LIVE
8 Biggest Crypto Lawsuits of All-TimeTesla Says It Did Not Sell Its Bitcoin Holdings in Q2 202610 Biggest Crypto Fraud Cases in 2026SEC Settles With Coinbase After 2024 LawsuitCelsius Founders Could Face Permanent Crypto Bans Beyond $16.5M Obligations: ReportSEC settles FOIA lawsuit with Coinbase, agrees to pay $150,000Pakistan FIA Launches Digital Asset Unit: What It MeansMovement Labs Bankruptcy Filing Raises Questions for MOVE BlockchainBessent Says Crypto Clarity Act Is at the 1-Yard LineWanchain Bridge Exploit Drains $13M in NIGHT Tokens8 Biggest Crypto Lawsuits of All-TimeTesla Says It Did Not Sell Its Bitcoin Holdings in Q2 202610 Biggest Crypto Fraud Cases in 2026SEC Settles With Coinbase After 2024 LawsuitCelsius Founders Could Face Permanent Crypto Bans Beyond $16.5M Obligations: ReportSEC settles FOIA lawsuit with Coinbase, agrees to pay $150,000Pakistan FIA Launches Digital Asset Unit: What It MeansMovement Labs Bankruptcy Filing Raises Questions for MOVE BlockchainBessent Says Crypto Clarity Act Is at the 1-Yard LineWanchain Bridge Exploit Drains $13M in NIGHT Tokens
Homepage/News/Cryptojacking Attacks Still On The Rise Even After Coinhive Shutdown
NEWS

Cryptojacking Attacks Still On The Rise Even After Coinhive Shutdown

BY Anca Florentis·2 MIN READ·MAY 3, 2019

Cryptojacking has been an issue in the world of cryptocurrencies ever since digital assets started gaining traction. The streak of malicious crypto mining is still on the rise even as Coinhive, the infamous cryptocurrency mining script, shut down its services earlier this year.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
1Key sections mapped in this report
3Internal references connected to related coverage
1External source domains cited in the article
2 minEstimated time to read the full report

Malwarebytes has reportedly blocked over 200,000 requests to link to Coinhive, just one day after the service officially shut down on March 8, 2019. Malwarebytes also revealed that they had found out a new mining software called ‘WebMinePool,’ that targets the web routers which were the previous aim of the Coinhive script.

“Interestingly, we still detect thousands of blocks for Coinhive-related domain requests, even though the service announced it was shutting down on March 8. Over the past week, our telemetry recorded an average of 50,000 blocks per day.” – read the official release issued by Malwarebytes.

According to the website, the reason why these websites can still be infected is due to the fact that many of these pages never had the remnants of previous Coinhive attacks completely removed from their code. That meant that bits of the JavaScript code which was used to request data from the Coinhive library are still present in the pages, meaning that attackers can use this route to once again infect the website.

The threat of Coinhive’s legacy prompted Mozilla Firefox to address this issue after the popular browser issued a statement called ‘Protecting Against Fingerprinting and Cryptocurrency Mining Available in Firefox Nightly and Beta.’

“At Mozilla, we have been working hard to protect you from threats and annoyances on the web, so you can live your online life with less to worry about. Last year, we told you about adapting our approach to anti-tracking given the added importance of keeping people’s information on the web private in today’s climate.” – read the report issued by Mozilla.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: malwarebytes.com
  • Byline - Reported by Anca Florentis
  • Coverage Desk - Primary editorial category: News
  • Media Asset - Featured image served from the WordPress media library