Author

Topic: [Edu] Bitcoin Wallet Dusting Attack and UTXO Control. (Read 307 times)

legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
There are some crypto exchange which allow dust to be converted into other crypto token which can be used for trading,
Your post is very good and it can help newbies to understand more about dust coin, and how UTXOs accumulate to increase the transaction virtual size or transaction weight which will make bitcoin transaction fee to be higher. But this part that I quote is what you did not get right because while talking about dust attack, it is not about exchanges but about noncustodial wallet, but which you also talked about.
member
Activity: 238
Merit: 59
Bitcoin dust is a small value UTXO or  UTXOs that may be up to and equvialent of a few cents .Dusting attack has to do with receiving small quantity on not searched Bitcoin. The most important part is not  to spend any Bitcoin dust not intended ,including it in a payment . Not all Bitcoin dust is harmful, sometimes wallets accumulate dust  because of change gotten from creating  a transaction .

The major difference between small change in a Fiat world and UTXOs is that,  The more U TXOs are needed to make a payment, the bigger the file size of transaction and the higher the fees paid to the  miner who adds the transaction to the Bitcoin blockchain.

There are some crypto exchange which allow dust to be converted into other crypto token which can be used for trading, also some wallet provider which have coin control features. When you have dusting attack ,they can be neutralized by locating the dust, freezing and isolating the dust
staff
Activity: 1316
Merit: 1610
The Naija & BSFL Sherrif 📛
Nice guide.
I stumbled on it as an Italian user pointed me here.
I might suggest adding this resource to your guide:


Dust Attack, what it is, why it is dangerous and how to prevent falling to it

This is an old thread of mine, hope you find this useful.

Only seeing this thread now, that's quite an interesting read. I've added the guide to the OP.
legendary
Activity: 2268
Merit: 16328
Fully fledged Merit Cycler - Golden Feather 22-23
Nice guide.
I stumbled on it as an Italian user pointed me here.
I might suggest adding this resource to your guide:


Dust Attack, what it is, why it is dangerous and how to prevent falling to it

This is an old thread of mine, hope you find this useful.
staff
Activity: 1316
Merit: 1610
The Naija & BSFL Sherrif 📛
Wallet like Mycelium and bluewallet that doesn't have dusk coin control so only have option of either sending the coin  to a mixer, sending to some charity address. Is it also possible for these wallet to separate the coins from their main coin before transferring also?
Mycelium wallet does not have coin control, but Bluewallet has coin control. On Bluewallet -> click on send -> the three dots at the right upper corner -> coin control. You will see your UTXOs and you can decide to label, or freeze the ones that you want. You can also decide to select the UTXOs that you want to spend.

If a wallet does not have coin control, you will not be able to spend or freeze the dust UTXOs.

Side Note: wallets without coin control are easy to dust attack.
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
Wallet like Mycelium and bluewallet that doesn't have dusk coin control so only have option of either sending the coin  to a mixer, sending to some charity address. Is it also possible for these wallet to separate the coins from their main coin before transferring also?
Mycelium wallet does not have coin control, but Bluewallet has coin control. On Bluewallet -> click on send -> the three dots at the right upper corner -> coin control. You will see your UTXOs and you can decide to label, or freeze the ones that you want. You can also decide to select the UTXOs that you want to spend.

If a wallet does not have coin control, you will not be able to freeze the dust UTXOs, and also you will not be able to (use coin control to) spend the dust UTXO in a way it will not link with your UTXOs in transactions.
sr. member
Activity: 700
Merit: 470
Hope Jeremiah 17vs7
Wallet like Mycelium and bluewallet that doesn't have dusk control so only have option of either sending the coin  to a mixer, sending to some charity address. Is it also possible for these wallet to separate the coins from their main coin before transferring also?
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
Thanks  for this It's being a while I used it I think I should  try it out again,  also duckduckgo it's not to a normal browser but in a minimal intermediary stage less to onions and candle though . I get used to it as it protects from unwanted pop up site and audios unlike onions but I will try checking it again
Duckduckgo is a normal browser but better. I can not advice anyone to go for Duckduckgo desktops versions (Windows and iOS) because they are still in beta version. For the mobile version, it can be regarded as a privacy browser, but not up to the way Tor can make someone  anonymous. Duckduckgo has Duckduckgo search engine which Tor is also using but it can not mask you and connect you with different nodes and different locations before routing your connection to the website that you want to visit like Tor does.
sr. member
Activity: 476
Merit: 299
Learning never stops!

The onion link will not work on normal browsers (like Duckduckgo). Tor is faster than before, you can try it out. I have used Tor several times with many mixers and it is as fast as normal browsers these days.

Clearnet link can work on Tor, but using the onion link is more private.


Thanks  for this It's being a while I used it I think I should  try it out again,  also duckduckgo it's not to a normal browser but in a minimal intermediary stage less to onions and candle though . I get used to it as it protects from unwanted pop up site and audios unlike onions but I will try checking it again
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
What about duckduckgo I don't really like Tor because of its slow Internet speed
The onion link will not work on normal browsers (like Duckduckgo). Tor is faster than before, you can try it out. I have used Tor several times with many mixers and it is as fast as normal browsers these days.

Clearnet link can work on Tor, but using the onion link is more private.
sr. member
Activity: 476
Merit: 299
Learning never stops!

Most mixers do not store logs, but if you value your privacy and IP address, use Tor when mixing instead of cleannet.


What about duckduckgo I don't really like Tor because of its slow Internet speed
staff
Activity: 1316
Merit: 1610
The Naija & BSFL Sherrif 📛
I want to ask something about this mixers I did some research though and I found that it provides  anonymity while doing transactions  but can can it compromise someone using it continuously
If you think that your anonymity can be compromised on a centralized mixer, you can use Whirlpool on Sparrow or Samourai wallet, they are decentralized mixers that make use of coinjoin to mix the coins. But in history, centralized mixers have not leaked their users data before, they even include it on their website that they do not keep logs. I can recommend mixers like Mixero and Sinbad, they are worth using. But if you still have doubt, you can use Whilepool.

It's also worth noting that Whirlpool only charges a one-time life fees from a certain input address, and it becomes exceedingly slow after the first mixing because you're mixing on another input address fees, and the speed also relies on the pool size. However, the mix following the first is always slow and free.

Most mixers do not store logs, but if you value your privacy and IP address, use Tor when mixing instead of cleannet.
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
I want to ask something about this mixers I did some research though and I found that it provides  anonymity while doing transactions  but can can it compromise someone using it continuously
If you think that your anonymity can be compromised on a centralized mixer, you can use Whirlpool on Sparrow or Samourai wallet, they are decentralized mixers that make use of coinjoin to mix the coins. But in history, centralized mixers have not leaked their users data before, they even include it on their website that they do not keep logs. I can recommend mixers like Mixero and Sinbad, they are worth using. But if you still have doubt, you can use Whilepool.
staff
Activity: 1316
Merit: 1610
The Naija & BSFL Sherrif 📛
Spending that UTXO is all they need to keep you under surveillance and gain access to your input wallet, and it's all a dust attacker needs to trace it back to your real-life identity and rob you. The rule is to never spend a Dust attack UTXO, and coin control is the only effective way to do it.
Some people prefer to send it along to a mixer. Some people prefer to send it to charity. Some people prefer to freeze it. Some people prefer to first freeze it but later mix it or send it to charity, if you send the coin to charity, your identity is not leaked. But if you decide not to spend it, that is not bad either. But the option that I will prefer is to use coin control to move all my coins out of the wallet leaving the dust coins and delete the affected wallet, or to send the dust coin out of the wallet completely.

Using coin control saves you mixing fees and also save those who do not like the idea of using third party to mix coins or using mixers. Sending your personal UTXOs to another wallet while freezing the dust UTXOs is another good strategy to cleanup the wallet too just as you said.

I want to ask something about this mixers I did some research though and I found that it provides  anonymity while doing transactions  but can can it compromise someone using it continuously

Nope except you get scammed by the mixer! We've seen how several mixers took away their customers funds. Whirlwind is one of those. Always DYOR before using any service.
sr. member
Activity: 476
Merit: 299
Learning never stops!
Spending that UTXO is all they need to keep you under surveillance and gain access to your input wallet, and it's all a dust attacker needs to trace it back to your real-life identity and rob you. The rule is to never spend a Dust attack UTXO, and coin control is the only effective way to do it.
Some people prefer to send it along to a mixer. Some people prefer to send it to charity. Some people prefer to freeze it. Some people prefer to first freeze it but later mix it or send it to charity, if you send the coin to charity, your identity is not leaked. But if you decide not to spend it, that is not bad either. But the option that I will prefer is to use coin control to move all my coins out of the wallet leaving the dust coins and delete the affected wallet, or to send the dust coin out of the wallet completely.
I want to ask something about this mixers I did some research though and I found that it provides  anonymity while doing transactions  but can can it compromise someone using it continuously
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
Spending that UTXO is all they need to keep you under surveillance and gain access to your input wallet, and it's all a dust attacker needs to trace it back to your real-life identity and rob you. The rule is to never spend a Dust attack UTXO, and coin control is the only effective way to do it.
Some people prefer to send it along to a mixer. Some people prefer to send it to charity. Some people prefer to freeze it. Some people prefer to first freeze it but later mix it or send it to charity, if you send the coin to charity, your identity is not leaked. But if you decide not to spend it, that is not bad either. But the option that I will prefer is to use coin control to move all my coins out of the wallet leaving the dust coins and delete the affected wallet, or to send the dust coin out of the wallet completely.
staff
Activity: 1316
Merit: 1610
The Naija & BSFL Sherrif 📛
First of all, this may be unrelated to this thread but it is worth mentioning. On this forum, Wasabi coinjoin is not recommended, although it is cheaper but the recommended coinjoin are Whirlpool on Sparrow wallet or Samourai, and Jointmarket if you run your own node. Wasabi has been a good wallet until their developers started working together with Chainanalysis. There are many other wallets that has coin control, and one of the most reputed one is Electrum. On mobile, Bluewallet supports coin control.

The Whirlpool is far better because you just pay a one-time cost to mix or coinjoin your coins, but having an unchanged mix returned to your wallet is quite unsafe if you do not know how to manage it. If you mix the unchanged coins or send it out with the conjoined coins, it will corrupt all of your coinjoined UTXOs.

Wassabi only implemented dust control after their customers was targeted a few years ago; I'm not sure about their relationship with Chainaanalysis.

Ps: I do not have Electrum desktop wallet but I will add it to the list.

2. Click UTXO => right click on the suspected dusting attack UTXO => Freeze UTXO
This is one of the ways to unlink your coins from dust attack coins. But the better way is to send them out of the wallet entirely if possible, like send it to a charity address. Or to send  your coins out of the wallet entirely while not sending the dust coins along. Or to send all the coins to a mixer to get a clean coin. I prefer it these way.

Or you can convert the coin to monero and convert it back to bitcoin on a decentralized exchange, or make use of /mix]mixero advanced if you do not want to use a decentralized exchange for the monero mixing method.

Spending that UTXO is all they need to keep you under surveillance and gain access to your input wallet, and it's all a dust attacker needs to trace it back to your real-life identity and rob you. The rule is to never spend a Dust attack UTXO, and coin control is the only effective way to do it.
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
First of all, this may be unrelated to this thread but it is worth mentioning. On this forum, Wasabi coinjoin is not recommended, although it is cheaper but the recommended coinjoin are Whirlpool on Sparrow wallet or Samourai, and Jointmarket if you run your own node. Wasabi has been a good wallet until their developers started working together with Chainanalysis. There are many other wallets that has coin control, and one of the most reputed one is Electrum. On mobile, Bluewallet supports coin control.

2. Click UTXO => right click on the suspected dusting attack UTXO => Freeze UTXO
This is one of the ways to unlink your coins from dust attack coins. But the better way is to send them out of the wallet entirely if possible, like send it to a charity address. Or to send  your coins out of the wallet entirely while not sending the dust coins along. Or to send all the coins to a mixer to get a clean coin. I prefer it these way.

Or you can convert the coin to monero and convert it back to bitcoin on a decentralized exchange, or make use of /mix]mixero advanced if you do not want to use a decentralized exchange for the monero mixing method.
staff
Activity: 1316
Merit: 1610
The Naija & BSFL Sherrif 📛
What is Dusting attack?

This is a common scenario in which an attacker sends a small amount of Sats to random Bitcoin wallets, which could be as little as 10 cents, 15 cents, or 20 cents worth of bitcoin. And by doing so, the attacker may now follow how you spend your Bitcoin, allowing them to figure out who you are, your identity, and how much Bitcoin you own. And this is dangerous because he hacker can now attack you and try to steal your Bitcoin if they know who you are and how much you have.

We are only familiar with phishing attacks, in which you may be sent a phishing email. This is when you send an email that appears to be from a legitimate organization. You click on the link, enter all of your information, and now you have given it all up, and there is computer ransom where someone takes over your computer, freezes it, and possibly steals a critical document on your computer, and the only way to unfreeze the computer is for you to pay ransom. Bitcoin dusting attacks are the most dangerous of all, especially for those who use most Bitcoin wallets without coin control/UTXO management, since you're forced to spend whatever UTXO you have in your wallet, including the UTXO that the attacker sent to your wallets, and as a Bitcoiner, your privacy is important, and you don't want people knowing your identity online, let alone how much money you have, and sometimes this dusting attack is sent by the government authorities.

Coin control/ UTXO management.


Coin control is critical for privacy since it allows users to choose between a compromised output (UTXO) and a private (UTXO) when spending Bitcoin.  To protect your anonymity, avoid using Bitcoin wallets without currency control, as this exposes you to Dusting attacks.

Methods for identifying dusting attacks and freezing compromised UTXOs from your private currency.


Dust attack control in Sparrow wallet.


1. A suspected dusted attacking UTXO is automatically identified in updated desktop wallets such as Sparrow and Wasabi wallets; these wallets are programmed to display a caution sign on an output (UTXO) less than 1000 Sats.  Most dusting attacks are motivated by greed, and most Nigerians fall victim to this type of attack because we believe so strongly in miracle money. If you find an unexpectedly small amount of output (UTXO) in your wallet, do not spend it; it is most likely an output (UTXO) attack.




2. Click UTXO => right click on the suspected dusting attack UTXO => Freeze UTXO



3. Now you can spend your private UTXOs without spending the suspected dusting attack UTXO.




Dust attack control in Waasbi wallet.


Goto settings => click Bitcoin => Dust Threasom ( You can adjust the amount of Bitcoin you do not wish to receive in your wallet since dust attack are always a low amount of Sats. Simple!



But these dusting attacks also can be used for good. They can be used to track stolen Bitcoin and also track the spending of hackers.



Other Topics

Dust Attack, what it is, why it is dangerous and how to prevent falling to it

[Edu] Bitcoin Wallet UTXO and Consolidation

[Rules] Unofficial General Guidelines For Posting( Na de koko dem)

[Info]Duplicates topics; How do we stop it?

[Support] Igebotz Nigerian Local Board Merit Source Application


Download sparrow desktop wallet https://sparrowwallet.com/download/
Download wasabi desktop wallet https://wasabiwallet.io/#download
Jump to: