Kraken temporarily restricted access to some customer accounts after nearly 12,000 small crypto transfers arrived from wallets identified by Arkham Intelligence as linked to HTX. The transfers occurred between August 17 and August 24 and were generally worth only a few cents or dollars. Kraken described the activity as a dust attack apparently designed to trigger sanctions controls by sending unwanted funds into customer deposit addresses.
The timing complicated the compliance response because HTX’s European sanctions status changed during the transfer window. The European Union regulation published on EUR-Lex lists HTX, identified as HUOBI GLOBAL SA, among third-country crypto service providers considered to significantly frustrate EU prohibitions, with the measure taking effect on August 23. Transfers therefore spanned periods both before and after the EU restriction became effective.
Tiny Transfers Created Major Compliance Problems
Kraken said some affected users were briefly locked out when its sanctions-screening systems detected the incoming funds. The exchange later restored customer access while continuing to hold the relevant sanctioned assets and working with authorities. The episode demonstrates that transaction value can be almost irrelevant when compliance systems are evaluating the provenance of blockchain funds.
Public blockchains make this problem difficult to prevent because wallet owners generally cannot stop another address from transferring tokens to them. An attacker can therefore create an on-chain association between an unrelated user and a flagged wallet without obtaining access to the victim’s account. In this case, the apparent objective was disruption rather than theft, using sanctions controls themselves as the attack surface.
Attribution remains contested. Arkham Intelligence labeled the sending wallets as associated with HTX, but HTX denied initiating the transfers. The exchange said its internal review found no official accounts responsible and that it was investigating possible wallet-attribution errors or malicious activity by a third party. The blockchain link is therefore observable, while responsibility for deliberately creating the transfers remains unproven.
Dust Attacks Test Sanctions Screening Models
The incident exposes a structural challenge for exchanges using blockchain analytics for sanctions compliance. Screening systems need to identify prohibited exposure quickly, but treating every unsolicited transfer as intentional interaction can create false positives and unnecessary account restrictions. The harder compliance question is not whether sanctioned funds should be detected, but how platforms distinguish voluntary dealings from contamination imposed by an outside sender.
That distinction becomes especially important for institutional users, where even a temporary restriction can interfere with withdrawals, collateral movements or treasury operations. A transfer worth pennies can create operational consequences far larger than its economic value if it triggers a full compliance review.
Kraken’s experience may increase pressure on exchanges to refine attribution models, escalation thresholds and procedures for handling unsolicited low-value deposits. The broader lesson is that transparent blockchain transaction histories can strengthen sanctions enforcement while simultaneously giving malicious actors a mechanism for manufacturing misleading associations.
Kraken has restored access to affected customers while isolating the disputed funds. The incident shows that sanctions compliance on public blockchains increasingly depends not only on tracing where assets came from, but also on determining whether the recipient ever intended to receive them.

