Sanctioned Crypto Dusting Campaign Briefly Locks Kraken Users Out
Kraken and other cryptocurrency exchanges are required to screen deposits linked to sanctioned entities and restrict accounts when compliance systems detect exposure. That safeguard can also be weaponized through a “dusting attack,” in which tiny amounts of tainted cryptocurrency are sent to many unrelated wallets. Recipients may then face automated controls despite having no role in initiating or soliciting the transfers.
Between Aug. 17 and Aug. 24, Kraken detected about 12,000 suspicious small-value transactions associated with HTX-linked wallets, briefly locking some users out of their accounts. The activity appeared designed to distribute sanctioned funds widely and trigger the exchange’s risk controls against unwitting recipients. Kraken has not disclosed the aggregate value of the transfers or the total number of accounts affected.
All Coverage
2 original reportsThe Backstory
The history behind this eventKraken Wins Fed Access but Account Remains Offline
Kraken Financial, the Wyoming-chartered banking arm of crypto exchange Kraken, applied for a Federal Reserve master account in October 2020. Such an account can allow an institution to settle dollars directly through Fedwire instead of relying on a correspondent bank. The approval therefore marked a breakthrough for digital-asset firms, which have historically struggled to gain direct access to the infrastructure underpinning the US banking system.
The Federal Reserve Bank of Kansas City approved Kraken Financial’s one-year, Fedwire-only account on March 4, 2026. Yet Chief Executive Brian Mathena told Wyoming lawmakers on July 15 that it remained offline more than four months later as the bank worked through technical certification and compliance controls. Kraken still lists Dart Bank as its US dollar wire provider, leaving the landmark approval without measurable commercial returns so far.
Kraken Faces Extortion Threat, Says Client Funds Remain Safe
U.S. cryptocurrency exchange Kraken was targeted by a criminal group suspected of recruiting an employee to improperly access customer support data, then using the threat of releasing video of internal system operations to demand payment. The incident highlights the need for exchanges to manage employee access and social-engineering risks alongside external hacking threats. Kraken stressed that its core systems were not broadly compromised and client funds were never exposed.
Kraken said in its latest disclosure that the incident involved only limited support data from about 2,000 accounts and caused no loss of funds. It refused to negotiate with or pay the extortionists. The exchange did not disclose the ransom demand or the exact date of the unauthorized access. It has strengthened access controls, taken action against the insiders involved and is working with law enforcement to track down the criminal group.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →