---
title: "Someone sent sanctioned money to Kraken customers, and their accounts locked"
description: "12,000 transfers went from a wallet belonging to HTX, sanctioned by the EU in July, to Kraken-linked addresses. Customers were briefly locked out. On a public ledger, anyone can send you money you did not ask for."
category: "Crypto"
category_url: https://boursel.com/category/crypto
author: "Hannah Blackwood"
published: 2026-08-25T19:38:01.000Z
updated: 2026-08-25T19:38:01.000Z
canonical: https://boursel.com/article/someone-sent-sanctioned-money-to-kraken-customers-and-their-accounts-locked
tags: ["kraken", "sanctions", "compliance", "htx", "crypto", "exchanges"]
---
# Someone sent sanctioned money to Kraken customers, and their accounts locked

12,000 transfers went from a wallet belonging to HTX, sanctioned by the EU in July, to Kraken-linked addresses. Customers were briefly locked out. On a public ledger, anyone can send you money you did not ask for.

Kraken says its customers were hit by a dust attack originating from a wallet belonging to HTX, the exchange formerly known as Huobi, which the European Union [sanctioned in July over alleged help to Russians circumventing sanctions](https://bitcoinmagazine.com/news/kraken-says-users-were-dust-attacked). Twelve thousand transfers went from the HTX wallet to Kraken-linked addresses. Customers were briefly locked out before access was restored.

A dust attack means sending very small amounts of cryptocurrency to a large number of addresses. The usual purpose is surveillance: watching where the dust moves next reveals which addresses are controlled by the same person.

This one appears to have had a different purpose.

## The attack is on the compliance system, not the wallet

Kraken's own reading is the important part: "We don't know who is behind these attacks, but they likely expect that if sanctioned funds land in a client account, it triggers a full account lock, causing operational disruption for a large number of users."

Read that carefully. Nobody is trying to steal anything. The attacker is using the exchange's legal obligations as the weapon, by pushing money from a sanctioned source into innocent accounts and letting the compliance rules do the damage.

The exchange has no good options. It must freeze sanctioned funds; that is not discretionary. If it locks the whole account it disrupts thousands of blameless customers, and if it does not, it risks handling sanctioned property. Kraken says its compliance team moved to restore access while continuing to hold the sanctioned funds as required, which is the correct threading of the needle and took time.

## Why this cannot happen at a bank

This is the part worth sitting with, and it is structural rather than a failure by anyone.

In the banking system, you cannot force money into a stranger's account. A payment requires the receiving institution to accept it, and a bank that spots a sanctioned originator returns or blocks the transfer before it reaches the customer. The customer is never in possession.

On a public blockchain there is no acceptance step. An address is a destination, and anyone who knows it can send to it without permission, notice or the recipient's involvement. The recipient then holds something they did not ask for, from a source they did not choose, and the compliance obligation attaches to the holding rather than to the intent.

Every property that makes a permissionless ledger useful, that anyone can transact with anyone without an intermediary's approval, is what makes this attack possible. It is not a bug in Kraken's systems.

## The timing

We reported this morning that OFAC has [issued sectoral determinations letting it sanction anyone operating in Iran's digital asset sector](/washington-can-now-sanction-anyone-in-iran-s-crypto-sector), and wrote then that the practical consequence lands on compliance departments rather than on Tehran.

Here is the consequence, arriving the same day from a different sanctions programme. The wider the designated universe becomes, the more addresses exist whose funds trigger an obligation, and the cheaper this attack gets. Someone willing to spend a few thousand dollars in dust can impose a much larger cost on an exchange and its users, and the cost scales with the number of sanctions regimes in force.

Kraken says it is working with authorities so the attacks do not have their intended effect. What that means in practice is unclear from the account available to us, and we are not going to guess at it.

## What a user can do

Very little, which is worth saying rather than pretending otherwise.

You cannot refuse an incoming transfer, you cannot un-receive dust, and the standard advice about not moving dusted funds addresses the surveillance version of this attack rather than this one. The exposure here is to your exchange's procedures, not to your own behaviour.

The question worth asking of any venue holding your assets is narrow: what happens to the rest of my balance when something arrives that the exchange must freeze. Kraken has now answered that in public, which is more than most have.
