As Much as 30% of a Blockchain's Transfers Are Spam. Here's What It Means for Sanctions Screening.
TRM User Conference
Which mission will you select?
Key takeaways
- Spam transfers operate at industrial scale across major blockchains. More than 2.7 billion suspected spam transfers crossed TRON, Ethereum, BSC, and Polygon between January and August 2026, reaching roughly 709 million wallet addresses. On Solana, a further 2.5 billion dust transfers landed in Q1 2026 alone.
- On TRON, 30% of all transfers between January and August 2026 were potential dust, and 60% of active wallets receiving funds were touched by dusting.
- The scale and type of spamming varies by blockchain economics and architecture. Low-fee chains enable high-volume dusting and zero-value transfers, while higher-fee chains favor more targeted counterfeit token spoofing. Solana's mint-authority validation makes counterfeit token spoofing impractical at scale.
- Spam creates a measurable operational burden for compliance teams. In 2026, 38% of all sanctions alert dismissals originated from dust. That number varied through the year, starting In January 2026 at 25% and falling to 10% by August 2026, with surges around sanctioning events like HTX.
- The average size of a sanctions alert dismissal due to dust is negligible (USD 0.0000588), with the median amount being USD 0.00 due to the zero-value transfer tokens, suggesting these dismissals are not removing economically significant activity.
- How much of that burden reaches any individual firm is an institutional choice. Firms have wide latitude over what their screening controls flag and at what thresholds, and the most mature compliance teams weigh sender, wallet characteristics, amount, and hop pattern in aggregate rather than acting on any single data point.
{{horizontal-line}}
Between January and August 2026, 30% of everything that moved on TRON was spam. Across five major blockchains, billions of transfers a year carry no value and serve no user's intent — they exist to plant an address in someone's transaction history. This report measures how much of that spam there is, what it costs the people sending it, and what it costs the compliance teams who have to separate it from genuine exposure.
What is blockchain noise?
A meaningful share of on-chain activity does not reflect real economic behavior. Instead, it consists of transactions that create records without representing genuine user intent or value transfer. Common sources of this activity include:
- Internal service transactions generated by platform operations rather than user activity
- Wallet consolidation transfers
- Dusting transfers that send negligible amounts to populate wallet transaction histories
- Zero-value transfers that create transaction records without moving funds
- Counterfeit token transfers involving tokens designed to resemble legitimate assets
- Spam and airdrop campaigns that distribute unsolicited tokens across large numbers of wallets
Among the forms of non-economic activity, this report focuses on spam transfers: unsolicited dust, zero-value transfers, and counterfeit token transfers. The intention of these transfers is not always visible on-chain. Some are deliberate address poisoning, an attack that manipulates wallet transaction history by planting attacker-controlled addresses resembling legitimate counterparties. Others are routine automated activity, such as exchanges activating their own deposit addresses. The analysis therefore identifies spam based on transaction characteristics rather than attempting to infer the sender's intent.
{{58-as-much-as-30-of-a-blockchains-transfers-are-spam-heres-what-it-means-for-sanctions-screening-callout-1}}
The scale of the problem
Across five major blockchains between January and August 2026, more than 2.7 billion suspected spam transfers crossed TRON, Ethereum, BSC, and Polygon, alongside a further 2.5 billion dust transfers on Solana in the first quarter alone. The intensity is most visible on TRON, where dust makes up 30% of total transfers, reflecting repeated and systematic pollution of transaction histories rather than one-off events.
TRON and Solana lead in dusting volume. On Solana, 2.5 billion dust transfers landed in Q1 2026 alone, accounting for 13% of activity and reaching 27 million addresses. Those figures cover Q1 2026 only, so they are not directly comparable to the eight-month totals for the other four chains.

Looking only at active addresses — those that received at least one transfer on the chain during the period — a large share encountered spam at least once: 60% on TRON through dusting, 44.5% on BSC through counterfeit tokens, and 20.8% on Ethereum through zero-value transfers. Spam is a structural feature of the transaction landscape on all four EVM and TRON networks measured.

BSC is dominated by counterfeit token spoofing. More than 460 million fake transfer events occurred between January and August 2026, with roughly 7,000 counterfeit-token contracts reaching more than 454 million addresses, or 44.5% of active receivers.
Ethereum sees lower spam volumes overall, but attackers there get more out of each contract than on any other chain measured. Just 390 counterfeit-token contracts reached 30.6 million addresses, roughly 18% of active Ethereum receivers, which is close to 79,000 addresses per contract against roughly 65,000 on BSC and 29,000 on Polygon.
Polygon sees a mix of all three attack types, with 24% of active receivers hit by counterfeit tokens at least once. Roughly 790 counterfeit-token contracts reached 22.7 million addresses.
The economics and architecture of blockchain spam
Spam is viable only where transfers cost little relative to the payoff, so it concentrates on low-fee chains. Which method attackers use follows the fee regime.
On TRON and Solana, dusting runs at volume for almost nothing. TRON's bandwidth and energy delegation model lets accounts transact without burning tokens, so all dusting on TRON across nearly eight months cost a combined USD 1,799. A thousand dust transfers on Solana costs under USD 1.
Ethereum inverts this. Dusting and zero-value transfers cost roughly USD 115 and USD 200 per thousand, so a few thousand transfers runs into the hundreds of dollars. Counterfeit tokens cost a fraction of a cent per transfer, since one deployment reaches many victims, and attackers shift accordingly. The economics still hold: one victim in a thousand misdirecting a stablecoin transfer repays a campaign many times over.
Ethereum is also getting cheaper. Dusting fell from roughly USD 200 per thousand in January 2026 to about USD 45 by August. Network gas was flat across that period, so this was a bidding change rather than a fee cut — spam senders paid 0.18 gwei by August against a 0.61 network average — with a falling ETH price accounting for much of the rest. Network gas sat below one gwei throughout, so "higher-fee" describes Ethereum relative to the other four chains, not in absolute terms.

BSC and Polygon sit between. Dusting on BSC costs about USD 28 per thousand, pushing attackers toward counterfeit tokens and zero-value transfers. Polygon is more even, at USD 7 to 8 per thousand for both, with counterfeit tokens under USD 0.25.
Architecture sets the ceiling. On EVM chains any contract can emit transfer events for any token, which is what lets counterfeit tokens work at scale. Solana's token program validates mint authority on every transfer, so an attacker cannot forge events for tokens they do not control, leaving dusting as effectively the only vector there.
What it costs compliance teams
For compliance teams running sanctions screening, spam creates a measurable problem by generating alerts from unsolicited inbound transfers rather than genuine user behavior.
So far in 2026, 36% of sanctions alert dismissals have been associated with spam. In January, approximately 25% of dismissals across organizations traced to spam activity after excluding one outlier organization with an unusually high volume of spam-related alerts. The impact can be much more pronounced at an individual organization. Including that outlier raises the January share to 80%.
How much of that burden reaches any individual compliance team depends on how its screening controls are designed. As Tom Armstrong, TRM's Head of Compliance Advisory, puts it, firms have wide latitude over what activity they flag and at what thresholds. More mature approaches consider sender and intermediary characteristics, transaction amounts, and hop patterns together rather than treating any single data point as determinative. An unsolicited inbound transfer of a fraction of a cent, from an address with no other history, is a different risk proposition from a funded transfer from a counterparty with sustained exposure, and screening logic can reflect that distinction. When screening controls account for those distinctions, the volume of dust-driven alerts reaching an analyst queue falls sharply.
By August 2026 the share of dismissed sanctions alerts traceable to dust had fallen from roughly 25% to 10%. Including the outlier mentioned above, the number declined from 80% to 33%. That decline reflects better screening configuration rather than less spam. Compliance teams are getting more efficient at filtering this noise before it reaches an analyst queue. Compliance teams are not dismissing economically significant activity. The average size of a sanctions alert dismissal due to dust is negligible (USD 0.0000588), with the median amount being USD 0.00 due to the zero-value transfer tokens.
Still, single events can disrupt the noise occurring on the blockchain. For example, in June 2026, immediately after the UK designated HTX, the share of dismissed sanctions alerts traceable to dust rose to 66%, up from 25% in January. A surge in dusting around a major designation feeds directly into alert volume, which means dust-specific screening rules matter most at exactly the moment screening queues are already under strain. It is also one reason exposure screening needs to extend beyond the designated addresses themselves.
What comes next
Spam is unlikely to disappear as long as transfers can be inserted into wallet histories at negligible cost. The practical goal is therefore to stop that activity from misleading users and generating unnecessary compliance alerts.
For compliance teams, that means distinguishing spam from genuine exposure using transaction value, address behavior, and other contextual signals. At the wallet layer, stronger safeguards can reduce the chance that spammed transaction histories turn into actual losses: validating paste targets, flagging addresses that appear only in dust transactions, and warning users about unfamiliar destinations.
Until those protections become standard, spam will remain a low-cost way to exploit the gap between what happens on-chain and how that activity is presented to users.
{{horizontal-line}}
Frequently asked questions (FAQs)
1. Can spam transfers steal funds from my wallet without my action?
No. Spam transfers do not compromise private keys or allow an attacker to move funds directly. The risk arises only when a user copies a lookalike address from their transaction history and manually sends funds to it.
2. How can I protect myself?
Verify the full destination address before sending funds rather than relying on the shortened address displayed by a wallet. Saved address books can also reduce the need to copy addresses from transaction histories.
3. What is TRM doing about blockchain spam?
TRM identifies spam activity across TRON, Ethereum, BSC, Polygon, and Solana and helps compliance teams distinguish it from genuine sanctions exposure. TRM Transaction Monitoring allows teams to combine multiple conditions when assessing exposure, which helps separate spam from transactions that warrant further investigation. TRM has also partnered with Sphinx to apply AI compliance agents to first-line alert triage, including resolving sanctions alerts caused by spam.
4. Why is blockchain spam difficult to stop?
The underlying transactions used in many spam campaigns, such as sending very small amounts of tokens to another wallet, are not inherently malicious. Combined with the extremely low cost of generating these transactions on some blockchains, that makes the activity difficult to prevent at the protocol level. The more practical defenses are identifying spam and preventing users from mistaking attacker-controlled addresses for legitimate counterparties.




















