Ethereum just posted a record day on the mainnet, yet the headline number quickly turned into a security warning. On-chain data showed that daily transactions topped 2.88 million on Jan. 16, setting a new high. Soon after, members of the crypto community argued that the spike did not come purely from organic demand, pointing instead to large-scale address poisoning and dust attacks.
The jump had initially been read as a constructive signal for the network. Lower transaction fees and network optimizations tied to the Fusaka hard fork made activity on Ethereum smoother, feeding the view that ecosystem usage was recovering and user participation was picking up. That reading now faces a serious challenge.
Nine of the top ten transaction-generating contracts were flagged as malicious
Crypto KOL @jason_chen998 wrote on X that one of the main forces behind the recent surge was a wave of address poisoning and dusting attacks. According to the cited on-chain data, 9 of the top 10 contracts generating transactions were malicious contracts. These contracts were sending tiny amounts of funds to massive numbers of addresses, creating activity at very high frequency.
That kind of behavior can inflate Ethereum’s transaction count without reflecting real user demand. The number looks strong. The quality of the activity is a different question.
How small transfers can be used to set up larger thefts
One purpose of dust attacks is de-anonymization. By sending tiny amounts to many wallets and watching where those funds move next, attackers can map relationships between addresses and make inferences about the people behind them. That information can later be used in phishing or social-engineering campaigns.
Another tactic relies on lookalike addresses. Many users copy wallet destinations from recent transaction history, so attackers generate fake addresses with opening and ending characters that closely resemble legitimate ones. They then send a small amount of dust so the fake address appears in the victim’s history, increasing the odds that a later transfer goes to the attacker by mistake.
Some dust transfers also include malicious tokens or links to malicious contracts. If a user interacts with those assets by transferring them out, approving them, or swapping them, hidden code may trigger wallet permissions and in some cases drain the account.
Lower Gas costs may have made spam campaigns cheaper
The report said that after the Fusaka upgrade in December 2025, Ethereum Gas fees dropped sharply. That change reduced the cost of running large spam campaigns, making it cheaper to push micro-transfers to thousands of addresses while keeping the attack economically attractive.
As a result, headline transaction growth can be lifted by noise. For regular users, the danger is not only inflated metrics but also the chance of missing suspicious activity in a crowded transaction history.
Check every address and avoid interacting with unknown dust
The protection advice is straightforward: verify every transfer address character by character instead of relying on copied recent history; use a hardware wallet and an address book, and send only to whitelisted destinations; do not interact with dust from unknown sources, including transfers, approvals, or swaps; review and revoke suspicious permissions on a regular basis; enable wallet features that hide tiny balances or filter dust; and avoid exposing wallet addresses in public when possible.
Ethereum’s transaction count did reach a new high. That does not mean every transaction reflected genuine usage, and the record has also drawn attention to a wallet-security risk that users cannot ignore.

