Curriculum·G405 Blockchain Analytics from the Compliance Side·about 33 min

The false positive and the cost of being wrong

By the end of this lesson you can

  • Explain how a dusting attack manufactures an on-chain connection a recipient never chose
  • Reason that an on-chain link is evidence to weigh, not proof of who someone is
  • Describe the cost of a false positive: harm to an innocent party and erosion of the tool
  • Corroborate an analytics match before acting, rather than treating it as certainty

Graduate · enrolled learners

This lesson opens with The Litecoin dusting attack, August 2019.

What happened
In August 2019 an unknown party sent tiny amounts of litecoin, dust, to hundreds of thousands of addresses in what became known as a dusting attack. The direct financial loss was negligible, a few cents scattered across the network, which is why the loss here is effectively zero. The point of a dusting attack is not to steal but to create connections: by sending dust from a chosen source to an address, an attacker manufactures an on-chain link between that source and the recipient, and if the recipient later spends the dust together with their own funds, that link can be used to cluster and deanonymize them, or simply to make an innocent address appear associated with a tainted origin. The recipients did nothing and chose nothing, yet on-chain they now had a connection to whatever address the dust came from. A dusting attack is the clean demonstration that an on-chain link between two addresses can be created by one party without the other's knowledge or consent, which is precisely why treating such a link as proof of anything about the recipient is a false positive waiting to happen.
The decision point
Blockchain analytics is powerful because the ledger is public, but everything it produces is an inference from on-chain connections, and connections are evidence to weigh, not proof of identity or intent. A false positive is what happens when a desk treats that inference as certainty: it acts against a party whose only offense is an on-chain link they may never have chosen, as a dusting attack manufactures deliberately and as ordinary activity through a shared service or a mixer can create by accident. The cost of being wrong is real and lands on someone: an innocent customer whose funds are frozen, whose account is closed, or who is reported as a criminal, and beyond that person, the credibility of the whole compliance tool, because a screening system that punishes the innocent loses the trust that lets it act on the guilty. So the decision an institution makes is to hold an analytics match as strong evidence that must be corroborated before it acts, distinguishing a connection a party created from one that was created around them, because the same transparency that lets a desk catch laundering lets an adversary, or mere coincidence, manufacture the appearance of it, and a desk that cannot tell the difference will eventually punish someone who did nothing.

What you will be able to answer

  • What is a dusting attack, and why does it matter for compliance?
  • What does blockchain analytics ultimately rest on?
  • What is the cost of a false positive?
  • How should a desk act on a strong analytics match?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Sources and review

Confidence medium·Volatility low·Reviewed 2026-09-16·Owner unassigned

Contested

The loss is recorded as zero because a dusting attack causes negligible direct financial loss; the real cost is the false positives it can produce, which fall on wrongly-flagged parties and are not captured by a theft figure. This is a deliberate use of a near-zero-loss incident to teach the cost of being wrong.

Not every on-chain link is a dusting attack; shared custodial services, exchanges and mixers create connections through ordinary activity too. The lesson's point is that a connection can be unchosen for many reasons, so it must be corroborated, not that every match is an attack.