
Last Tuesday, a pseudonymous trader known as 0xZiye logged into his Coinbase account and found 7.5 USDT he never asked for sitting in his deposit address. The funds came from a wallet that blockchain explorers tag as belonging to HTX — the exchange formerly known as Huobi. Coinbase’s response, according to his post, was blunt: explain where the money came from, or the account gets closed.
By Wednesday, similar reports were spreading across Chinese crypto media: small, unsolicited USDT deposits tagged to HTX were landing in people’s accounts — often just 7 to 12 — and compliance teams were freezing or threatening to freeze the receiving accounts. The panic peaked at a terrible moment: on August 23, Binance’s restrictions on transfers touching HTX and ten other platforms officially took effect.
If you use USDT on TRON — and the network now hosts more than 399 million accounts — this story touches you more than you might think. Most of these microdeposits arrive as TRC-20 USDT, meaning they travel over exactly the rail you use every day. In this guide, I’ll walk through what actually happened, why a $7 deposit can lock an account, how dusting differs from address poisoning, and the practical steps I recommend every TRON USDT user take this week.
The reports started on August 18 and developed fast. Here is the timeline as it unfolded:
Two details matter. First, these were not near-zero dust amounts — several dollars is unusual for a classic dusting attack, which typically sends fractions of a cent. Second, no on-chain evidence has tied the transfers to HTX or to Justin Sun directly. Whether the deposits are a deliberate poisoning campaign, mislabeled addresses, or something else entirely, the damage to recipients happened before any of that was settled.
The reason a few dollars of USDT can trigger a freeze has nothing to do with the amount and everything to do with where the funds are labeled as coming from: compliance software at major exchanges now treats any HTX-linked coin as toxic — even money the user never requested. Here is the regulatory background that made this possible:
| Date | Event |
| March 2025 | Garantex, a sanctioned Russian exchange, is dismantled by law enforcement. |
| May 2025 | A7 LLC is sanctioned for supporting Russia’s war effort. |
| May 26, 2026 | The UK sanctions Huobi Global S.A. and HTX-linked names over suspected dealings with A7 and Garantex. |
| July 23, 2026 | The EU adopts Council Regulation 2026/1848 as part of its 21st Russia sanctions package, adding HTX to a list of crypto services facing a transaction ban. |
| August 2026 | Unsolicited HTX-tagged microtransfers are reported across exchanges. |
| August 23, 2026 | The EU transaction ban and Binance’s HTX-linked restrictions take effect. |
A critical nuance: the EU measure is a dealing ban, not an asset freeze. It prohibits persons and firms in the EU, the EEA, and Switzerland from transacting with the listed entities, and gives those users a limited three-month window to withdraw funds and close accounts. But because crypto is global, the screening logic ripples far beyond Europe.
Binance announced its restrictions on August 14, in three phases: August 7 (Shelbit, Aban Tether Exchange), August 13 (A7 Nigeria, A7 Africa, PilotFinance Ltd.), and August 23 (HTX/Huobi Global SA, EXMO Ltd., BitPapa, Exnode/Exnode Pay, Rapira, ABCeX, Aifory Pro, WhiteBird, NoOnecrypto, Tradex, and Monease). The exact count varies by source — Reuters counted 18 corporate entities, the Council lists 14 crypto services, and Binance’s notices cover 16 — because screening systems match registered legal entities, not consumer-facing brands.
The controversial part: Binance appears to be enforcing the EU list globally, not just for European users. Justin Sun has argued the restrictions affect only UK and EU users, but Binance’s public notice does not state that geographic limitation. As one analysis put it, anyone can send funds to a public address — yet the receiver carries the burden of proof. That asymmetry is the real story of this panic.
People have been calling this event “dusting,” but it’s worth being precise, because the differences decide what you should actually do.
Classic dusting sends tiny amounts — often fractions of a cent — to thousands of wallets at once. The goal is usually de-anonymization: when a recipient later sweeps that dust into a transaction alongside other funds, blockchain-analysis tools can cluster the addresses together and link them to a single owner. The amount is deliberately too small to spend on its own, which is why the standard advice is “don’t touch the dust.”
Address poisoning is the attack family behind most recent USDT losses. Attackers generate a “vanity” address matching the first and last few characters of an address you frequently transact with, then send a tiny transfer from it to your wallet. The fake address now sits in your transaction history — and the next time you copy a recipient from history instead of your address book, you copy the poison address and your funds go to the attacker. This has produced some of the largest single losses in crypto: one victim lost $50 million in USDT in December 2025 after copying a spoofed address just 26 minutes after sending a test transaction.
Compliance poisoning — the best description of what happened this week — is different from both. The amounts were larger (7–12), the apparent goal is contaminating addresses so any funds touching them become suspect, and the cost falls on the receiver’s account access rather than their balance. It resembles the “dusting” a revived Salomon Brothers entity ran last year, firing tiny amounts at 40,000 Bitcoin wallets while claiming 150 billion in supposedly abandoned Bitcoin.
| Attack | Amount sent | Goal | Who pays |
| Classic dusting | Fractions of a cent | De-anonymization via clustering | Privacy, long term |
| Address poisoning | Tiny, near-zero | Trick you into copying a lookalike address | Your balance, instantly |
| Compliance poisoning | Small but noticeable ($7–12) | Make receiving addresses look contaminated | Your account access, immediately |
The HTX panic is one week of news, but it sits on top of an attack wave that has become one of the most common threats in crypto. The scale:
What these numbers have in common: none of them involve hacking a blockchain. They exploit a feature working exactly as designed — public ledgers are pseudonymous, not private, and anyone can deposit into any address. Attackers simply abuse the fact that humans verify addresses with their eyes instead of their keys.
TRON is the most-targeted environment for this kind of attack for a simple reason: it carries more USDT than any other network. As of mid-August 2026, USDT on TRON stood at 91.2 billion — ahead of Ethereum — with more than 399 million total accounts, 15 billion cumulative transactions, and roughly 12.1 million daily transactions. Around 93% of TRON’s stablecoin transfers are direct peer-to-peer movements, and a majority are for less than 1,000.
That means a few things for you:
There is a practical upside: wallets are catching up. On August 22, imToken released version 2.19.0 with address-poisoning defenses — an address confirmation firewall that forces you to re-check addresses before copying, full-chain risk alerts, and a default-on feature that hides high-risk transactions — and it explicitly supports both Ethereum and TRON accounts.
Beyond imToken, the response has been broad:
The direction of travel is clear: security is moving out of “user vigilance” and into the send flow itself. But the final layer of defense is still your own behavior — and your own wallet structure.
If you take nothing else from this article, take these eight habits. They are cheap, take minutes to set up, and neutralize most of the attack surface described above.
If you are reading this because a few dollars of unrequested USDT just appeared in your wallet, here is the sequence I recommend:
An unsolicited deposit alone does not make you a suspect — it makes you a compliance data point. But the burden of proof is on you, which is why evidence and fast, proactive communication matter.
If you followed Point 8’s fifth step, you just did the one security action in this entire guide that actually costs money: a TRC-20 transfer to your new address. On TRON, that transfer consumes 65,000 tron energy (about 131,000 for a brand-new address). Pay by burning TRX and it costs about 6.5 TRX — roughly 2.15 at current prices; rent energy from the rental market instead and the same transfer runs 1.5–3 TRX — about 0.50 to $1.00, a saving of roughly 54–77% depending on the live rate.
Why does a security guide care? Because safety advice only gets followed when it’s cheap. After a contamination scare you may need two or three cleanup transfers — a new receiving address, a sweep to your spending wallet — and at $2.15 each, hesitation is real. At fifty cents, it isn’t. Don’t let a two-dollar fee talk you out of doing the right thing: rent the tron energy, make the transfer, and move on.
The HTX dusting panic is, at its core, a compliance event rather than a hack — nobody’s private key was stolen, and no protocol was broken. But it exposes the same uncomfortable truth that address poisoning has been teaching us all year: on a public blockchain, anyone can deposit into your address, and the burden of dealing with the consequences falls on you.
What I want you to take away from this week’s news:
The dusting wave will pass, but the pattern won’t. Address poisoning, contamination, and compliance-driven freezes are now permanent features of the crypto landscape. The defenses are permanent too — and most of them cost nothing but attention, and a little tron energy.
1. I received an unsolicited small USDT deposit. Should I send it back? No — not as an on-chain transfer to the sender. Returning funds to a flagged address can look like you are transacting with it and can trigger a second compliance review. Document it, leave it untouched, and contact your exchange’s support team if you want it resolved.
2. Is my account frozen forever? In most cases, no. These are risk-screening holds rather than permanent bans. The first publicized case in this wave was resolved within days — the trader’s Coinbase account was restored after review. Cooperate with the process and provide the transaction evidence.
3. Did HTX or Justin Sun actually send these deposits? There is no on-chain evidence tying the transfers to HTX or to Justin Sun directly. HTX denies initiating any such transfers and says it is tracing the funds; Justin Sun called the reports fabricated. Whether the deposits were a deliberate poisoning campaign or mislabeled addresses, the outcome for recipients was the same either way.
4. Do these events affect my normal USDT transfers on TRON? No. Ordinary transfers from your own wallet are not affected unless they touch one of the restricted platforms. What changes is only the risk profile of addresses linked to HTX or the other listed entities — and the general advice to keep clean, well-separated wallets.
5. What does “sanctioned wallet” mean, and how do I avoid touching one? A wallet is treated as sanctioned-linked if compliance screening matches it to a sanctioned entity — for example, any wallet that withdrew from HTX after May 26, 2026 is currently treated as sanctioned by many screening systems. You avoid the issue by not transacting with restricted platforms, verifying counterparties on P2P markets, and keeping receiving and spending addresses separate.
6. Does staying safe cost more in fees? A little — every transfer on TRON consumes tron energy. The one that matters most here, moving funds to a clean address, costs about 2.15 in burned TRX or 0.50–1.00 with rented energy. If you’d rather not manage the energy yourself, services that run their own pools — like Tronsell.io, which operates a self-operated pool of 400 million staked TRX — let you rent tron energy on demand and keep the math on your side.
Disclaimer: This article is for educational and informational purposes only and does not constitute financial, investment, or legal advice. Sanctions designations, exchange policies, and compliance screening practices are subject to change without notice, and the events described are based on public reports as of August 24, 2026. Crypto assets are volatile and carry risk. Always do your own research and consult a qualified professional before acting. Tronsell.io operates a self-operated TRON energy pool and does not guarantee any specific outcome regarding account freezes, compliance reviews, or sanctions enforcement.