Justiin Sun dismisses ‘made up’ HTX address poisoning rumors
Justin Sun has denied allegations that HTX exchange wallets sprayed unsolicited USDT transfers across unrelated addresses, but provided no technical evidence or investigation details to support his claim. The incident exposes how sanctioned exchange counterparties, HTX faces restrictions in the UK and EU since May 2024, can trigger compliance freezes at downstream platforms even through nominally small transfers, creating operational friction for institutional market participants.
- HTX founder Justin Sun dismissed reports of address poisoning as “all made up” on August 18 without providing investigation details or naming accusers
- Traders received unsolicited USDT transfers ranging from 7.5 to 12 USDT, triggering account freezes at downstream platforms including Coinbase
- HTX is designated a sanctioned counterparty in the UK and EU as of May 26, 2024, making any withdrawal from it a potential compliance trigger
- August 18 Date Sun dismissed allegations of address poisoning via social media post
- May 26, 2024 Effective date HTX became sanctioned counterparty in UK and EU jurisdictions
- 12 USDT Maximum amount of unsolicited transfer reported to individual traders
Justin Sun, founder of TRON and owner of the HTX exchange (formerly Huobi), rejected claims that his platform had conducted unauthorized micro-transfers to unrelated wallet addresses on August 18, calling the reports “fabricated” without substantiation.
The denial came hours after traders began circulating screenshots of small USDT deposits landing in their personal wallets, with blockchain explorers flagging the source addresses as belonging to HTX infrastructure.
Sun’s response included a link to an unspecified follow-up document but omitted the specific technical details that institutional investors and compliance teams typically require to evaluate such claims, no transaction hashes, no timeline of alleged activity, no named third-party investigators.
Small Transfers Trigger Compliance Freezes Across Downstream Platforms
The transfers themselves were modest in nominal value but substantial enough to evade typical dust attack detection thresholds. Individual traders reported receiving between 7.5 and 12 USDT in unsolicited deposits, amounts that sit well above the near-zero sums characteristic of blockchain dust attacks.
A trader known as 0xZiye reported receiving 7.5 USDT to a Coinbase account and attributed the transfer to HTX operations. Critically, when those funds arrived in downstream addresses maintained on platforms like Coinbase, compliance systems flagged the deposits as originating from a sanctioned source, threatening account suspension.
0xZiye reported that Coinbase initially demanded explanation of the deposit’s source and threatened account closure unless he resolved the compliance inquiry. The trader wrote publicly that “HTX is crazily transferring out small amounts, polluting other addresses,” a framing that suggested either deliberate action or gross operational negligence.
However, Phyrex, a blockchain analyst widely followed by institutional traders, confirmed within hours that 0xZiye’s Coinbase account had returned to normal status after escalation to Coinbase’s legal and compliance departments. This rapid resolution indicated that downstream platforms could distinguish between genuine risk and administrative friction once the true source was clarified.
The incident demonstrates how sanctions designation creates cascading compliance obligations across the custody and exchange ecosystem, even for transfers that pose no direct financial risk.
HTX Sanctioned Status Since May Creates Liability Chain for Any Outbound Transfer
The root cause of the compliance freezes had nothing to do with the transfers themselves and everything to do with HTX’s regulatory standing. In May 2024, HTX became designated a sanctioned counterparty in both the United Kingdom and the European Union, placing it in the same category as exchanges and platforms subject to formal financial restrictions.
As a direct consequence, any wallet that withdrew funds from HTX after May 26, 2024 was flagged as having a connection to a sanctioned entity, a status that triggers automated compliance review at major downstream platforms.
Binance has frozen transactions linked to HTX, Exmo, and more than a dozen other exchanges and some decentralized venues, establishing a de facto industry standard for treating HTX outflows as compliance risks. Even Hyperliquid, a decentralized derivatives platform, implemented address blacklisting for wallets flagged as HTX-connected.
The implication is stark: any transfer originating from HTX infrastructure, whether authorized or accidental, carries inherent compliance friction at major custody and trading venues. This creates operational drag that institutional users and market makers must navigate regardless of the transfer’s legitimacy or intended recipient.
HTX’s official response dodged the core issue. The exchange stated it had “not conducted any related transfers or testing activities” and claimed it would refrain from speculation before completing an internal review. Molly, HTX’s head of marketing, asserted that the platform “absolutely” did not engage in such behavior and suggested either misattribution or deliberate sabotage.
However, neither the exchange nor Sun addressed why HTX-designated addresses appeared in blockchain explorer data associated with the transfers, nor did they clarify whether blockchain analytics firms had misidentified the wallet ownership through faulty attribution logic.
Sun’s Denial Lacks Technical Evidence as Questions Persist Over Attribution
Sun’s brief dismissal on August 18 left the substantive questions unresolved. Institutional investors and compliance teams require specific technical data to evaluate such claims: transaction hashes, wallet derivation paths, signing keys, or forensic blockchain analysis from third-party firms. Sun provided none of these.
His reference to an unspecified follow-up document, coupled with the absence of any detailed investigation summary, suggested either incomplete due diligence or a deliberate choice to avoid public disclosure of HTX’s internal findings.
The attribution question remains open and material for institutional market participants. Blockchain explorers and on-chain analytics firms assign wallet ownership to entities based on clustering algorithms, known deposit/withdrawal patterns, and public labeling by exchange operators.
These methods are heuristic rather than definitive, misattribution is possible, particularly if HTX infrastructure was compromised or if a third party spoofed HTX wallet addresses. HTX’s suggestion that “attribution as a possible culprit” introduces ambiguity that cannot be resolved through social media denial alone.
Institutional customers require formal third-party verification or transparent investigation summaries to assess the true source and intent of the transfers.
The lack of technical transparency compounds the reputational and operational risk HTX faces in institutional markets already skeptical of platforms operating under sanctions designation.
The incident will likely remain a compliance nuisance for HTX users until either the exchange publishes a detailed forensic analysis naming the true source of the transfers, or regulatory clarity emerges on whether HTX itself has been spoofed or whether its systems conducted the transfers deliberately. In the interim, major platforms like Coinbase, Binance, and decentralized venues will continue applying sanctions-linked filtering to any HTX-originated transaction, forcing institutional traders to route funds through alternative venues or accept delays in compliance review. Sun’s next concrete step, whether a formal investigation report with named third-party validators or a technical remediation disclosure, will determine whether this becomes a routine compliance friction point or a deeper institutional confidence issue for the HTX ecosystem.