More and more websites are mining crypto-coins in your browser to pay their bills, line pockets

No, Chrome isn't slowing down – you're just silently digging up cyber-cash

By John Leyden

Posted in Security, 13th October 2017 05:29 GMT

Updated Sketchy websites are increasingly using cryptocurrency mining as a source of income.

CoinHive – the most prevalent cryptocurrency mining code provider – and its clones are becoming an alternative to dodgy advertising affiliate programs and survey scams in many cases.

More than 220 websites – mostly porn sites and torrent trackers – silently launch mining threads when surfers visit their sites, according to a new study by Adguard. The consumer-focused security firm reckons at least $43K was mined in Monero, as of October 10, based on the average time spent on website. Cryptocurrency mining code contaminated websites with an aggregated audience of 500 million people.

Real Mad-quid: Murky cryptojacking menace that smacked Ronaldo site grows


Cryptojacking scripts sometimes turn up on mainstream websites. For example, TV channel Showtime and the official website of Real Madrid star Cristiano Ronaldo were both caught harbouring CoinHive code recently. Pirate Bay admitted that it had experimented with the technology, something that happened without telling users beforehand.

Security researchers such as Troy Mursch (aka Bad Packets) have found it difficult to get sites to act on reports of infection. This means it can be difficult to determine whether third party hackers have planted the code on insecure sites or whether it’s there as a sanctioned money making move. The anonymity offered by digital currencies adds to the confusion.

The largest website sporting mining code is the Dropbox clone, which is a top-1000 website, according to Alexa's worldwide rankings of sites by traffic, with 60 million-plus monthly visitors, Adguard reports.

The CoinHive team has called on website operators to inform their users about mining operations but there’s no facility to block misuse of the technology by the unscrupulous, according to Adguard, which adds that three more clones of CoinHive appeared over the three week period of its recent study.

Ad blockers and antivirus programs have added features that block browser mining. AdGuard has updated its apps to give users the choice to let a site mine, or to forbid it to launch mining in their browsers. Informed consent lies at the root of objections to cryptocurrency mining practices. Done with permission the technology offers an alternative revenue stream to publishers outside of online ads, which many find either intrusive or annoying.

An earlier study on how cryptocurrency mining is being abused can be found in a blog post by Malwarebytes here. ®

Updated at 0803 UTC on 13 October to add: said that it had it removed CoinHive JavaScript code from its site after completing tests. “Ads are better :),” it told El Reg.


As a reader just emailed in to point out, El Reg ourselves have done this sort of thing in the past (just kidding – it was an April Fool's Day joke!)

Sign up to our NewsletterGet IT in your inbox daily


More from The Register

Real Mad-quid: Murky cryptojacking menace that smacked Ronaldo site grows

They’re taking our processor cycles

Pirate Bay digs itself a new hole: Mining alt-coin in slurper browsers

Would you trade your CPU time and electricity bill for pirated content?

CBS's Showtime caught mining crypto-coins in viewers' web browsers

Who placed the JavaScript code on two primetime dot-coms? So far, it's a mystery

Europe-wide BitTorrent indexer blockade looms after Pirate Bay blow

Analysis Euro Court of Justice decides infamous search engine does infringe copyright

Costa Rica complains of US govt harassment over Pirate Bay domain

Registry operator points finger at US embassy staffer

Google's Chrome cloaks Pirate Bay in red screen of malware death

Scam ads abound

Google blocks Pirate Bay

Another day, another cryptocurrency miner lurking in a Google Chrome extension

Plus: A new stealthier Monero crafter emerges

Adblock Plus owners commandeer Pirate Bay man's tip jar Flattr

Two horsemen of the apocalypse unite

Iceland's Pirate Party loses four MPs in new elections

Vote sinks by a third but Pirati can still reach government with its skeleton crew