Published · 5d agoInvest3 min read
Unsolicited HTX dust makes taint an operations problem, not a blocklist problem
Users report unsolicited USDT arriving from HTX-tagged addresses, and any wallet touched since May 26 may fail exchange screening. That calls for a remediation path, not just a list.
Context for builders, not their beat.See today for builders

What happened
- Multiple users reported receiving USDT from wallets linked to the HTX exchange, formerly Huobi.
- HTX has been sanctioned as a counterparty in the UK and the European Union.
- All wallets interacting with or withdrawing from HTX since May 26 are considered in breach of the sanctions.
- A token contract for a new HTX asset has interacted with thousands of wallets on BNB Smart Chain, while other users report receiving USDT from an address tagged as HTX48.
- The recent transactions are often larger than the usual dust attack, often handing over up to 12 USDT, and the attack is not using any new or counterfeit tokens.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Multiple users report receiving USDT from wallets linked to HTX, the exchange formerly known as Huobi, which has been sanctioned as a counterparty in the UK and the European Union [1][2]. Because all wallets interacting with HTX since May 26 are treated as in breach of those sanctions, a transfer you did not ask for and cannot refuse can be the event that fails your screening [3].
The mechanics are unglamorous and effective. A token contract for a new HTX asset has interacted with thousands of wallets on BNB Smart Chain, while other users report USDT arriving from an address tagged HTX48 [4]. The amounts run up to 12 USDT, larger than classic dust, and the campaign uses no new or counterfeit tokens [5]. That combination defeats the usual heuristics: there is no fake ticker to ignore and no zero-value transfer to dismiss. Ordinarily a dust attack tries to trick a user into sending funds to the wrong address; this one has been described as compliance poisoning, aimed at the screening layer rather than the user [6].
Consequences are already showing up. Some KOLs and insiders report that the dust has led to centralized accounts being frozen for review [7]. Hyperliquid and some DeFi protocols are blacklisting affected wallets, so the exposure is not limited to venues with a compliance department [8]. Binance previously froze transactions from HTX, Exmo and 14 other exchanges, which is 16 counterparties in total [9][1], and has not confirmed whether it will screen for inbound dust specifically [10]. An HTX ambassador said the exchange did not intentionally send out any assets and that this was not its usual mode of behavior [11]. Justin Sun, the TRON founder who owns HTX, has not responded to questions about the campaign and has been promoting a new AI model [12].
There is a precedent, and it is only partly reassuring. After the US sanctioned Tornado Cash, one user spent $50,000 contaminating addresses with dust [13]. Automated risk filtering did not result in bans for all affected wallets and accounts [14], and OFAC later ruled that non-material passive receipt of funds was not enough to make an account an accomplice to a banned service [15]. That ruling came from a US agency; the designations driving the HTX problem are UK and EU [2][15]. At $50,000, the earlier attacker could have funded roughly 4,166 transfers at the 12 USDT ceiling seen here [2], which tells you the cost of poisoning a large book of high-profile wallets is trivial relative to the review hours it consumes.
The practical opening is that screening practice is not uniform. Binance has been the strictest, freezing some accounts over suspicious transactions, while other brokerages flag the received transfer and sometimes let the user send it back to a self-custodial wallet without freezing the balance [16]. That is a remediation path, and it only works if a desk can show which transfer arrived unsolicited, when, and that it was never commingled with deposit flow. Segregated deposit addresses, no automatic sweeping, and dated provenance records are the difference between a flag and a freeze. Critics argue the measures against HTX are overreach that spends enforcement resources on legitimate users rather than on-chain crime [17], which may be right and will not unfreeze anyone's account.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Multiple users reported receiving USDT from wallets linked to the HTX exchange, formerly Huobi.
ReportedView cited source - [2]
HTX has been sanctioned as a counterparty in the UK and the European Union.
ReportedView cited source - [3]
All wallets interacting with or withdrawing from HTX since May 26 are considered in breach of the sanctions.
ReportedView cited source - [4]
A token contract for a new HTX asset has interacted with thousands of wallets on BNB Smart Chain, while other users report receiving USDT from an address tagged as HTX48.
ReportedView cited source - [5]
The recent transactions are often larger than the usual dust attack, often handing over up to 12 USDT, and the attack is not using any new or counterfeit tokens.
ReportedView cited source - [6]
Usually a dust attack has the goal of making users send funds to the wrong address; this time the attack has been tagged as compliance poisoning.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cryptopolitan.comHristina Vasileva5d agoHTX-linked transfers trigger fears of wallet screening and freezes


