Coinhive was a browser-based JavaScript miner for Monero that became widely abused to cryptojack visitors’ computers. Check Point identified it as the most prevalent malware online in a January 16, 2018 finding. That ranking was time-bounded: Coinhive remained at the top of Check Point’s global threat index for 15 successive months through February 2019, then shut down on March 8, 2019.
What was Coinhive malware?
Coinhive supplied JavaScript that used a visitor’s browser to mine Monero. The service itself could be deployed with disclosure and consent, but attackers frequently inserted its code into compromised websites or caused it to run without meaningful authorization. In those cases, the software was part of a cryptojacking operation: someone else’s computer performed cryptocurrency-mining work for the attacker or site operator.
Because the miner ran in a browser tab, a victim did not necessarily need to install a conventional executable. Visiting a compromised page could be enough to start the script while the page remained open.
Why did Coinhive become so prevalent?
Attackers could recruit many browsers
Mining becomes more useful when more CPUs contribute work to the same pool. Check Point threat-intelligence researcher Lotem Finkelsteen described the incentive this way: “The more CPUs participate in the mining process, the more complicated it becomes to successfully mine the currency.” He added that threat actors therefore sought to recruit as many CPUs as possible, including website visitors’ computers.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Browser delivery lowered the installation barrier
A website operator or attacker could add a script to a page instead of persuading every victim to install a separate program. That made large numbers of short-lived mining sessions possible across ordinary computers, phones and other browser-equipped devices.
Prevalence depended on the measurement window
Check Point’s January 2018 statement described the threat landscape at that time; it did not establish that Coinhive would remain the leading malware indefinitely. Check Point later reported 15 consecutive months at the top of its global threat index, ending in February 2019.
How did Coinhive use a victim’s CPU?
The JavaScript performed mining calculations in the browser. In abusive deployments, the workload could consume up to 100% of a target’s CPU, according to CyberScoop’s January 2018 report. Malwarebytes’ post-shutdown analysis likewise observed that browser miners could drive CPU use to its maximum while a tab was open.
- Performance: Other applications and browser tabs could become slow, unresponsive or crash.
- Power: Sustained processor activity increased electricity use and could drain laptop batteries faster.
- Visibility: Closing the affected tab generally stopped that browser session’s work, but a compromised site could trigger the script again on a later visit.
CPU usage alone does not prove that Coinhive was present. High utilization can also result from video, games, software updates or other legitimate workloads.
Rank #3
Was Coinhive the most common cryptojacker?
It was the leading service in Check Point’s cited global threat-index measurements, but prevalence figures vary by source, date and methodology. A USENIX Security internet-scale study crawled 49 million domains and found cryptojacking on 0.011% of domains in its sample. In the period it measured, Coinhive had a larger installation base than CoinImp, although CoinImp’s WebSocket proxies were handling significantly more traffic in the second half of 2018.
| Measure | Finding | Qualification |
|---|---|---|
| Check Point global threat index | Coinhive ranked first for 15 successive months | Reported through February 2019; the January 2018 “most prevalent” finding was a snapshot of that threat landscape |
| USENIX domain study | 0.011% of domains showed cryptojacking | 49 million domains crawled; study-period result, not a current prevalence rate |
| USENIX comparison | Coinhive had a larger installation base than CoinImp | CoinImp WebSocket proxies processed significantly more traffic in the second half of 2018 |
Is Coinhive still active?
No. Check Point reported that Coinhive announced it would cease operation on March 8, 2019 because the service was no longer economically viable. That means the original Coinhive service is defunct, even though old references to its name and copied scripts may still appear online.
Rank #4
Malwarebytes found that many websites and routers still contained Coinhive-related JavaScript after the shutdown. Requests for the service continued to be blocked, but failed connections meant those remnants were not conducting active Coinhive mining.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What happened to cryptojacking after the shutdown?
Coinhive’s closure removed a major browser-mining service, but it did not eliminate cryptojacking. ENISA reported a 78% drop in web-based cryptojacking hits during the second half of 2019 after the shutdown. The decline indicates how important Coinhive had been to web-based activity, while residual scripts and other miners continued to exist.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
Modern investigations should therefore distinguish between the defunct Coinhive brand, leftover code that no longer reaches a working service, and unrelated cryptominers that may use different infrastructure or execute directly on a host.
How can you recognize a suspected browser miner?
- A particular site causes unusually high CPU usage while its tab is open.
- The computer becomes hot, loud or sluggish during ordinary browsing.
- A laptop’s battery drains faster only on specific pages.
- Browser developer tools or security software flag mining-related scripts or connections.
These signs are indicators, not a definitive diagnosis. Close the tab, update the browser and operating system, remove unknown extensions, and run a reputable security scan. Site owners should inspect third-party JavaScript, review router and content-management-system changes, and remove unauthorized scripts rather than assuming every blocked Coinhive request represents ongoing mining.
Quick Recap
Coinhive in context
| Question | Coinhive |
|---|---|
| Execution model | Browser-based JavaScript |
| Cryptocurrency | Monero |
| Consent issue | Legitimate disclosure was possible, but widespread abuse involved mining without informed authorization |
| Typical resource impact | Could drive CPU usage as high as 100% while a tab was open |
| Operational status | Service ceased operation on March 8, 2019 |
| After-effects | Residual scripts remained on some sites and routers; web-based cryptojacking later fell sharply but did not disappear |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




