Skip to content

Spam and Dust Tokens Are Inflating Your Portfolio

6 min read · Verified September 2026

Spam tokens are airdropped into public wallet addresses without your involvement, and some carry a nominal price taken from a near-empty liquidity pool, so a tracker that sums every balance reports a total that is far too high. Filter them by value threshold or hide them individually. Never swap or approve one.

You open your holdings and there are forty-one line items. You recognise five. Sitting near the top is something called "USDC Claim Reward" valued at $4,812, and you have never bought it, never heard of it, cannot sell it, and cannot make it go away.

Your tracker is not broken. It is reading the chain correctly and doing exactly what you asked, which is to sum the value of everything in the address. The problem is that a public address is a public inbox with no lock on the letterbox.

How did tokens I never bought end up in my wallet?

A blockchain address has no permission gate for incoming transfers. If somebody knows your address, they can send you a token, and it lands in your balance whether you want it or not. There is no accept prompt, no spam folder, no blocklist, and no way to refuse delivery in advance. Wallets and trackers can only decide what to show you after the fact.

Spammers work at scale because the cost per address is fractions of a cent on most chains. They pull address lists straight from public explorers, filter for wallets that have moved real money, and blast a contract call to a hundred thousand of them at once. If you have ever bridged funds, minted anything, or held a token that had a genuine airdrop, you are on those lists permanently.

What arrives comes in two rough shapes. Dust is a tiny quantity of something real or something that mimics something real, sent in amounts too small to matter. Sometimes the motive is analytics: watch where the dust moves and you learn which addresses belong to the same person, which is one of the quiet costs of using a single address for everything. Sometimes the motive is address poisoning, where the sending address is crafted to share its first and last few characters with an address you actually use, so that a future copy-paste from your history sends real funds to the attacker.

Bait tokens are the noisier kind. These carry names that are instructions: a claim URL, a fake rebate, a warning that your position is about to expire. The name is the payload. Everything about the token exists to get you to a website.

Neither type can take anything from you by arriving. That distinction matters, and we will come back to it.

Watching a wallet read-only lets you hide dust without ever touching the spam contract.

Why does a worthless token show a price at all?

This is the part that produces the fake five-figure line item, and it is worth understanding because it explains a lot about crypto pricing generally.

There is no central registry that decides what a token is worth. Price for anything outside the majors is derived from trades, and on-chain that means the ratio of reserves in a liquidity pool. Deploy a token with a supply of ten billion, pair a few thousand of them against forty dollars of a real asset in a fresh pool, and you have manufactured an implied price. Multiply that price by the ten million tokens you airdropped to each victim and the arithmetic produces a number with commas in it.

The pool is real. The price is real in the narrow sense that one trade did occur at it. What is fictional is the idea that the market could absorb your holding at anything close to that number. This is the same problem, in an extreme form, that makes two apps quote different figures for the same thin-liquidity asset, covered in why the same coin shows two different prices.

The distortion is not always upward. More often spam adds no value and pure noise: dozens of unpriced rows that bury the four positions you actually care about, so the holdings screen becomes something you scroll past rather than read. A portfolio you stop reading is worse than one that is slightly wrong.

How do I filter dust without hiding something real?

The blunt instrument is a value threshold, and for most people it is the correct one. Hide anything below a dollar, or below ten dollars if your positions are large, and the list collapses back to something legible. The threshold approach has the advantage of working on future arrivals too, which matters because the spam does not stop.

The risk is obvious: a real position can sit below your threshold. If you hold a small amount of something deliberately, exclude it by hand from the filter rather than raising the threshold to accommodate it. Most trackers, this one included, let you hide and unhide individual assets, and hiding is a display decision that leaves transaction history untouched.

For anything that survives the threshold and still looks wrong, verify the contract address on a block explorer rather than trusting the name. Etherscan and its equivalents on other chains show the token's holder count, its transfer history and whether the contract is verified. A token held by four hundred thousand addresses with two transfers each is an airdrop, not an asset. This check takes thirty seconds and is the only reliable way to tell a real low-cap token from a manufactured one, since names and logos can be copied freely.

If you watch several addresses, do this once per address rather than once globally. Spam distribution is uneven, and the wallet you use for minting will be far dirtier than the one you use for holding, which is one of the arguments for the separation described in running a multi-wallet setup.

Why is swapping a spam token the dangerous part?

Here is the thing most people get backwards. Receiving spam is harmless. Attempting to get rid of it is where money is lost.

Swapping a token on a decentralised exchange requires you to grant the exchange contract permission to move that token on your behalf. That approval is a signed transaction, and a malicious token contract can be written so that the approval flow presents you with something other than what you think you are signing — a permit covering a different asset entirely, or a blanket allowance on a token you actually hold. You went to clear four dollars of garbage and signed away your stablecoin balance.

The second trap is the honeypot. The contract permits buying and blocks selling, either outright or for every address except the deployer's. The price chart looks alive because purchases keep going through. Nobody has ever exited.

The third is the claim site. The token's name sends you to a page that asks you to connect a wallet and sign to claim, and the signature is a transfer authorisation. In the worst version it asks for your recovery phrase directly, which no legitimate site or app ever needs and which is covered plainly in why you never share your seed phrase. The fake sites are usually well made; the fake apps that go with them are covered in spotting fake crypto apps.

The correct action for a spam token is nothing at all. Do not swap it, do not send it anywhere, do not approve it for anything, and do not visit whatever its name tells you to visit. Hide it in your tracker so the number is right, and leave it in the wallet forever. It costs you nothing to hold and everything to touch.

If you have already granted an approval you regret, revoke it. The mechanics are the same as revoking an exchange key, and how to revoke access you've granted walks through the process.

Spam volume tracks activity, so a wallet that mints and bridges will accumulate faster than one that holds. Set the threshold once, check new arrivals when you reconcile rather than when they appear, and use a regular audit pass to confirm the filter is hiding noise and not a position. The list stays readable, and the number at the top stays one you can quote without checking it twice.

Common questions

No. Receiving a token is passive and cannot move anything out of your wallet. The risk begins the moment you interact with it — approving it for a swap, or signing whatever the site printed in its name asks you to sign. Ignoring it entirely costs you nothing.

No. Most of them cannot be sold at the price shown, because the pool backing that price holds a few dollars. Many are honeypots that permit buying and block selling. The gas you would spend attempting it is a guaranteed loss against an almost certainly fictional gain.

Hiding is a display setting in your tracker, not a block on the chain. New spam keeps arriving because your address is on a list that gets resold. A value threshold handles this automatically, since it filters future arrivals as well as current ones.

An attacker sends you a worthless transfer from an address whose first and last characters match one you have used before. Later, when you copy a recipient address out of your transaction history, you copy theirs. Always verify the middle characters of any address you paste, not just the ends.

Rarely. Exchanges list a curated set of assets and screen deposits, so the spam problem is almost entirely a self-custody problem. If your total looks wrong on the exchange side, the cause is usually API key scope rather than spam.

It should not. Hiding removes an asset from the holdings view and the total; it does not delete transaction records. If you later find the token was real, unhiding restores it with its history intact.

Read-only wallet tracking across 15+ blockchains, with 10,000+ assets priced and everything below your threshold hidden.

Keep reading

← All guides