of tainted crypto can force a regulated platform’s compliance systems into a full account lock.

A Wave of Tiny Transfers Locked Accounts

According to Arkham Intelligence, roughly 12,000 micro-transfers worth a few cents to a few dollars reached addresses linked to Kraken between 17 and 24 August.

Kraken’s automated screening flagged the incoming funds as tied to UK- and EU-sanctioned wallets and froze the affected customer accounts. The platform has since restored access for those customers, but the transferred funds themselves remain held.

The company's spokesperson said the attackers “likely expect that if sanctioned funds land in a client account, it triggers a full account lock.” The company added that it does not know who sent the transfers.

Kraken said its compliance team restored account access for affected customers while continuing to hold the sanctioned funds, and that it is working with authorities as the transfers continue.

A Blockchain Gap That Standard AML Models Weren’t Built for

Conventional sanctions screening assumes a link between an incoming transaction and the recipient’s own behaviour.

A permissionless blockchain breaks that assumption: anyone can send crypto to a public address without the recipient’s consent, and the transfer still appears in that customer’s history.

As a result, compliance teams quickly realise that detecting exposure is no longer enough. They have to distinguish the nature of that exposure - something transaction-monitoring tools weren’t built to make quickly at scale.

HTX has denied involvement in the dust transfers and has suggested some of the activity could have come from independent actors amid disputes over frozen funds.

The case still leaves several questions open. Kraken has said it does not know who initiated the transfers, and it has not disclosed how many customers were affected or the total value of the funds now being held.

The next issue for centralised platforms is whether unsolicited exposure to sanctioned wallets should be treated differently from customer-initiated activity.

A wallet linked to sanctioned exchange HTX flooded Kraken-linked addresses with thousands of near-worthless transfers, showing how a few cents of tainted crypto can force a regulated platform’s compliance systems into a full account lock.

A Wave of Tiny Transfers Locked Accounts

According to Arkham Intelligence, roughly 12,000 micro-transfers worth a few cents to a few dollars reached addresses linked to Kraken between 17 and 24 August.

Kraken’s automated screening flagged the incoming funds as tied to UK- and EU-sanctioned wallets and froze the affected customer accounts. The platform has since restored access for those customers, but the transferred funds themselves remain held.

The company's spokesperson said the attackers “likely expect that if sanctioned funds land in a client account, it triggers a full account lock.” The company added that it does not know who sent the transfers.

Kraken said its compliance team restored account access for affected customers while continuing to hold the sanctioned funds, and that it is working with authorities as the transfers continue.

A Blockchain Gap That Standard AML Models Weren’t Built for

Conventional sanctions screening assumes a link between an incoming transaction and the recipient’s own behaviour.

A permissionless blockchain breaks that assumption: anyone can send crypto to a public address without the recipient’s consent, and the transfer still appears in that customer’s history.

As a result, compliance teams quickly realise that detecting exposure is no longer enough. They have to distinguish the nature of that exposure - something transaction-monitoring tools weren’t built to make quickly at scale.

HTX has denied involvement in the dust transfers and has suggested some of the activity could have come from independent actors amid disputes over frozen funds.

The case still leaves several questions open. Kraken has said it does not know who initiated the transfers, and it has not disclosed how many customers were affected or the total value of the funds now being held.

The next issue for centralised platforms is whether unsolicited exposure to sanctioned wallets should be treated differently from customer-initiated activity.

About the Author: Tanya Chepkova
Tanya Chepkova
  • 404 Articles
  • 3 Followers
About the Author: Tanya Chepkova
Tanya Chepkova is a News Editor at Finance Magnates with more than 16 years of experience in financial journalism, covering forex, crypto, and digital asset markets. Her work spans daily industry reporting and data-driven, long-form explainers focused on market structure, trading models, and regulatory shifts. Before joining Finance Magnates, she led the editorial team of a cryptocurrency-focused media outlet for six years. Her reporting combines analytical depth with clear storytelling, with particular attention to how structural changes in trading, stablecoin infrastructure, and emerging products such as prediction markets reshape the broader financial ecosystem. She covers global developments and provides additional insight into CIS markets. Areas of Coverage: Crypto and digital asset markets Prediction markets Stablecoins and cross-border payments Industry analysis and long-form explainers
  • 404 Articles
  • 3 Followers

More from the Author

CryptoCurrency

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}