
Crypto Miner (Coinhive) in YouTube Ads
During normal browsing on YouTube, at some point, the antivirus Avast reported something that was not good
During normal browsing on YouTube, at some point, the antivirus Avast reported something that was not good. From the Chrome Inspector it appeared that one of the ads was infected and tried to load a crypto miner from Coinhive.
Everything has been reported to Google.
Without answer. Well done, Google.
What Coinhive was
Coinhive was a service that provided a JavaScript snippet to mine the Monero cryptocurrency directly in a site visitor’s browser, using their CPU. It launched as a “legitimate” alternative to ads (have the visitor mine instead of showing them banners), but was quickly weaponized: inject it — into a compromised site or, as in this case, into an ad — and visitors would start mining without knowing it, CPU pinned at 100% and laptop fans spinning up.
How it ended up in the ads
Ad networks like Google Ads accept creatives (often simple HTML/JS tags) from thousands of different advertisers. It only took one malicious advertiser slipping past automated review with an ad that, once loaded, injected the mining script — and millions of users ended up mining Monero for someone else without knowing it. The phenomenon, known as cryptojacking, hit numerous major sites and ad networks in 2017-2018, not just YouTube.
How it played out
Coinhive shut down in March 2019, after Monero’s value collapsed and antivirus software, ad blockers (uBlock Origin), and dedicated extensions like NoCoin adopted widespread blocking — the same pressure that ultimately made its business model unsustainable.

Co-Founder & CTO at PAPION. Senior full-stack engineer specializing in React, TypeScript, Node.js, and application security.