Skip to main content

Cryptojacking turns your PC into a Bitcoin mine, but you won’t see a cent

Image used with permission by copyright holder

(in)Secure is a weekly column that dives into the rapidly escalating topic of cybersecurity.

Cryptocurrency has fought for its reputation ever since its creation. Bitcoin fans have always had to defend against accusations that it’s only purpose is for illicit activities — that it’s a currency for criminals. Bill Gates even argued it has caused death in his recent Reddit AMA.

Now, cryptocurrency has yet another problem to deal with: cryptojacking. It’s the act of hacking a computer for use in cryptocurrency mining, usually without the owner knowing about it. It’s the newest evolution of malware — and it looks set to spread like wildfire.

A brave, new world

In February, Salon announced a new crowdfunding campaign that caught headlines across the internet. You can donate your computing power through cloud mining to help support the publication. It doesn’t require the installation of software, or even setting up an account.

Just like that, an alternative to paid subscriptions and ad-based revenue has appeared. Cloud mining was already catching on, and now it’s finding new, interesting use cases.

Also in February, security researcher Scott Helme published his findings on the dark side of the technology. Without getting consent from either the owner of the website or visitors, cryptocurrency scripts can be hacked into websites, which then hack visitor’s CPU power. That’s cryptojacking.

The past year has witnessed several large-scale attacks on websites like the LA Times, Tesla, and Politifact, but recently the trend has escalated in an even more startling way. Research shows that thousands of legitimate websites, including some that belong to government institutions, have been cryptojacked.

How? Helme puts it this way: “If you want to load a cryptominer on 1,000+ websites, you don’t attack 1,000+ websites, you attack the one website that they all load content from.” In one case, an assistive technology called Text Help was compromised. Any website that used it then cryptojacked visitors, without either the website owners or visitors having a clue.

https://twitter.com/Scott_Helme/status/962684239975272450

Another recent report claims 50,000 websites already have crypto-mining malware ready to steal your computer’s power without your knowledge. Seven thousand websites have been discovered to contain this strain of cryptojacking on the WordPress platform alone.

Both Salon and the hackers behind recent attacks use the same tool — a JavaScript miner called CoinHive. It can be embedded on a webpage and functions in the visitor’s browser window. Hackers have taken the script and implemented it to immediately force visitors to donate their CPU power toward mining Monero coins, or XMR. (What’s that, you ask? Read our guide to the best Bitcoin alternatives).

The internet could become one big, illicit crypto-mining operation.

That wasn’t CoinHive’s intent. Instead, its developers “dream about it as an alternative to micro payments, artificial wait time in online games, intrusive ads, and dubious marketing tactics.” It’s a rather clever idea, really. The average PC is much more powerful than needed to browse the web, so why not use a bit of that performance to pay for content? The creators of CoinHive told Motherboard recently that “their reputation couldn’t be worse,” lamenting that they didn’t see the potential of cryptojacking at the time.

To be clear, cryptojacking isn’t an easy way for hackers to get rich. If a site has 10–20 active miners all day, CoinHive claims “you can expect a monthly revenue of about 0.3 XMR (~$86).” It’s relatively easy for hackers to implement, however, and the anonymous nature of cryptocurrency makes the payoff hard to trace. Consider it low reward, but very low risk. So long as cryptocurrencies keep rising in value, cryptomining — and its dark side, cryptojacking — will continue to spread.

This is only the beginning

It’s not hard to imagine cryptojacking’s future. Today, ads are everywhere you look on the internet, and off. Ads appear everywhere from YouTube to free software. Cloud cryptomining could provide an alternative, letting you “donate” some processor power for free web content or software.

We could also see a future where cryptojacking is constantly in the news — and in much greater potency. The internet could become one big illicit crypto-mining operation, and the fight against that won’t be easy. Hackers will find efficient and more subtle ways of secretly contorting innocent CPUs to make a quick buck. Right now, it’s not yet possible to mine cryptocurrency in-browser using a visitor’s GPU, which would provide much more substantial hashing power. Such a thing can’t be too far away.

Image used with permission by copyright holder

And it doesn’t stop with in-browser mining.

Imagine the way adware works today. You’re installing a piece of software, and you quickly click through a few checkboxes to complete the installation. Without being fully aware of it, you’ve installed a piece of software that generates revenue for a company by inserting ads into your browser. Because it’s invisible, cryptojacking malware tougher to deal with. You might not even notice it quietly humming along in the background as it slows your computer and fills someone’s crypto-wallet.

This is certain to happen in a future where cryptocurrency cements its position as an online currency. It’ll give developers and website owners a new way to make legitimate cash from their work — and profit-driven hackers another potent tool in their toolbox.

Editors' Recommendations

Luke Larsen
Senior Editor, Computing
Luke Larsen is the Senior editor of computing, managing all content covering laptops, monitors, PC hardware, Macs, and more.
Best Samsung Galaxy deals: S24, Buds, Watches and more
The Galaxy Z Fold 4's Cover Screen.

Samsung’s Galaxy lineup is made up of several different types of devices, and if you’re in the market for some savings, you’ll often find Samsung Galaxy tech among the best headphone deals, the best smartwatch deals, the best tablet deals, and the best phone deals. With so many different devices among the Galaxy lineup, and with so many Samsung Galaxy deals out there for the picking, we rounded up what we feel are the best Samsung Galaxy deals to shop right now. Reading onward you’ll find discounts on some of the best tablets, best smartwatches, and best wireless earbuds the Samsung Galaxy lineup has to offer, as well as some impressive discounts on Galaxy phones.
Samsung Galaxy Buds 2 -- $97, was $150

If you're looking for headphone deals but you want an alternative to Apple's AirPods, you should consider the Samsung Galaxy Buds 2. The wireless earbuds have great battery life that's made even better with an included charging case. While some of the other Galaxy Buds out there include the Galaxy Buds Live, Galaxy Buds Pro, and Galaxy Buds+, but with the Galaxy Buds 2's active noise-cancelation you can block out unwanted sounds and keep your focus on whatever you’re working on, watching, or listening to. You can also control the headphones with touch controls on each earbud, and they connect easily to any Bluetooth device.

Read more
Best Microsoft Office deals: Get Word, PowerPoint, and Excel for free
Students using Microsoft Office software on their laptops outside.

While the fight of Microsoft vs Google when it comes to office apps might be never-ending, if you're the sort of person who prefers dealing with Microsoft, you'll be happy to know that there are quite a few good deals you can take advantage of. As you may know, most of Microsoft's apps have gone under one rather expensive subscription service, Microsoft 365, but you can still get older parts of the suite for relatively good prices. In fact, you can even get a free trial of Microsoft Word to test it out, although you'd still need to pay to get the full suite of tools.
Best Microsoft Office deals
Microsoft Office is a pay once, receive once service. You don't have to pay recurring monthly fees to use it, but the software also never updates. For what it's worth, the Microsoft Office packages are labelled "2021", so they're all fairly recent but also ripe for a good deal. With the exception of AI integrations, not much has really changed in the past couple of years when it comes to your basic document creation and these programs should continue to be effective for years to come. Depending on what package you get, you'll get access to different apps, based on the needs of the target audience. For example, Microsoft Office Home & Student 2021 keeps it lean and cool and with Microsoft Word, Microsoft Excel, and Microsoft PowerPoint being the only apps included.

Here are our favorite deals for the classic Microsoft Office experience:

Read more
Best refurbished MacBook deals: Get a MacBook Air for $140 and more
A stack of MacBooks is pictured from the top down.

Apple is one of the best laptop brands, and that's not surprising, given that various types of MacBooks regularly top the list of best laptops on the market. Unfortunately, sitting at the top does also mean that they are quite expensive, so fi you want to get your hands on one without paying an arm and a leg, going for a refurbished model is the way to go about it. Luckily, most MacBooks you'll find tend to be under warranty or have relatively good return windows, so even if there is a fault somewhere, you can return it and get a replacement or your money back.

To help you pick the best MacBook for your budget, we've gone out and picked some of the best refurbished MacBook deals we could find and compiled them below. That said, if you still don't want to go for a refurbished one, you could always check out these great MacBook deals as well.
MacBook Air 11.6-inch (2015) -- from $112

Read more