> ## Content Index
> Fetch the complete content index at: https://blog.amlbot.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Unknown Crypto Appeared in My Wallet: Dusting, Scam Tokens, and AML Risk
- URL: https://blog.amlbot.com/unknown-crypto-in-wallet/
- Published: 2026-09-04T11:27:48.000Z
- Updated: 2026-09-04T11:27:48.000Z
- Author: AMLBot Team
- Tags: AMLBot Academy

You open your wallet and something is there that was not there before. Maybe it is a token you never bought. Maybe a fraction of a dollar in a cryptocurrency you do not recognize. Maybe an NFT from a project you have never heard of. Maybe a small USDT transfer from an address that means nothing to you. Two instincts compete. The first: someone hacked my wallet. The second: free crypto — maybe I should claim it. Both are usually wrong.

Knowing a public wallet address is enough to send something to it. On most blockchains, the recipient does not approve an incoming transfer before it lands. Funds simply arrive. That means an unexpected asset could be harmless spam, a dusting attempt, an address-poisoning transaction, a scam-token bait, an unsolicited airdrop, a legitimate mistaken transfer, or a genuine payment from a sender the wallet owner simply does not recognize. Receiving something you did not ask for is not the same as giving someone access to your wallet. But what you do next — clicking, connecting, approving, swapping, returning, or "claiming" — can have real security and AML consequences. Before doing anything: **do not click, connect, sign, approve, swap, return, or "claim" until you understand what arrived.**

## First Identify What Actually Appeared in the Wallet

The response depends on what the asset actually is. A tiny amount of real Bitcoin, an unknown ERC-20 token with a suspicious name, and a micro-transaction from a familiar-looking address require different interpretations.

### A Tiny Amount of a Real Cryptocurrency

This might be a small amount of BTC, LTC, TRX, or another native asset, a few cents of USDT or USDC, or a negligible amount of another established token. Possible explanations include dusting, address poisoning, a testing transaction, a payment remainder, a mistaken transfer, or ordinary spam. Classic dusting is especially associated with UTXO-based networks like Bitcoin. An attacker sends tiny UTXOs to many addresses and monitors what happens later. If the dust is later spent together with other UTXOs in the same transaction, the resulting on-chain link can help correlate addresses that may belong to the same user. Dusting itself does not give the attacker control over private keys and is not necessarily a direct theft attempt — major wallet providers describe it primarily as a privacy and deanonymization technique rather than a wallet-compromise method. Not every tiny transfer is dusting. It may also be a routing artifact, a payment rounding remainder, or simply a mistake.

### An Unknown Token

This is especially common on programmable chains like Ethereum, TRON, and BNB Chain. The wallet may show an unknown ERC-20 or TRC-20 token, a fake version of a known asset, a token named after a popular brand, a token with a website URL in its name, a token displaying an apparently high fiat value, or a token that cannot actually be sold or swapped on any real market. An important distinction: a token appearing in a wallet does not mean the user bought it or interacted with its contract. Anyone able to distribute the token can send it to any address. The scam token is designed as bait — its purpose is to get the user to visit a website, connect the wallet, "verify" holdings, claim a reward, swap the token, or approve a contract. MetaMask explicitly recommends leaving unsolicited scam tokens alone rather than interacting with them.

### An Unknown NFT or Collectible

The same concept applies to NFTs. An unsolicited NFT may contain a project name, a fake prize claim, a URL, instructions to "claim" a reward, or a support contact address. The NFT itself is usually just spam. The dangerous step is following the embedded instructions — connecting the wallet, signing a message, or approving an operator in response to what the NFT says.

### A Tiny Transaction from a Familiar-Looking Address

This may be address poisoning rather than dusting. The pattern works like this: the user previously sent funds to a legitimate address. An attacker creates a new address with similar beginning and ending characters. The attacker sends a small or zero-value transaction to the user's wallet. The malicious lookalike address now appears in the wallet's transaction history. Later, the user copies an address from recent history instead of the original verified source — and sends funds to the attacker. The goal is not to do anything with the tiny amount received. The goal is to manipulate future address selection. 

💡

For a real investigation of how this technique led to a $50,000 loss, see our case study on [how address poisoning can redirect a real crypto payment](https://blog.amlbot.com/honey-trap-how-address-poisoning-scammed-50k-and-how-it-was-recovered/).

## Receiving Crypto and Interacting with It Are Two Different Events

This is the most important security distinction in the article.

**Receiving** means a third party sends something to a public address. Usually no action from the recipient is required. This alone does not reveal the seed phrase, private key, or wallet password. Ordinary receipt does not by itself create a token approval.

**Interacting** means the user then opens an unfamiliar website, connects the wallet, signs a message, approves a token spending limit, approves an NFT operator, executes a swap, calls an unknown contract, or imports a seed phrase into a suggested application. This is where the risk changes. A malicious approval can authorize a smart contract to spend the user's tokens later — even without any further action from the user.

The main danger is not that a token exists at the address. The danger is executing an unverified transaction, approval, signature, or website workflow in response to it. 

💡

For more on how malicious approvals work as an attack vector, see our article on [how malicious token approvals can drain a crypto wallet](https://blog.amlbot.com/how-to-avoid-crypto-scams-in-2026-warning-signs-and-prevention-checklist/).

A critical warning: never provide a private key, seed phrase, Secret Recovery Phrase, wallet backup, or keystore file to anyone — regardless of the reason given. No legitimate process for removing an unsolicited token requires these credentials. 

💡

For more on [why private keys and seed phrases must never be shared](https://blog.amlbot.com/understanding-the-basics-of-cryptocurrency-security-private-keys-public-keys-and-seed-phrases/), see our crypto wallet security guide.

## Why Would Someone Send Crypto to a Stranger?

The motives behind unsolicited transfers fall into four groups.

1. **Observation.** The sender wants to see whether the address remains active, correlate UTXOs, profile wallet activity, or potentially connect addresses. The typical mechanism is dusting.
2. **Manipulation.** The sender wants to influence what the user sees later — planting a lookalike address in transaction history, or placing a misleading token name in the wallet display. The typical mechanisms are address poisoning and fake-token distribution.
3. **Bait.** The sender wants the user to take an action — click a link, connect a wallet, approve a contract, pay a "fee," or reveal credentials. The typical mechanisms are scam tokens, fake airdrops, unknown NFTs with embedded instructions, and fake "claim" sites.
4. **No scam at all.** The sender made a mistake. Someone tested the address. A legitimate project distributed an airdrop. A payment came from a service wallet the user does not recognize. A business or friend used an unfamiliar sending address. An automated payment or refund arrived.

Unexpected does not mean malicious. The right first question is: what exactly happened on-chain? Not: how do I get rid of it?

## Does Unsolicited Crypto Affect My Wallet's AML Risk?

### The Blockchain Records the Transfer Regardless of Consent

If a wallet address receives a transaction, that transaction becomes part of the observable on-chain history. An analytics system can potentially see the sending address, the amount, the asset, the direct relationship, the sender's attribution, and the risk categories associated with the source. It cannot determine consent simply from the transfer itself. A user saying "I did not ask for this" can be relevant context — but it does not erase the blockchain record.

### Exposure Is Not the Same as Responsibility

Suppose a wallet receives a tiny unsolicited transfer from an address later associated with scam activity. A screening tool may detect the connection. That detection does not establish that the recipient knows the sender, participated in the scam, controlled the sending wallet, or requested the funds.

Interpretation should consider the amount, direction, source, frequency, asset, directness of the connection, the wallet's wider activity, whether the funds were later used or moved, and whether there are repeated transactions from the same source. 

💡

For more on [why a wallet risk score is a signal rather than a verdict](https://blog.amlbot.com/crypto-wallet-risk-score-explained-what-low-medium-and-high-risk-actually-mean/), see our risk-score explainer.

### Spam Tokens and Valuable Crypto Are Not the Same AML Question

An unknown spam token with no real liquidity or market value and a real BTC, ETH, or USDT transfer from an identifiable risky source create fundamentally different AML questions. For AML review, what matters is whether the asset is economically meaningful, whether it can actually be transferred, what amount was received, where it came from, whether the user later combined, moved, exchanged, or spent it, and whether it represents a material part of the wallet balance. Not every random spam-token airdrop should materially raise the overall AML risk assessment.

### Moving to a New Wallet Does Not Erase the Transaction History

Creating a new wallet and moving everything there does not reset blockchain provenance. Analytics systems can follow the transfer between addresses. Moving legitimate holdings to a new address may be appropriate for operational or security reasons in some situations, but it should not be treated as a way to erase previous exposure.

If a material unsolicited transfer has arrived and the user wants to understand the risk, the right step is to [check the sending wallet or incoming transaction for AML risk](https://amlbot.com/crypto-checker?ref=blog.amlbot.com) — evaluating the source based on on-chain data rather than judging it from the token name alone.

## What Should You Do with an Unknown Transfer?

**If it is an unknown token or NFT:** do not follow embedded URLs. Do not connect the wallet to a site advertised by the asset. Do not approve or sign transactions simply to remove or claim it. Hide the asset in the wallet UI if the wallet supports that function. Verify the contract and project independently if there is a legitimate reason to investigate further.

**If it is dust:** do not assume a tiny amount is free money. On UTXO networks, understand that spending behavior may reveal address relationships — use wallet coin-control functionality where available. On account-based networks, do not automatically apply Bitcoin-style UTXO dusting logic — determine whether the transfer looks more like spam, address poisoning, or an ordinary small transfer.

**If it looks like address poisoning:** do not copy destination addresses from recent transaction history. Verify the full destination address using the original trusted source. Check more than the first and last few characters. Use saved or verified address-book entries where appropriate.

**If someone contacts you asking for the crypto back:** do not immediately send funds to a new address supplied in a chat, email, or token metadata. First verify the original transaction, sending address, asset, amount, claimed sender, and why the requested return address differs. For a significant or disputed amount, preserve the TxID and communications and consider getting relevant platform or legal guidance before moving the funds.

**If the transfer has meaningful AML exposure:** preserve the TxID. Save the screening result. Avoid unnecessary consolidation before understanding the source. Document why the transfer was unsolicited if that is relevant. If an exchange or compliance team later asks about it, provide transaction-specific context rather than claiming the transaction never existed.

## When an Unknown Asset Becomes a Real Security Incident

Receiving an unfamiliar asset is different from discovering unauthorized outbound transactions, assets transferred without intent, unexpected token approvals, unknown operator approvals, changed wallet permissions, a seed phrase entered on a suspicious site, a transaction signed after interacting with an unknown token, multiple assets leaving the wallet, or an attacker funding gas and then removing tokens.

If the user only received something — do not immediately frame the wallet as stolen.

If the user interacted and unauthorized funds started moving — stop treating the situation as spam-token cleanup and treat it as a possible wallet compromise. Immediate priorities include stopping interaction with the suspicious site or contract, preserving transaction hashes and screenshots, reviewing approvals where appropriate, securing remaining assets using a wallet or device the user trusts if compromise is reasonably suspected, documenting what was signed and when, and tracing the unauthorized outbound transfer if funds have already moved.

💡

For guidance on what information to collect after unauthorized fund movement, see our article on [what information to collect if crypto has been stolen](https://blog.amlbot.com/my-crypto-was-stolen-what-information-to-collect/). If funds have actually left the wallet without authorization and the user needs to follow where they went, AMLBot's [automated tool for tracing stolen crypto transactions](https://amlbot.com/ai-tracer?ref=blog.amlbot.com) can map the visible money trail across wallets, bridges, and supported blockchains. Tracing is not needed merely because a spam token arrived — it becomes relevant when real funds have moved without permission.

## Conclusion

Unknown crypto appeared in my wallet. What does that mean? Not enough information yet. First identify whether it is a real asset, dust, a spam token, an unsolicited NFT, an address-poisoning transaction, or a mistaken or legitimate transfer. Then separate two questions. **Security:** Did I merely receive something, or did I sign, approve, or interact with something? **AML:** What on-chain connection does this transfer create, how material is it, and what does the transaction context show?

A public wallet can receive assets without permission. What matters next is **understanding what arrived and avoiding unnecessary interaction before acting**. An unknown asset in your wallet is not automatically free money, proof of a hack, or proof of AML trouble. Treat it first as an unexplained on-chain event — and identify it before you do anything with it.

## FAQ

#### Why Did Random Crypto Appear in My Wallet?

Anyone who knows a public wallet address can usually send assets to it without asking permission first. An unexpected transfer may be dust, a scam token, an airdrop, an address-poisoning transaction, a mistaken payment, or a legitimate transfer from a sender you do not recognize.

#### Can Someone Hack My Wallet Just by Sending Me a Token?

Simply receiving a token does not normally reveal your private key or seed phrase and does not by itself give the sender permission to spend your other assets. The danger often begins when the recipient follows a malicious link, connects the wallet, signs a transaction, or approves a smart contract.

#### What Is a Crypto Dusting Attack?

A dusting attack involves sending very small amounts of cryptocurrency to wallet addresses and monitoring how those funds are later used. On UTXO-based networks such as Bitcoin, spending the dust together with other outputs can sometimes help an attacker correlate addresses and analyze a user's activity.

#### Is Dusting the Same as Address Poisoning?

No. Dusting traditionally focuses on tracking and correlating wallet activity. Address poisoning places a malicious lookalike address into transaction history so that the victim may accidentally copy it for a future payment. A small transfer may be used in both tactics, but their goals are different.

#### What Should I Do with a Scam Token in My Wallet?

Do not follow links or instructions associated with the token, and do not sign transactions simply to claim, swap, verify, or remove it. If the wallet supports hiding suspicious assets, hiding the token from the interface is generally safer than interacting with an unknown contract.

#### Can an Unsolicited Transfer Increase My Wallet's AML Risk?

An incoming transfer becomes part of the wallet's visible blockchain history, so an AML system may detect the connection to the sending address. Its significance depends on factors such as the source, amount, asset, direction, directness of exposure, and wider wallet activity. Receipt alone does not prove involvement with the sender.

#### Should I Send Unexpected Crypto Back to the Sender?

Do not automatically return it, especially to a different address supplied through an unsolicited message, website, or token metadata. First verify the original transaction and the person claiming to be the sender. Material or disputed transfers may require additional platform or legal guidance before funds are moved.

#### Can I Remove AML Risk by Moving My Crypto to a New Wallet?

Moving assets to another address does not erase their prior blockchain transaction history. Blockchain analytics can generally follow the transfer between addresses, so creating a fresh wallet should not be treated as a way to reset the provenance of funds.

#### How Do I Know If an Unknown Token Has Actually Compromised My Wallet?

An unknown incoming asset alone does not prove compromise. More serious signs include unauthorized outgoing transactions, unexpected token approvals, wallet-permission changes, assets leaving after you signed an unfamiliar transaction, or activity you cannot account for.

#### When Should I Trace an Unknown Crypto Transaction?

Tracing becomes relevant when there is an actual unauthorized movement of your funds or another material transaction that requires deeper investigation. A harmless spam token or tiny unsolicited incoming transfer usually does not require a theft investigation simply because it appeared in the wallet.