Dusting Attack
A dusting attack is the sending of tiny amounts of cryptocurrency, called dust, to many wallet addresses in order to track, deanonymize, or bait their owners. The amounts are too small to matter financially; their value to the sender lies in what happens afterward.
In the original privacy-focused form, an analyst or attacker sends dust to thousands of Bitcoin addresses and then watches the blockchain. If a wallet later combines that dust with other coins in one transaction, the attacker learns that those addresses share an owner, gradually linking activity and sometimes connecting it to an exchange identity. In the now more common scam form, the dust is a token or NFT with an enticing or instructive name, for example one that mimics a claim voucher or contains a website URL; visiting that site leads to a phishing page or wallet drainer. Address poisoning transfers, which plant lookalike addresses in your history, are a related use of dust.
Receiving dust is harmless by itself, and this is the key misconception to correct: unsolicited tokens cannot steal from you, and interacting with them is what creates risk. The sensible response is to ignore dust entirely, never visit URLs embedded in token names, and avoid selling or swapping unknown tokens, since some are designed so that any interaction triggers a malicious contract. Privacy-conscious Bitcoin users can also mark dust as do-not-spend in wallets that support coin control.