Diego Betto
Coinhive Miner inside YouTube ads

Diego Betto · January 25, 2018 · 1 min di lettura

Crypto Miner (Coinhive) in YouTube Ads

During normal browsing on YouTube, at some point, the antivirus Avast reported something that was not good

Condividi:XLinkedInFacebookWhatsApp

During normal browsing on YouTube, at some point, the antivirus Avast reported something that was not good. From the Chrome Inspector it appeared that one of the ads was infected and tried to load a crypto miner from Coinhive.

Everything has been reported to Google.

Without answer. Well done, Google.

The original tweet

What Coinhive was

Coinhive was a service that provided a JavaScript snippet to mine the Monero cryptocurrency directly in a site visitor’s browser, using their CPU. It launched as a “legitimate” alternative to ads (have the visitor mine instead of showing them banners), but was quickly weaponized: inject it — into a compromised site or, as in this case, into an ad — and visitors would start mining without knowing it, CPU pinned at 100% and laptop fans spinning up.

How it ended up in the ads

Ad networks like Google Ads accept creatives (often simple HTML/JS tags) from thousands of different advertisers. It only took one malicious advertiser slipping past automated review with an ad that, once loaded, injected the mining script — and millions of users ended up mining Monero for someone else without knowing it. The phenomenon, known as cryptojacking, hit numerous major sites and ad networks in 2017-2018, not just YouTube.

How it played out

Coinhive shut down in March 2019, after Monero’s value collapsed and antivirus software, ad blockers (uBlock Origin), and dedicated extensions like NoCoin adopted widespread blocking — the same pressure that ultimately made its business model unsustainable.

Condividi:XLinkedInFacebookWhatsApp
Diego Betto

Written by

Diego Betto

Co-Founder & CTO at PAPION. Senior full-stack engineer specializing in React, TypeScript, Node.js, and application security.