A user opens their Rabby Wallet portfolio dashboard and notices unfamiliar tokens appearing in their asset list. The addresses are not ones they recognize, and the token names suggest promises of rewards, airdrops, or exclusive opportunities. This is a dust attack: an adversary has sent small quantities of tokens to their wallet address without permission, hoping to exploit attention, curiosity, or automated contract interactions. The dust itself may be worthless, but the payload—a hidden contract designed to track activity, execute phishing redirects, or harvest wallet data—can be dangerous.
Dust attacks have become routine for holders on EVM-compatible blockchains, particularly those with transparent ledgers where wallet addresses are publicly observable. Arbitrum, Polygon, Avalanche, Fantom, and Ethereum itself are all common targets because their transaction histories and account balances are permanently recorded. A wallet that holds recognizable assets or participates in visible DeFi activity becomes a natural destination for unsolicited tokens. The attack relies on the assumption that users will interact with the token to inspect it, trade it, or check its contract—at which point the malicious code can activate.
Understanding dust attacks and their mechanics
A dust attack does not require the sender to have any relationship with the target wallet. Because blockchain addresses are pseudonymous and transaction histories are public, an attacker can identify active wallets by scanning the chain directly. Any address that has participated in a swap, staking interaction, or token transfer is visible and potentially vulnerable. The attacker then deploys a new token contract and distributes it in tiny amounts across thousands of addresses, including yours.
The token itself is often designed to appear legitimate at first glance. Its name might reference a recognized blockchain, claim to represent an upcoming airdrop, or suggest financial rewards. The contract code, however, contains a malicious function triggered when the holder attempts to sell, transfer, or even view the token’s details on a decentralized exchange interface. Some contracts are engineered to drain the entire wallet; others collect data about the holder’s other assets or execute a phishing redirect designed to trick the user into approving unauthorized token transfers.
The reason dust attacks work at scale is that they exploit behavioral patterns. A user sees a new token, assumes it might be a legitimate airdrop or promotional distribution, and clicks to investigate. That click—or the approval transaction that follows—is the attack’s true trigger. The attacker never needs the user to actually sell or move the token. Many dust attacks succeed simply by convincing the holder to execute a contract interaction that grants the attacker’s code permission to examine the wallet, execute a script, or monitor future activity.
EVM-compatible blockchains are particularly susceptible because they support complex smart contracts and token approvals are permanent by default. A holder who approves a dust token for trading might unknowingly grant the attacker’s contract the ability to access other tokens in the wallet, subject to the scope of permissions set in the approval. This is why Rabby Wallet and similar applications now include transaction preview and approval warnings designed to expose the actual permissions being requested.
How Rabby Wallet detects and flags spam tokens
Rabby Wallet includes automatic spam token detection as part of its core security design. When a new token appears in your wallet, the system checks it against known fraud databases, analyzes its contract code for common attack patterns, and compares its metadata against verified token registries. If the token fails these checks—or if it has no verifiable history—Rabby marks it as spam or suspicious by default. This happens without user intervention and protects holders from accidentally interacting with a malicious contract.
The detection logic also examines token creation date, contract age, liquidity, and trading volume. A token that was deployed today and has never traded is more likely to be a dust attack than a genuine airdrop. Similarly, tokens with zero or near-zero liquidity are often fake because they cannot be sold; their only function is to trigger an on-chain interaction. Rabby’s interface visually separates spam tokens from legitimate holdings, allowing users to see at a glance whether a new arrival is questionable.
The system is not infallible because new attack methods are invented constantly and blockchain analysis cannot always distinguish a poorly-designed legitimate token from a sophisticated scam. However, the automatic flagging significantly reduces the chance that a user will accidentally approve or transfer a malicious token without first understanding what they are interacting with. Users should still treat any suspicious token with caution even if Rabby does not explicitly flag it—unusual names, recent creation dates, and zero trading volume are all red flags worth investigating further.
Manual identification methods for tokens in your portfolio
If a token does not appear to be flagged automatically, or if you want to verify Rabby’s assessment yourself, several manual checks can help determine whether it is legitimate or spam. Start by examining the token contract address directly on a blockchain explorer such as Etherscan or similar tools for the relevant chain. Note the contract creation date: if it was deployed in the last few hours or days, it is almost certainly not a long-established project.
Next, check the contract’s transaction history. A legitimate token should show active transfers over time, participation in liquidity pools, and use by multiple wallets. A dust token typically appears in your wallet as its only significant transaction. Look for the contract’s source code verification: if the code is not visible on the blockchain explorer, the creator deliberately obscured it, which is a strong indicator of malicious intent. Legitimate projects publish their code so auditors and users can examine it.
Search the token’s name and contract address on security databases such as rugpull.io, etherscan’s verified contracts list, or community security forums. If other users have reported the token as a scam, those reports will appear. Check whether the token has a genuine website or official social media accounts; many dust attacks use names that closely mimic real projects without maintaining any actual presence. If a token promises rewards or airdrops, search the project’s official channels to confirm whether the distribution is real.
Finally, examine the token’s holder distribution. Use a tool like Etherscan’s holder list to see whether thousands of wallets hold tiny amounts (a signature pattern of dust attacks) or whether holdings are more naturally distributed. If every holder has exactly the same amount and received it on the same date, it is almost certainly spam. Legitimate tokens show varied holdings and acquisition patterns over time.
Hiding and removing spam tokens safely
Rabby Wallet provides built-in controls to hide spam tokens from your portfolio view without removing them from the blockchain. This is the safest approach for most users because it eliminates visual clutter while avoiding any interaction with the malicious contract. To hide a token, right-click on it in your assets list and select “Hide” or use the token management menu. The token will no longer appear in your portfolio, but it remains in your wallet at the blockchain level.
Hidden tokens can be unhidden at any time through the wallet’s settings or asset management interface, which is useful if you later want to verify something about the token or if a dust attack turns out to have been a legitimate but poorly-designed distribution. Hiding is therefore a reversible action that costs nothing and requires no blockchain transaction.
Removing spam tokens entirely from your wallet requires sending them to a null address or burning them if the token contract supports a burn function. This is more complex because it involves creating and signing a transaction, which costs network fees and leaves a permanent record on the blockchain. Most users should not attempt this unless they are confident in their understanding of the process, as mistakes can result in lost tokens or failed transactions that still consume fees.
If you do choose to remove a spam token, the safest method is to use Rabby Wallet’s built-in send function to transfer the token to the token contract’s own address or a community-designated burn address if one exists. Before executing, preview the transaction carefully to confirm the recipient address, amount, and fee. Never approve the spam token’s contract for trading or movement before sending it, as this grants the malicious code permission to interact with your wallet.
Protecting yourself against future dust attacks
The most effective defense is to minimize wallet visibility and avoid clicking on unsolicited tokens. Because blockchain addresses are public, attackers can identify active wallets through their transaction history. There is no way to completely hide an address that has participated in on-chain activity, but you can reduce the frequency of dust attacks by avoiding the behavior that triggers them: making public transactions from one address repeatedly over time makes that address a priority target.
When dust attacks do arrive, resist the urge to investigate immediately. Many users have been compromised precisely because they clicked on a dust token to see what it was or attempt to trade it away. The Rabby Wallet app provides transaction preview functionality that shows you exactly what contract functions are being called before you sign, so review that information carefully for any token you decide to interact with.
Keep your wallet software updated because Rabby regularly releases security patches and improves its spam detection algorithms. Attackers continuously develop new tricks, and older versions of the wallet may not recognize the latest attack patterns. Enable hardware wallet support if you plan to hold significant assets: connecting Ledger, Trezor, or similar hardware devices adds an extra signing step that makes it harder for malware or phishing attacks to execute unauthorized transactions even if they gain temporary access to your browser extension.
Never approve an unverified token for unlimited spending. When you interact with a token on a decentralized exchange, the system may request permission to transfer unlimited amounts in the future. Always set a spending limit to the exact amount you plan to trade, and revoke old approvals for tokens you no longer use. Rabby’s approval management tools make this straightforward—review your active token approvals regularly and remove access for any token you recognize as spam or no longer need.
When to seek help and verify token legitimacy
If you encounter a token that appears to be from a project you recognize but cannot verify as legitimate, your first step should be to check the project’s official website and social media accounts directly. Do not click links from the token itself or from search results; navigate to the official domain or social handle you have seen before. Legitimate projects will confirm whether a dust distribution or airdrop is real.
If a token claims to be an airdrop, check the official claim page or smart contract on the project’s verified website. Many airdrop scams send tokens to multiple wallets without any legitimate claim mechanism. If there is no way to claim or verify the airdrop through official channels, the token is spam regardless of its name. Community security groups and Discord channels associated with major projects often have pinned lists of known scams, which is another resource for verification.
When in doubt, the safest action is to hide the token through Rabby’s interface and move on. There is no obligation to investigate every unsolicited token that appears in your wallet. Users who hold significant assets or participate actively in DeFi should expect dust attacks to arrive regularly and should develop a routine practice of reviewing their token list weekly, hiding spam, and ignoring anything they cannot verify.
Broader security context for token wallet management
Dust attacks are one of many vectors that target holders of a secure crypto wallet. They are effective precisely because they exploit the transparency of blockchain technology: everyone can see which addresses hold which tokens, creating an environment where attackers can perform mass distribution at minimal cost. This is not a flaw unique to Rabby; it affects every token wallet on EVM-compatible chains because the underlying infrastructure is shared.
The best mitigation remains user awareness combined with strong device security. Ensure your computer or mobile device runs updated antivirus software, use strong passwords for your wallet and email accounts, and enable two-factor authentication wherever possible. If your device is compromised by malware, a dust attack becomes irrelevant because the attacker can access your private keys directly. Phishing remains the most effective attack method against cryptocurrency holders, and dust tokens are just one social engineering tactic among many.
For NFT wallet users, dust attacks can also involve unwanted NFTs. Rabby’s NFT management features include similar hiding and filtering capabilities, though NFT scams often target holders through compromised metadata or embedded malicious content rather than executable smart contracts. The principle remains the same: hide or ignore anything you do not recognize, verify legitimacy through official sources, and never approve contracts unless you fully understand what permissions you are granting.
The long-term trend in cryptocurrency security is toward better wallet interfaces that make the actual technical details more transparent. Transaction preview, permission warnings, and automatic spam detection are all steps in that direction. However, no interface can eliminate user choice entirely. Ultimately, protecting yourself from dust attacks requires developing a habit of skepticism: treat unsolicited tokens as suspicious by default, use your wallet’s built-in safety features, and remember that legitimate airdrops and distributions are always verifiable through official sources.
Frequently asked questions
What should I do if I accidentally approve a spam token for trading?
Immediately revoke the approval using Rabby Wallet’s token approval management tool or a specialized contract interaction platform. You can set the approval amount to zero, which removes the malicious contract’s permission to access your wallet. Do not send the token anywhere, and do not approve any follow-up transactions. If you believe the contract has already executed a malicious function, move significant assets to a new wallet address to prevent further damage.
Can hiding a token in Rabby Wallet remove it from the blockchain?
No. Hiding a token only removes it from your portfolio view within Rabby; the token remains in your wallet at the blockchain level. To permanently remove it, you must send it to a burn address or null address, which requires a blockchain transaction and network fees. Hiding is safe and reversible; burning is permanent and costly. For most dust tokens, hiding is sufficient.
How can I tell the difference between a legitimate airdrop and a dust attack?
Check the project’s official website, social media, and blockchain explorer to confirm the airdrop is real. Legitimate airdrops have a claim mechanism, official announcement, and defined criteria for eligibility. Dust tokens have no legitimate source, no claim process, and often a suspicious name or recent contract creation date. If you cannot find official confirmation, treat the token as spam and hide it in your wallet.