HTX investigates mass small transfers resembling address-poisoning attack
Security & Exploits ·
HTX said it is reviewing reports of small unsolicited transfers appearing to come from its exchange addresses, an incident some users have linked to a poisoning-style scheme, with some accounts reportedly frozen as a result.
According to a report, HTX said an internal review found no evidence that it had initiated any related transfers or testing activity tied to the transactions in question. The exchange said it is still examining the source and cause of the activity, including the possibility that the transfers stem from address-labeling or on-chain attribution errors rather than any action taken by HTX itself. HTX said it would disclose findings once its investigation is confirmed, according to the same report.
The episode has produced downstream effects beyond HTX’s own platform. Unsolicited transfers that appeared to originate from HTX addresses reportedly triggered anti-money-laundering freezes on Coinbase, according to corroborating accounts in the cluster, even as HTX maintained it was not behind the transactions. Separately, HTX users have reported unauthorized transfers landing in their addresses, prompting the exchange to again deny initiating the transactions while it investigates.
The pattern described — large volumes of small transfers sent to addresses associated with an exchange, seemingly to create a false trail — is consistent with what is commonly called an address-poisoning attempt, though HTX has not confirmed that characterization and instead has floated attribution or labeling errors as an alternative explanation. The distinction matters: if the transfers were sent by a third party rather than HTX, the AML flags and account freezes triggered at Coinbase and reportedly on some HTX-linked accounts may reflect misattributed on-chain activity rather than exchange-side compromise.
Three separate sources are covering the cluster, pointing to the incident's transactions to HTX-associated addresses, the resulting freezes, and the exchange's denial of involvement. HTX has not yet specified how many addresses or accounts were affected, nor has it detailed the volume or timing of the small transfers involved.
What remains unresolved is the root cause: whether the transactions were sent by an external actor attempting a poisoning-style deception, or whether the issue lies in how on-chain analytics tools or exchanges are labeling and attributing addresses to HTX. HTX's stated commitment to disclose confirmed findings, referenced in a statement, leaves open whether frozen accounts will be restored and whether other exchanges will revisit the AML flags triggered by the same transfers.