Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Coinhive was a browser-based JavaScript miner for Monero that became widely abused for cryptojacking—using visitors’ computers to mine cryptocurrency without informed authorization. Check Point identified it as the most prevalent malware online in a January 16, 2018 report covered by CyberScoop. That was a time-bounded ranking, not a description of a service that remains active: Coinhive shut down on March 8, 2019 after mining was no longer economically viable.

What Coinhive malware was

Coinhive provided JavaScript that a website could run in a visitor’s browser to use the computer’s processor for Monero mining. The intended model could be disclosed and consent-based, but attackers frequently embedded the script in compromised websites or triggered it without meaningful notice or permission. That unauthorized use of someone else’s CPU is known as cryptojacking.

Because the miner ran in the browser, a victim generally did not need to install a conventional executable. Opening an infected page could be enough to start mining while the tab remained active.

How cryptojacking used a visitor’s CPU

Mining in the browser

Mining requires many processors to perform repeated calculations. Check Point threat-intelligence researcher Lotem Finkelsteen explained that threat actors recruit large numbers of CPUs because more participating CPUs make successful mining more likely. In a malicious Coinhive deployment, the website’s JavaScript recruited the visitor’s processor into the attacker’s mining pool.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Performance and power effects

  • CyberScoop reported that cryptojackers could consume up to 100% of a target’s CPU.
  • High utilization could make other applications slow, unresponsive or prone to crashing.
  • On laptops and mobile devices, sustained processor activity could drain the battery faster and increase heat and electricity use.
  • Malwarebytes observed that browser miners could drive CPU usage to its maximum for as long as the tab was open.

These symptoms were not proof of Coinhive specifically; other browser scripts, updates and extensions can also cause heavy CPU use. The distinctive risk was unauthorized mining tied to a web page or embedded third-party resource.

Was Coinhive really the most common cryptojacker?

Yes, within the dated measurement cited by Check Point. Its global threat index ranked Coinhive first for 15 successive months through February 2019. The January 2018 CyberScoop headline reflected that period’s prevalence data, not a permanent status.

Finding What it measures Time or scope
Check Point ranking Coinhive ranked first in the global threat index 15 successive months through February 2019
USENIX Security study Cryptojacking appeared on 0.011% of domains in a crawl of 49 million domains Internet-scale study published in 2019
USENIX comparison Coinhive had a larger installation base than CoinImp, while CoinImp WebSocket proxies handled significantly more traffic in the second half of 2018 Study period, including the second half of 2018
ENISA assessment Web-based cryptojacking hits fell 78% Second half of 2019, after Coinhive’s closure

The figures describe different things: a threat-index ranking, the presence of mining on sampled domains, installation counts and traffic. They should not be treated as interchangeable estimates of all cryptojacking activity.

What happened to Coinhive?

Coinhive announced that it would cease operation on March 8, 2019, citing a lack of economic viability. The shutdown ended the service’s active mining infrastructure, but it did not instantly remove every copy of its code from the web.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Residual scripts after the shutdown

Malwarebytes found Coinhive-related JavaScript still present on some websites and routers after the service closed. Requests to the former service were blocked, so those leftover scripts could no longer perform active Coinhive mining through the shut-down service. Their presence could nevertheless indicate an unmaintained or compromised system and warranted removal.

Cryptojacking after Coinhive

Cryptojacking did not disappear with Coinhive. Other miners and delivery methods persisted, but ENISA measured a 78% drop in web-based cryptojacking hits during the second half of 2019 after the closure. The decline shows Coinhive’s importance to the browser-mining ecosystem while also showing that the broader abuse continued.

How Coinhive compares with other cryptojacking threats

Coinhive’s defining characteristics were its browser execution, Monero mining and dependence on a live service and mining pool. When assessing another miner, use the same questions:

  • Where does it run? A browser script behaves differently from malware installed on the host operating system.
  • Was there meaningful consent? Disclosed, limited mining is different from hidden use of a visitor’s resources.
  • What does it mine and how? The cryptocurrency and mining algorithm affect processor load, compatibility and profitability.
  • What is the resource impact? Look for sustained CPU use, heat, battery drain and degraded application performance.
  • How was prevalence measured? Rankings, domain crawls, installation bases and network traffic answer different questions.
  • Does it depend on an active service? A provider shutdown can disable old scripts without removing them from websites or devices.

What users and site owners should take away

  • A Coinhive warning or blocked request today does not mean Coinhive is still operating; the service ended in 2019.
  • An old script can remain in a page, router or content-management system after its backend has shut down and should be removed rather than ignored.
  • Unexpected, sustained CPU use while a particular website is open is a reason to inspect that site, browser extensions and network controls, not automatic proof of one named miner.
  • Website operators should audit third-party JavaScript, remove unauthorized mining code and make any resource-intensive activity explicit and consent-based.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The Bottom Line

Coinhive was the leading browser-cryptojacking service in Check Point’s 2018–February 2019 measurements, but it is defunct. Its March 8, 2019 shutdown sharply reduced web-based cryptojacking; residual scripts and other miners still made cleanup and monitoring necessary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.