Cats bring you things. A leaf, a bottle top, something that was recently alive, placed carefully where you will step on it. The gesture is not hostile and it isn't quite a gift either — the current best guess is that it's instruction, or an invitation, or just a cat moving an object to where cats think objects belong.
The correct response is the same regardless: don't panic, don't eat it, and think for a second before you pick it up.
Your bitcoin wallet receives doorstep offerings too, and the same posture applies.
1. Dust, and Why Someone Sent You 500 Sats
Every so often, a wallet receives a tiny unsolicited amount from an address it doesn't recognise. A few hundred sats — too small to be a mistake, too small to be worth anything.
This is usually a dust attack, and the mechanism is worth understanding because it's elegant and slightly unsettling.
The sender isn't trying to give you money. They're trying to tag you. They send dust to thousands of addresses at once, then watch the chain. When one of those dust outputs later gets spent together with your other coins — which happens automatically if your wallet includes it in a transaction — it links all those inputs as belonging to the same person. Your previously separate addresses have just been merged into one visible identity by a payment you never asked for.
The attacker is typically a chain-analysis firm, a marketer, or someone building a profile for a later approach.
What to do: nothing, deliberately. Receiving dust is harmless. Spending it is the problem. If your wallet supports coin control, label the dust as "do not spend" and leave it there forever — it costs more in fees to move than it's worth anyway. Many modern wallets now flag suspicious dust automatically; if yours does, let it.
2. The Near-Identical Address
The related trick: a transaction appears in your history from an address that looks almost exactly like one you've used — same first four characters, same last four, different middle.
The goal is your copy-paste habit. Later, you grab an address from your transaction history instead of from the source, and the money goes to the attacker.
What to do: never copy an address out of your history. Get it from the person or the invoice, every time. And check the middle of the string, not just the ends, before confirming — the ends are precisely what the attack matches.
3. Tokens You Didn't Ask For
If you use any chain that supports tokens, you'll eventually find an unrequested token in your wallet with a name like a prize or a website embedded in it.
These are bait. The value isn't real, and the only way to "claim" or sell it is to visit a site and connect your wallet — at which point the actual attack happens: a signature request that grants permission over the assets you do own.
What to do: nothing at all. Don't connect, don't claim, don't sell, don't investigate out of curiosity. Hide it if your wallet lets you. On bitcoin proper this is rarer, but the instinct transfers: an asset you didn't expect is not an opportunity, it's a lure.
4. Coins From a Source You'd Rather Not Have
Harder and more honest: sometimes a payment arrives with history you don't love — from a service that was later sanctioned, from a mixer, from a counterparty who turned out to be a problem.
You can't prevent this. Anyone can send to any address, and you have no veto. But you can limit how much it affects you:
- Keep received coins separated and labelled, especially anything from an unfamiliar source. Don't merge them with your savings.
- Know that exchanges run heuristics on deposits. If you deposit coins with a history their screening dislikes, expect questions, delays or a frozen account — not because you did anything, but because their risk model is automated and blunt.
- Keep records of where payments came from. For a business, that's the difference between a short conversation and a long one.
This is an uncomfortable property of a transparent ledger that privacy-maximalist writing tends to skip: your coins carry a visible past that was not written by you.
5. The General Rule
All of the above collapses into one principle:
Receiving is always safe. Spending is where decisions happen.
Nobody can take your coins by sending you something. No incoming transaction can drain a wallet. Every attack in this article works later, through a transaction you make — by consolidating dust, by copying a poisoned address, by signing something on a website.
Which means the defence is entirely on the outbound side: look at what you're spending, where it's going, and what you're merging together. The doorstep can't hurt you. Picking the thing up without looking at it can.
The Point
Tuga has brought me a leaf, a bottle cap, half of something I didn't identify, and once a live mouse that then lived behind the washing machine for two days. None of them were attacks. All of them required me to think briefly before acting.
Your wallet's doorstep is public, permanently, and anyone can leave something on it. That's a feature of a system where nobody needs permission to pay you. Just look before you pick anything up — and when it's dust, leave it exactly where it is.
Receiving is safe. Think before you spend what arrived. 🐾⚡