Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
browser malware

Coinhive Was Once the Web’s Most Prevalent Cryptojacking Malware

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Coinhive was a browser-based JavaScript miner for Monero that became widely abused to cryptojack visitors’ computers. Check Point identified it as the most prevalent malware online in a January 16, 2018 finding. That ranking was time-bounded: Coinhive remained at the top of Check Point’s global threat index for 15 successive months through February 2019, then shut down on March 8, 2019.

What was Coinhive malware?

Coinhive supplied JavaScript that used a visitor’s browser to mine Monero. The service itself could be deployed with disclosure and consent, but attackers frequently inserted its code into compromised websites or caused it to run without meaningful authorization. In those cases, the software was part of a cryptojacking operation: someone else’s computer performed cryptocurrency-mining work for the attacker or site operator.

Because the miner ran in a browser tab, a victim did not necessarily need to install a conventional executable. Visiting a compromised page could be enough to start the script while the page remained open.

Why did Coinhive become so prevalent?

Attackers could recruit many browsers

Mining becomes more useful when more CPUs contribute work to the same pool. Check Point threat-intelligence researcher Lotem Finkelsteen described the incentive this way: “The more CPUs participate in the mining process, the more complicated it becomes to successfully mine the currency.” He added that threat actors therefore sought to recruit as many CPUs as possible, including website visitors’ computers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Browser delivery lowered the installation barrier

A website operator or attacker could add a script to a page instead of persuading every victim to install a separate program. That made large numbers of short-lived mining sessions possible across ordinary computers, phones and other browser-equipped devices.

Prevalence depended on the measurement window

Check Point’s January 2018 statement described the threat landscape at that time; it did not establish that Coinhive would remain the leading malware indefinitely. Check Point later reported 15 consecutive months at the top of its global threat index, ending in February 2019.

How did Coinhive use a victim’s CPU?

The JavaScript performed mining calculations in the browser. In abusive deployments, the workload could consume up to 100% of a target’s CPU, according to CyberScoop’s January 2018 report. Malwarebytes’ post-shutdown analysis likewise observed that browser miners could drive CPU use to its maximum while a tab was open.

  • Performance: Other applications and browser tabs could become slow, unresponsive or crash.
  • Power: Sustained processor activity increased electricity use and could drain laptop batteries faster.
  • Visibility: Closing the affected tab generally stopped that browser session’s work, but a compromised site could trigger the script again on a later visit.

CPU usage alone does not prove that Coinhive was present. High utilization can also result from video, games, software updates or other legitimate workloads.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was Coinhive the most common cryptojacker?

It was the leading service in Check Point’s cited global threat-index measurements, but prevalence figures vary by source, date and methodology. A USENIX Security internet-scale study crawled 49 million domains and found cryptojacking on 0.011% of domains in its sample. In the period it measured, Coinhive had a larger installation base than CoinImp, although CoinImp’s WebSocket proxies were handling significantly more traffic in the second half of 2018.

Measure Finding Qualification
Check Point global threat index Coinhive ranked first for 15 successive months Reported through February 2019; the January 2018 “most prevalent” finding was a snapshot of that threat landscape
USENIX domain study 0.011% of domains showed cryptojacking 49 million domains crawled; study-period result, not a current prevalence rate
USENIX comparison Coinhive had a larger installation base than CoinImp CoinImp WebSocket proxies processed significantly more traffic in the second half of 2018

Is Coinhive still active?

No. Check Point reported that Coinhive announced it would cease operation on March 8, 2019 because the service was no longer economically viable. That means the original Coinhive service is defunct, even though old references to its name and copied scripts may still appear online.

Malwarebytes found that many websites and routers still contained Coinhive-related JavaScript after the shutdown. Requests for the service continued to be blocked, but failed connections meant those remnants were not conducting active Coinhive mining.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happened to cryptojacking after the shutdown?

Coinhive’s closure removed a major browser-mining service, but it did not eliminate cryptojacking. ENISA reported a 78% drop in web-based cryptojacking hits during the second half of 2019 after the shutdown. The decline indicates how important Coinhive had been to web-based activity, while residual scripts and other miners continued to exist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Modern investigations should therefore distinguish between the defunct Coinhive brand, leftover code that no longer reaches a working service, and unrelated cryptominers that may use different infrastructure or execute directly on a host.

How can you recognize a suspected browser miner?

  • A particular site causes unusually high CPU usage while its tab is open.
  • The computer becomes hot, loud or sluggish during ordinary browsing.
  • A laptop’s battery drains faster only on specific pages.
  • Browser developer tools or security software flag mining-related scripts or connections.

These signs are indicators, not a definitive diagnosis. Close the tab, update the browser and operating system, remove unknown extensions, and run a reputable security scan. Site owners should inspect third-party JavaScript, review router and content-management-system changes, and remove unauthorized scripts rather than assuming every blocked Coinhive request represents ongoing mining.

Coinhive in context

Question Coinhive
Execution model Browser-based JavaScript
Cryptocurrency Monero
Consent issue Legitimate disclosure was possible, but widespread abuse involved mining without informed authorization
Typical resource impact Could drive CPU usage as high as 100% while a tab was open
Operational status Service ceased operation on March 8, 2019
After-effects Residual scripts remained on some sites and routers; web-based cryptojacking later fell sharply but did not disappear

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.