Cryptojacking Explained: Hackers Using Your Computer to Mine Bitcoin


Your computer has been running slower than usual. The fan is spinning constantly, even when you’re not doing much. Your electricity bill crept up last month, and you’re not sure why. Your laptop feels warm to the touch more often than it used to.

You might assume it’s age. Maybe a Windows update running in the background. Maybe you just have too many tabs open.

But there’s another possibility most people never consider: someone else might be using your computer right now — without your knowledge, without your permission, and entirely for their own financial gain.

This is called cryptojacking, and it’s one of the most widespread cyberthreats that almost nobody talks about.

Unlike ransomware, it doesn’t lock your files. Unlike spyware, it doesn’t obviously announce itself. It just sits quietly on your device, burning through your processor, draining your battery, hiking up your power bill, and potentially shortening the lifespan of your hardware — all while generating cryptocurrency for a stranger on the other side of the world.

This article explains exactly what cryptojacking is, how it gets onto your devices, how to tell if you’re already a victim, and what to do about it. No technical background required.


Crypto currency, mining farm, block chain, growth of profit isometric composition on violet background vector illustration

What Is Cryptojacking? (Clear Definition)

Cryptojacking is the unauthorized use of someone else’s computer, phone, or other device to mine cryptocurrency. Attackers secretly install mining software — or run it through a web browser — that hijacks your device’s processing power to solve complex mathematical problems, generating cryptocurrency that goes directly to the attacker.

To understand why this is worth doing from an attacker’s perspective, you need a brief, jargon-free explanation of cryptocurrency mining.

Cryptocurrencies like Bitcoin and Monero don’t have a central bank printing new coins. Instead, new coins are generated through a process called mining — where computers compete to solve extremely complex mathematical puzzles. The first computer to solve the puzzle gets rewarded with newly created cryptocurrency.

Solving these puzzles requires enormous computing power. Running that computing power requires expensive hardware and significant electricity. For a legitimate miner, this is a real investment with real costs.

Cryptojackers have found a way around those costs: use other people’s computers. By spreading mining software across thousands or even millions of devices, they aggregate massive computing power without paying a cent for hardware or electricity. The victims absorb all the costs. The attacker collects all the profits.

It’s effectively theft — not of your files or your money directly, but of your device’s resources and your electricity.


How Big Is the Cryptojacking Problem?

Bigger than most people realize.

Cryptojacking surged alongside the cryptocurrency boom and has remained a persistent, evolving threat. Security researchers at firms including Symantec, SonicWall, and Kaspersky have consistently ranked cryptojacking among the most frequently detected malware types globally.

At its peak in 2018, cryptojacking scripts were found running on hundreds of thousands of websites simultaneously — including, in one notable documented case, on the websites of the Los Angeles Times and several government portals across the US and UK. These sites had been compromised without their owners’ knowledge, and every visitor who landed on those pages had their device temporarily recruited into the attacker’s mining operation.

The shift toward mining Monero (rather than Bitcoin) made cryptojacking even more attractive to attackers. Monero is specifically designed to be mined on regular consumer hardware — no specialized mining rigs required — and its privacy features make transactions harder to trace. Your laptop or desktop is genuinely useful for mining Monero in a way it simply isn’t for Bitcoin anymore.

The threat never went away. It evolved. Today’s cryptojacking operations are more sophisticated, better hidden, and targeting a wider range of devices — including smartphones, smart TVs, and cloud servers.


Hidden mining abstract concept vector illustration. Cryptocurrency mining method, miner bot, secret web program, hidden embed script development, security, blockchain technology abstract metaphor.

How Cryptojacking Gets Onto Your Device

There are two primary delivery methods, and understanding both helps you protect yourself against each.

Method 1: File-Based Cryptojacking (Malware)

This works similarly to other malware infections. You download or run a file that secretly installs a cryptocurrency miner on your device. The miner then runs persistently in the background — often disguised as a legitimate system process — every time your computer is on.

Common delivery routes include:

  • Phishing emails with malicious attachments or links — the same vectors used for ransomware, often running both threats simultaneously on infected machines
  • Trojanized software downloads — free applications, game mods, pirated software, or utilities downloaded from unofficial sources that bundle a miner with the main install
  • Malicious browser extensions that install a miner while appearing to offer useful functionality
  • Exploit kits that probe your browser or plugins for vulnerabilities and silently install the miner without any interaction

File-based cryptojacking is more persistent than browser-based attacks — it survives reboots and continues running even when you’re not browsing the web. It’s the more serious of the two forms.

Method 2: Browser-Based Cryptojacking (In-Browser Mining)

This variant requires no download at all. Malicious JavaScript code is embedded in a webpage, and when you visit that page, the script runs directly in your browser — immediately commandeering your device’s CPU to mine cryptocurrency for as long as you have the tab open.

Close the tab, and the mining stops. No persistent infection, no installed files.

This sounds less serious, but the scale makes it significant. A popular website with millions of daily visitors can generate substantial mining revenue for an attacker even if each individual session only lasts a few minutes. And as noted above, even legitimate, high-traffic websites have been compromised to serve these scripts without their owners’ knowledge.

Some website owners have also used in-browser mining intentionally — framed as an alternative to advertising, where users “pay” for free content by contributing computing power. The ethical debate around consensual mining is real, but what we’re discussing here is the unauthorized version, which is unambiguously theft.


How to Tell If Your Device Has Been Cryptojacked

This is where cryptojacking gets tricky. By design, it’s meant to stay hidden. But it’s not invisible — it leaves detectable traces if you know what to look for.

Performance symptoms:

  • Your computer runs noticeably slower than usual, even for simple tasks
  • The CPU fan runs constantly or at unusually high speeds, even when the computer appears idle
  • Your device runs hot to the touch more frequently than before
  • Applications take longer to open or respond
  • Your browser slows down significantly on certain websites or in general

Battery and power symptoms:

  • Your laptop battery drains much faster than it used to
  • Your electricity bill has increased without a clear explanation
  • Your device struggles to maintain charge even on light usage

Task Manager signals (Windows):

Open Task Manager (press Ctrl + Shift + Esc) and look at the CPU column. Normal background processes on an idle computer should use a small fraction of your CPU — typically under 10–15% in aggregate. If you see CPU usage consistently at 80–100% when you’re not running anything demanding, something is consuming those resources.

Look for processes you don’t recognize with high CPU usage. Right-click any suspicious process and search the name online to determine whether it’s legitimate. Cryptomining processes are sometimes disguised with names that resemble legitimate Windows processes — “svchost.exe” is a real Windows process, but malware frequently mimics that naming pattern.

Browser-specific signals:

If the slowdown happens primarily in your browser, open your browser’s built-in task manager. In Chrome, go to Menu → More Tools → Task Manager. Look for tabs or extensions consuming unusually high CPU. A tab showing 80%+ CPU usage when it’s just a news article or simple webpage is a red flag.

On mobile devices:

Smartphones can be cryptojacked too, though their processors are less valuable to attackers. Signs include unusual battery drain, the device running hot, and data usage spiking unexpectedly. These symptoms have other possible causes, but if multiple appear together, cryptojacking is worth investigating.


Real-World Examples Worth Knowing About

The Coinhive Era

The most significant chapter in cryptojacking history involves a service called Coinhive, which launched in 2017. Coinhive provided a JavaScript mining script that website owners could embed — framed as a revenue alternative to advertising. The idea wasn’t inherently malicious.

But the script was almost immediately weaponized by attackers who injected it into compromised websites without the owners’ knowledge. At its height, Coinhive’s script was detected on hundreds of thousands of websites. Security firm Malwarebytes ranked it as the most commonly detected malicious threat globally for multiple consecutive months. Coinhive eventually shut down in 2019 when Monero’s value dropped and made the operation less profitable — but the techniques it pioneered remain in use through successor scripts.

The Government Website Compromises

In 2018, a security researcher discovered that a widely-used accessibility plugin called Browsealoud — installed on thousands of government and public sector websites across the US, UK, and Australia — had been compromised to serve a Coinhive mining script. Every visitor to those government sites had their browser hijacked for mining without any indication anything unusual was happening. This case illustrated that even institutional, trusted websites could become cryptojacking vectors through their third-party components.

Cloud Infrastructure Attacks

More recently, cryptojacking has evolved to target cloud servers — where the computing resources are far more powerful than consumer devices. Attackers compromise misconfigured cloud instances and deploy industrial-scale miners. Google’s own threat intelligence team documented a surge in cloud cryptojacking attacks, noting that compromised cloud instances were being put to work within seconds of being breached. This mostly affects businesses, but it’s a reminder of how seriously the security community takes this threat.


Cryptojacking vs. Ransomware: Key Differences

People sometimes confuse cryptojacking with ransomware because both involve malware and cryptocurrency. They’re actually quite different in intent, method, and impact.

Ransomware wants your attention — it announces itself loudly, demands action, and creates an immediate crisis. Cryptojacking wants the opposite. Its entire value depends on you not knowing it’s there. The moment you detect and remove it, the attacker loses their revenue stream from your device.

Ransomware is a one-time hit. Cryptojacking is designed for long-term passive income. An attacker would rather quietly earn from your device for months than trigger a single dramatic event that prompts you to wipe your system.

The damage profiles also differ. Ransomware can cause immediate, catastrophic data loss. Cryptojacking causes gradual, cumulative harm — degraded performance, increased power costs, accelerated hardware wear, and shortened device lifespan. The financial damage to individual victims is typically lower, but multiplied across thousands or millions of devices, the attacker’s gains are substantial.

Both threats use many of the same delivery mechanisms — phishing, malicious downloads, drive-by exploits — which is why protection against one tends to overlap significantly with protection against the other.


How to Remove Cryptojacking Malware

If you suspect your device is currently being used for cryptomining, here’s a clear action plan.

For browser-based cryptojacking:

Start simple. If you notice the symptoms primarily while browsing, close the suspicious tab. If your computer performance returns to normal, the culprit was likely a browser-based mining script on that page.

Next, audit your browser extensions. Go to your browser’s extension settings and remove anything you don’t recognize, don’t actively use, or didn’t deliberately install. Extensions accumulate over time and represent a real attack surface.

Clear your browser cache. Some persistent browser-based miners store themselves in cached data and attempt to reload even after the original tab is closed.

For file-based cryptojacking:

Run a full system scan with a reputable antivirus program. Most established security tools now detect common cryptomining malware — it’s a well-documented threat family and appears in most malware signature databases.

If your current antivirus comes back clean but you’re still experiencing symptoms, consider running a second-opinion scan with a dedicated malware removal tool. Sometimes a fresh scan with different detection logic catches things a primary tool missed.

Check your Task Manager carefully for processes consuming abnormal CPU resources. Research any unfamiliar processes. If you find one confirmed as a cryptominer, note its location before your antivirus removes it.

In severe cases — particularly where the miner has installed itself deeply into system processes — a clean reinstall of your operating system is the most reliable path to certainty. This is the same advice that applies to ransomware, and for the same reason: a system you can’t fully trust is a liability.

Our malware removal guide walks through the full removal process step by step for users who want more detailed guidance.


How to Protect Yourself From Cryptojacking Going Forward

The good news: the defenses against cryptojacking are practical, accessible, and largely overlap with good general security hygiene.

Install reputable antivirus with real-time protection. The most direct defense against file-based cryptojacking is security software that detects mining malware before it installs or while it’s running. Behavioral detection — which flags processes consuming abnormally high CPU resources — is particularly effective here, since it can catch new mining variants even before they’re in signature databases. We’ve tested how leading antivirus programs handle cryptomining threats, and the differences between products are real and meaningful.

Use a browser extension that blocks mining scripts. Several extensions specifically target in-browser cryptojacking — tools like NoCoin or minerBlock maintain lists of known mining scripts and block them from executing. uBlock Origin, a widely-used ad blocker, also blocks most known mining scripts as part of its broader filtering. These are free, lightweight, and highly effective against browser-based attacks.

Keep everything updated. Browser-based cryptojacking frequently exploits vulnerabilities in outdated browsers and plugins. Keeping your browser, operating system, and all software current closes the doors that drive-by cryptojacking exploits most commonly use.

Be cautious about what you install. The same rules that protect against ransomware apply here: only download software from official sources, avoid pirated content, review browser extensions carefully, and never disable your security software as part of an installation process.

Monitor your CPU usage periodically. You don’t need to check constantly, but making a habit of occasionally glancing at your Task Manager gives you early warning if something unexpected is consuming your resources. Set a mental baseline for what your CPU usage looks like at idle — anything significantly higher than that baseline without an obvious explanation is worth investigating.

Use a VPN on public networks. Public Wi-Fi creates additional exposure to man-in-the-middle attacks that can inject malicious scripts into your browsing session. A VPN encrypts your traffic in a way that blocks this specific vector. See our VPN reviews for options that balance strong protection with ease of use.

On mobile: Only install apps from official app stores. Google Play and the Apple App Store both have screening processes — imperfect, but meaningful — that unofficial sources lack. Be particularly skeptical of apps that request unusual permissions or drain your battery unexpectedly after installation.


Common Myths About Cryptojacking

Myth: “Only high-powered gaming computers are worth targeting.”

Attackers aren’t looking for individually powerful machines — they’re looking for volume. Your average laptop contributes a small amount of mining power, but when multiplied across thousands of similarly compromised devices, it adds up to a profitable operation. No computer is too modest to be worth targeting.

Myth: “Macs don’t get cryptojacked.”

Cryptojacking malware for macOS has been documented and actively circulates. The macOS platform’s growing market share has made it a more attractive target over time. Mac users who assume they’re safe without security software are taking an unjustified risk.

Myth: “Browser-based cryptojacking is harmless because it stops when I close the tab.”

The impact on your device is real even during a short session — CPU stress, battery drain, and heat generation all occur while the script runs. Repeated exposure across multiple browsing sessions compounds the wear on your hardware. And not all “browser-based” miners actually stop when the tab closes — some use service workers or other techniques to persist briefly after tab closure.

Myth: “If my antivirus hasn’t flagged anything, I’m clean.”

Antivirus is effective but not infallible. Some cryptominers disguise themselves well enough to evade signature-based detection, particularly newer variants. Behavioral symptoms — unexpected high CPU usage, abnormal heat, battery drain — remain important signals even when your security software hasn’t raised an alarm.


When You Actually Need Better Protection

Free antivirus and Windows Defender provide some coverage against known cryptojacking malware, but they have gaps — particularly against newer variants and sophisticated browser-based attacks.

If any of these apply to you, the case for a paid security solution becomes clear:

  • Your device regularly feels slow or hot without obvious reason
  • You spend significant time browsing varied or unfamiliar websites
  • You download software or media frequently
  • You use your device for work involving sensitive data
  • You’ve experienced any malware infection in the past
  • You want protection that actively monitors CPU anomalies in real time

Premium antivirus suites typically include web protection that blocks malicious mining scripts at the network level — before they even reach your browser. Combined with behavioral monitoring that flags abnormal CPU usage, this creates a two-layer defense that free tools generally can’t match.

Our breakdown of free vs paid antivirus covers exactly where the protection gaps lie, if you want to make an informed comparison.


The Honest Bottom Line

Cryptojacking doesn’t make headlines the way ransomware does. It won’t lock your files, flash a threatening message, or demand immediate action. It’s designed to be invisible — and for a long time, that invisibility has allowed it to thrive at enormous scale.

But invisible doesn’t mean harmless. Stolen processing power is still theft. A device running hotter and harder than it should be ages faster. An electricity bill that’s higher than it should be costs real money over months and years. And a device already compromised by one piece of malware is a device that’s demonstrated a vulnerability — one that other threats can exploit.

The defenses are practical and largely free. Keep your software updated. Use a browser extension that blocks mining scripts. Install security software with real-time protection. Pay attention to what your CPU is doing.

Cryptojacking depends on victims who don’t notice and don’t act. Now you know what to look for. That changes the equation significantly.

If you’re not sure your current protection covers cryptojacking and the other threats that use the same delivery methods, it’s worth taking a few minutes to check. Our antivirus comparison guide shows you exactly what the leading options detect and block — including cryptomining threats — so you can make a confident, informed decision.


Frequently Asked Questions

What is cryptojacking in simple terms? Cryptojacking is when someone secretly uses your computer, phone, or other device to mine cryptocurrency without your permission. Malicious software or browser scripts hijack your device’s processing power to generate digital currency for the attacker, while you experience the side effects — slower performance, higher electricity bills, overheating, and accelerated hardware wear.

Can cryptojacking damage your computer? Yes, over time. Cryptocurrency mining pushes your CPU to run at high capacity for extended periods, generating significant heat and putting sustained stress on hardware components. This can shorten the lifespan of processors and cooling systems, degrade battery health in laptops and phones, and cause thermal throttling that permanently affects performance. It won’t cause immediate catastrophic damage, but sustained exposure takes a measurable toll.

How do I know if my computer is mining cryptocurrency? Open Task Manager (Ctrl + Shift + Esc on Windows) and check CPU usage while the computer is idle or running only light tasks. Normal idle CPU usage is typically under 10–15%. If it’s consistently much higher — especially at 80–100% — with no obvious explanation, something is consuming those resources. Also watch for constant fan activity, unusual heat, and rapid battery drain on laptops and phones.

Does closing the browser stop cryptojacking? For simple browser-based cryptojacking, closing the tab stops the mining script. However, some advanced variants use browser service workers or other persistence techniques to continue briefly after tab closure. File-based cryptomining malware runs independently of your browser entirely and continues regardless of your browsing activity.

Can smartphones be cryptojacked? Yes, though they’re less commonly targeted than computers because their processors are less powerful. Android devices are more vulnerable than iPhones due to Android’s more open app ecosystem. Signs include unusual battery drain, the device running warm, unexpected data usage, and general sluggishness. Sticking to official app stores and keeping the operating system updated are the primary defenses.

Is cryptojacking illegal? In most jurisdictions, yes. Unauthorized use of someone else’s computing resources constitutes a form of computer fraud or unauthorized access — criminal offenses under laws like the Computer Fraud and Abuse Act in the US and equivalent legislation in other countries. Even browser-based cryptojacking, which involves no persistent infection, involves unauthorized execution of code on a visitor’s device without consent.

What’s the best way to prevent cryptojacking? A combination of approaches works best: install reputable antivirus with real-time behavioral monitoring, add a browser extension that blocks known mining scripts (uBlock Origin or dedicated tools like minerBlock), keep all software and browsers updated, avoid downloading software from unofficial sources, and periodically check your CPU usage for unexplained spikes. No single measure is perfect, but together they make cryptojacking your device significantly more difficult.

Leave a Reply

Your email address will not be published. Required fields are marked *