ダスティング攻撃とは?仮想通貨ダストの仕組みと対策

この記事は次の言語でご利用いただけます:

Author logo
Patrick Dike-Ndulue
Post image

フィッシング詐欺などの古典的な手口はよく知られていますが、ダスティング攻撃はより目立ちにくい方法で行われます。この攻撃は「仮想通貨ダスト」と呼ばれるごく少額の暗号資産をウォレットアドレスに送信することで成立します。ダストは詐欺師がウォレットの動きを追跡し、不正利用を狙うきっかけとなる場合があります。

仮想通貨を扱う方は、ダスティング攻撃の仕組みやリスクを理解し、資産や個人情報を守ることが大切です。

仮想通貨ダストとは?

仮想通貨ダストとは、善意または悪意の目的で複数のウォレットアドレスにごく少額の暗号資産が送られる現象を指します。
In Bitcoin, for instance, the dust limit set by Bitcoin Core is approximately 546 satoshis (0.00000546 BTC), which some wallet nodes may reject due to its small size. In Tether(USDT), it's often 0.01USDT or even lesser.
 

Additionally, crypto dust can result from rounding errors or leftover amounts after a trade, which can't be traded but may be convertible to the exchange's native token.
 

While mostly harmless and sometimes used for promotional purposes, like alternative advertising, you should be aware of dust attacks and safeguard against them.
 

ダスティング攻撃とは?

A crypto dusting attack involves sending a small amount of cryptocurrency, referred to as dust, to your crypto wallet address. These transactions are often sent at similar intervals, in quick succession or timed to happen whenever you interact with your wallet.

 

The attacker address sending the dust token to you is often very similar to the real wallet address you often interact with. 


By tracking the movement of the dust, attackers can also identify which wallets belong to the same user. Then they send more dusts to these wallets and wait for the target to slip up by sending funds to the fake address.
 

ダスティング攻撃が危険な理由


Malicious actors can also take it further by use crypto dusting attacks to send phishing emails to affected users. They study the transaction patterns of targeted wallets and send phishing emails disguised as legitimate cryptocurrency exchanges or wallet providers.

 

These emails may request that users click a malicious link or connect their Web3 wallets to update or verify their account details. The user unknowingly surrenders their wallet and assets to the bad actor by clicking these links. Be cautious and thoroughly research requests for account information to avoid falling victim to attacks.

 

ダスティング攻撃の実行者は?


Anyone with access to cryptocurrency and the ability to send small amounts to multiple wallets can carry out a dusting attack. 
 

Not all the crypto dust transferred to a crypto wallet’s address is a scam. Dusting can be used for reasons other than hacking activities.

政府機関(税務当局や法執行機関など)が、マネーロンダリングや脱税、詐欺などの犯罪捜査のために仮想通貨ダストを利用することもあります。こうしたデータは、ユーザーの特定やウォレットの追跡、取引履歴の監視などに活用されます。
 

Blockchain analytics platforms may conduct dusting attacks for research purposes, collaborating with crypto projects subject to crypto exploits to crack down on criminal cases.

また、開発者がソフトウェアの耐久性やトランザクション速度、ネットワークの拡張性・セキュリティプロトコルをテストする目的でダストを使う場合もあります。これにより、脆弱性や改善点を発見できます。

 

ダスティング攻撃の仕組み


We've established that crypto dust involves sending small amounts of cryptocurrency to targeted wallet addresses to compromise their privacy. Typically, the amount sent to each wallet is less than the transaction fee required to send it, making it seem insignificant to the user. 

 

Crypto dusting attacks can be used to manipulate the transaction history of a cryptocurrency. Attackers can artificially increase transaction volume and create a false demand for a particular cryptocurrency by sending small amounts of it to multiple wallets.

 

ダスティング攻撃の防止策


パブリックアドレスでダストを受け取ること自体を完全に防ぐのは難しいですが、詐欺被害のリスクを減らすための対策は可能です。たとえば、ダスト専用のウォレットを作成し、受け取ったダストをそこに移す方法があります。これにより、攻撃者はオンチェーンの取引履歴を追跡しにくくなります。

 

Use a hierarchical deterministic wallet

このタイプのウォレットでは、取引ごとに新しいアドレスを生成できるため、詐欺師が取引履歴を追跡しにくくなります。

 

Avoid untrustworthy crypto airdrops
Some malicious actors take advantage of the popularity of meme coins by promoting fake crypto projects and urging users to submit their wallet addresses or interact with illicit smart contracts in exchange for rewards. Unfortunately, complying with these requests can leave you vulnerable to crypto dust, which can eventually be used to conduct large attacks.

 

送金前に宛先アドレスのすべての文字を必ず確認する

 

Do not copy addresses from the blockchain explorer

攻撃者はどうやってウォレットアドレスを知るのか? 

ブロックチェーン技術は匿名性(正確には疑似匿名性)を提供しており、ユーザーは個人名や個人情報ではなくアドレスで識別されます。また、ブロックチェーンの台帳は公開されているため、誰でも取引履歴を確認し、特定のアドレスの動きを追跡できます。

However, they have no information whatsoever about the identity of the address owners. 

 

ダスティング取引を受け取っても心配する必要は?
Dust transactions in your wallet cannot give anyone access to your funds. It's best to simply ignore it and try not to interact with the “dust” or its originating address. 

 

ダスティング攻撃の影響を受けやすいブロックチェーン

Cryptocurrency addresses vulnerable to dusting attacks are typically UTXO-based, common in blockchains like Bitcoin, Litecoin, and Dash. Each transaction generates a new address for the remaining change. UTXO ensures transaction integrity by tracking unspent outputs, which can be used in subsequent transactions.

 

Think of it as the change from a $10 bill after a $9.59 purchase; this change, or "crypto dust," can be used in future transactions. Attackers can trace these small amounts to identify victims by analyzing the transaction origins with advanced tools.

ダスティング攻撃の見分け方

One way to identify a dusting attack in a wallet is by spotting deposits of tiny amounts of cryptocurrency that cannot be withdrawn or spent. The dusting attack transaction will be visible in your wallet's transaction history or in the blockchain explorer.
 

主なダスティング攻撃の事例 


In October 2020, Binance was targeted by a dusting attack where small amounts of BNB (BNB) were sent to multiple wallets. The victims then received a confirmation of the transaction along with a malware link that, upon clicking, could hack their system.

 

In late 2018, Samourai Wallet alerted its users of a dusting attack and requested them to mark "Do Not Spend" on their UTXOs to mitigate the issue. 
They implemented a real-time dust-tracking alert and an easy-to-use feature to mark suspicious funds with a "Do Not Spend" note to assist users in safeguarding their transactions against future attacks.
 

よくある質問(FAQ)


1. ダスティング攻撃とは?

ダスティング攻撃とは、ごく少額の暗号資産(ダスト)を多数のアドレスに送りつけ、受け取り側のプライバシーを追跡・特定しようとする悪意ある行為です。

 

2. ダスティング攻撃で仮想通貨は盗まれる?
Dusting attacks cannot steal crypto directly. With information retrieved from a dusting attack, hackers use sophisticated tools to trick wallet holders into phishing sites and then steal their crypto assets. Dusting attacks are used to identify the individuals behind wallets and break their privacy, while phishing sites disguise scam tokens as airdrops of free cryptocurrency to steal wallets' funds and NFT assets. Browser-based wallets like MetaMask and Trust Wallet are particularly vulnerable to these attack

 

3. ダスティング攻撃を受けたかどうかの見分け方は?

もしウォレットに少額かつ身に覚えのない仮想通貨が入金されていた場合、特に手数料の関係で出金や利用が難しい場合は、ダスティング攻撃の可能性があります。また、個人情報の入力や無料配布を装った不審なメッセージやメールにも注意してください。

 

4. ダスティング攻撃のリスクは?

ダスト自体は直接的なリスクではありませんが、プライバシー侵害や詐欺のきっかけになる可能性があります。攻撃者がダスティングで得た情報を使い、フィッシングやなりすまし詐欺などを仕掛ける場合もあります。

 

5. ダスティング攻撃を受けたと感じたら?

もしダスティング攻撃の疑いがある場合、不審な取引やメッセージには決して触れず、ウォレット提供元に報告してください。

Author logo
著者 Patrick Dike-Ndulue

Senior editor covering crypto, onchain equities, and technology.

Author logo
レビュー担当者 Rukkayah Jigam

Writer & editor covering digital assets and product updates.