As Much as 30% of a Blockchain's Transfers Are Spam. Here's What It Means for Sanctions Screening.

TRM Team

TRM User Conference

Which mission will you select?

REGISTER NOW
November 2-3, 2026
Washington, D.C.
As Much as 30% of a Blockchain's Transfers Are Spam. Here's What It Means for Sanctions Screening.

Key takeaways

  • Spam transfers operate at industrial scale across major blockchains. More than 2.7 billion suspected spam transfers crossed TRON, Ethereum, BSC, and Polygon between January and August 2026, reaching roughly 709 million wallet addresses. On Solana, a further 2.5 billion dust transfers landed in Q1 2026 alone.
  • On TRON, 30% of all transfers between January and August 2026 were potential dust, and 60% of active wallets receiving funds were touched by dusting.
  • The scale and type of spamming varies by blockchain economics and architecture. Low-fee chains enable high-volume dusting and zero-value transfers, while higher-fee chains favor more targeted counterfeit token spoofing. Solana's mint-authority validation makes counterfeit token spoofing impractical at scale.
  • Spam creates a measurable operational burden for compliance teams. In 2026, 38% of all sanctions alert dismissals originated from dust. That number varied through the year, starting In January 2026 at 25% and falling to 10% by August 2026, with surges around sanctioning events like HTX.
  • The average size of a sanctions alert dismissal due to dust is negligible (USD 0.0000588), with the median amount being USD 0.00 due to the zero-value transfer tokens, suggesting these dismissals are not removing economically significant activity.
  • How much of that burden reaches any individual firm is an institutional choice. Firms have wide latitude over what their screening controls flag and at what thresholds, and the most mature compliance teams weigh sender, wallet characteristics, amount, and hop pattern in aggregate rather than acting on any single data point.

{{horizontal-line}}

Between January and August 2026, 30% of everything that moved on TRON was spam. Across five major blockchains, billions of transfers a year carry no value and serve no user's intent — they exist to plant an address in someone's transaction history. This report measures how much of that spam there is, what it costs the people sending it, and what it costs the compliance teams who have to separate it from genuine exposure.

What is blockchain noise?

A meaningful share of on-chain activity does not reflect real economic behavior. Instead, it consists of transactions that create records without representing genuine user intent or value transfer. Common sources of this activity include:

  • Internal service transactions generated by platform operations rather than user activity
  • Wallet consolidation transfers
  • Dusting transfers that send negligible amounts to populate wallet transaction histories
  • Zero-value transfers that create transaction records without moving funds
  • Counterfeit token transfers involving tokens designed to resemble legitimate assets
  • Spam and airdrop campaigns that distribute unsolicited tokens across large numbers of wallets

Among the forms of non-economic activity, this report focuses on spam transfers: unsolicited dust, zero-value transfers, and counterfeit token transfers. The intention of these transfers is not always visible on-chain. Some are deliberate address poisoning, an attack that manipulates wallet transaction history by planting attacker-controlled addresses resembling legitimate counterparties. Others are routine automated activity, such as exchanges activating their own deposit addresses. The analysis therefore identifies spam based on transaction characteristics rather than attempting to infer the sender's intent.

{{58-as-much-as-30-of-a-blockchains-transfers-are-spam-heres-what-it-means-for-sanctions-screening-callout-1}}

The scale of the problem

Across five major blockchains between January and August 2026, more than 2.7 billion suspected spam transfers crossed TRON, Ethereum, BSC, and Polygon, alongside a further 2.5 billion dust transfers on Solana in the first quarter alone. The intensity is most visible on TRON, where dust makes up 30% of total transfers, reflecting repeated and systematic pollution of transaction histories rather than one-off events.

TRON and Solana lead in dusting volume. On Solana, 2.5 billion dust transfers landed in Q1 2026 alone, accounting for 13% of activity and reaching 27 million addresses. Those figures cover Q1 2026 only, so they are not directly comparable to the eight-month totals for the other four chains.

Looking only at active addresses — those that received at least one transfer on the chain during the period — a large share encountered spam at least once: 60% on TRON through dusting, 44.5% on BSC through counterfeit tokens, and 20.8% on Ethereum through zero-value transfers. Spam is a structural feature of the transaction landscape on all four EVM and TRON networks measured.

BSC is dominated by counterfeit token spoofing. More than 460 million fake transfer events occurred between January and August 2026, with roughly 7,000 counterfeit-token contracts reaching more than 454 million addresses, or 44.5% of active receivers.

Ethereum sees lower spam volumes overall, but attackers there get more out of each contract than on any other chain measured. Just 390 counterfeit-token contracts reached 30.6 million addresses, roughly 18% of active Ethereum receivers, which is close to 79,000 addresses per contract against roughly 65,000 on BSC and 29,000 on Polygon.

Polygon sees a mix of all three attack types, with 24% of active receivers hit by counterfeit tokens at least once. Roughly 790 counterfeit-token contracts reached 22.7 million addresses.

The economics and architecture of blockchain spam

Spam is viable only where transfers cost little relative to the payoff, so it concentrates on low-fee chains. Which method attackers use follows the fee regime.

On TRON and Solana, dusting runs at volume for almost nothing. TRON's bandwidth and energy delegation model lets accounts transact without burning tokens, so all dusting on TRON across nearly eight months cost a combined USD 1,799. A thousand dust transfers on Solana costs under USD 1.

Ethereum inverts this. Dusting and zero-value transfers cost roughly USD 115 and USD 200 per thousand, so a few thousand transfers runs into the hundreds of dollars. Counterfeit tokens cost a fraction of a cent per transfer, since one deployment reaches many victims, and attackers shift accordingly. The economics still hold: one victim in a thousand misdirecting a stablecoin transfer repays a campaign many times over.

Ethereum is also getting cheaper. Dusting fell from roughly USD 200 per thousand in January 2026 to about USD 45 by August. Network gas was flat across that period, so this was a bidding change rather than a fee cut — spam senders paid 0.18 gwei by August against a 0.61 network average — with a falling ETH price accounting for much of the rest. Network gas sat below one gwei throughout, so "higher-fee" describes Ethereum relative to the other four chains, not in absolute terms.

BSC and Polygon sit between. Dusting on BSC costs about USD 28 per thousand, pushing attackers toward counterfeit tokens and zero-value transfers. Polygon is more even, at USD 7 to 8 per thousand for both, with counterfeit tokens under USD 0.25.

Architecture sets the ceiling. On EVM chains any contract can emit transfer events for any token, which is what lets counterfeit tokens work at scale. Solana's token program validates mint authority on every transfer, so an attacker cannot forge events for tokens they do not control, leaving dusting as effectively the only vector there.

What it costs compliance teams

For compliance teams running sanctions screening, spam creates a measurable problem by generating alerts from unsolicited inbound transfers rather than genuine user behavior.

So far in 2026, 36% of sanctions alert dismissals have been associated with spam. In January, approximately 25% of dismissals across organizations traced to spam activity after excluding one outlier organization with an unusually high volume of spam-related alerts. The impact can be much more pronounced at an individual organization. Including that outlier raises the January share to 80%.

How much of that burden reaches any individual compliance team depends on how its screening controls are designed. As Tom Armstrong, TRM's Head of Compliance Advisory, puts it, firms have wide latitude over what activity they flag and at what thresholds. More mature approaches consider sender and intermediary characteristics, transaction amounts, and hop patterns together rather than treating any single data point as determinative. An unsolicited inbound transfer of a fraction of a cent, from an address with no other history, is a different risk proposition from a funded transfer from a counterparty with sustained exposure, and screening logic can reflect that distinction. When screening controls account for those distinctions, the volume of dust-driven alerts reaching an analyst queue falls sharply.

By August 2026 the share of dismissed sanctions alerts traceable to dust had fallen from roughly 25% to 10%. Including the outlier mentioned above, the number declined from 80% to 33%. That decline reflects better screening configuration rather than less spam. Compliance teams are getting more efficient at filtering this noise before it reaches an analyst queue. Compliance teams are not dismissing economically significant activity. The average size of a sanctions alert dismissal due to dust is negligible (USD 0.0000588), with the median amount being USD 0.00 due to the zero-value transfer tokens.

Still, single events can disrupt the noise occurring on the blockchain. For example, in June 2026, immediately after the UK designated HTX, the share of dismissed sanctions alerts traceable to dust rose to 66%, up from 25% in January. A surge in dusting around a major designation feeds directly into alert volume, which means dust-specific screening rules matter most at exactly the moment screening queues are already under strain. It is also one reason exposure screening needs to extend beyond the designated addresses themselves.

What comes next

Spam is unlikely to disappear as long as transfers can be inserted into wallet histories at negligible cost. The practical goal is therefore to stop that activity from misleading users and generating unnecessary compliance alerts.

For compliance teams, that means distinguishing spam from genuine exposure using transaction value, address behavior, and other contextual signals. At the wallet layer, stronger safeguards can reduce the chance that spammed transaction histories turn into actual losses: validating paste targets, flagging addresses that appear only in dust transactions, and warning users about unfamiliar destinations.

Until those protections become standard, spam will remain a low-cost way to exploit the gap between what happens on-chain and how that activity is presented to users.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. Can spam transfers steal funds from my wallet without my action?

No. Spam transfers do not compromise private keys or allow an attacker to move funds directly. The risk arises only when a user copies a lookalike address from their transaction history and manually sends funds to it.

2. How can I protect myself?

Verify the full destination address before sending funds rather than relying on the shortened address displayed by a wallet. Saved address books can also reduce the need to copy addresses from transaction histories.

3. What is TRM doing about blockchain spam?

TRM identifies spam activity across TRON, Ethereum, BSC, Polygon, and Solana and helps compliance teams distinguish it from genuine sanctions exposure. TRM Transaction Monitoring allows teams to combine multiple conditions when assessing exposure, which helps separate spam from transactions that warrant further investigation. TRM has also partnered with Sphinx to apply AI compliance agents to first-line alert triage, including resolving sanctions alerts caused by spam.

4. Why is blockchain spam difficult to stop?

The underlying transactions used in many spam campaigns, such as sending very small amounts of tokens to another wallet, are not inherently malicious. Combined with the extremely low cost of generating these transactions on some blockchains, that makes the activity difficult to prevent at the protocol level. The more practical defenses are identifying spam and preventing users from mistaking attacker-controlled addresses for legitimate counterparties.

This is some text inside of a div block.
Subscribe and stay up to date with our insights

How spam becomes an attack

Most wallet interfaces truncate blockchain addresses for readability. A 42-character Ethereum address like 0x71C7656EC7ab88b098defB751B7401B5f6d8976F displays as 0x71C7…976F, showing only the first six and last four characters. When a user verifies a paste, they typically check those visible characters only.

An attacker generates a vanity address whose first and last characters match a legitimate counterparty, using a GPU-based generator that finds a match in seconds to minutes. The remaining hidden characters can be anything. When the victim next copies a recent address from their wallet history, they copy the attacker's. The cost of the attack is asymmetric: cheap to execute, irreversible once the victim sends.

This copy-paste failure is the foundation of the attack. The attack then operates in three distinct modes, each with different cost structures and detection profiles:

Canonical token dusting. The attacker sends a small amount of a real token, often fractions of a cent in a stablecoin, to the victim. The transaction is legitimate — real tokens move — but its only purpose is to insert the attacker's address into the victim's history. This is the oldest and simplest variant.

Zero-value transfers. The attacker creates a transaction that transfers zero tokens while listing the victim's address as the sender, without the victim's knowledge or approval. No private keys are compromised. On certain blockchains, notably TRON, the rules governing token transfers allow anyone to submit a zero-amount transfer on behalf of any address. The result is a fabricated transaction record in the victim's wallet history that appears to show funds sent to the attacker's address, even though nothing moved. The victim sees this entry and may copy the attacker's address for a future transfer.

Counterfeit token spoofing. The attacker deploys a fake token contract that mimics a legitimate token's name and symbol, then generates transfer events that appear in block explorers and wallets as if the victim received or sent the real token. This is the most sophisticated variant because it exploits both token transfers and address histories, and it requires deploying a smart contract. That makes it more costly to execute than dusting or zero-value transfers.

All three share the same goal: planting an attacker-controlled address into a victim's transaction history where it can be mistaken for a trusted counterparty. Which method attackers use depends largely on the economics and architecture of the underlying blockchain.