Coinhive was a browser-based JavaScript service that mined Monero using visitors’ CPU cycles. Its code became widely associated with cryptojacking: secretly using a website visitor’s computing resources without meaningful consent. Check Point ranked it the most prevalent malware in its January 2018 threat report, but Coinhive shut down on March 8, 2019, so that ranking describes a past period—not a current threat ranking.
What Coinhive was and how cryptojacking worked
Coinhive provided JavaScript that could run in a visitor’s browser and use the computer’s processor to mine Monero. Mining pools combine computing power from many machines; more participating CPUs can improve the chance of successfully mining cryptocurrency, which helps explain why attackers sought to make other people’s computers participate. Check Point threat-intelligence researcher Lotem Finkelsteen described the incentive: “Thus threat actors work to recruit as many CPUs as they can to their mining pools; and why not using random CPUs of website users?” (CyberScoop, January 16, 2018)
Coinhive itself was a mining service; cryptojacking describes its unauthorized use. In malicious deployments, attackers placed its code on compromised websites or otherwise caused it to run without visitors’ informed authorization. This differed from a disclosed, optional arrangement in which a site clearly told visitors what resources would be used and obtained their agreement.
What the “most prevalent” ranking meant
CyberScoop reported on January 16, 2018, that Check Point had identified Coinhive as the most prevalent malware online at that time. That is a dated ranking, not a measure of every infected website or a claim that Coinhive remains active. Check Point later reported Coinhive had held the top spot in its global threat index for 15 successive months through February 2019. (Check Point Research, 2019)
#1 Best Overall
Other measurements describe different things and should not be conflated with a threat-index ranking. A USENIX Security study crawled 49 million domains and found cryptojacking on 0.011% of them. Within the period it examined, Coinhive had a larger installation base than CoinImp, while CoinImp WebSocket proxies were digesting significantly more traffic in the second half of 2018. Installation counts, traffic, and a vendor’s prevalence ranking are distinct measures. (USENIX Security, 2019)
What unauthorized mining could do to a computer
A browser miner consumes processor capacity while it runs. CyberScoop reported that cryptojackers could use up to 100% of a target’s CPU, potentially slowing or crashing other processes and increasing electricity use. (CyberScoop, January 16, 2018) Malwarebytes’ post-shutdown analysis likewise described browser miners driving CPU usage to its maximum while a tab was open. (Malwarebytes)
Rank #2
For a person using a laptop or desktop, high processor demand can mean sluggish applications, heat, fan noise, and greater power consumption. The exact effect depends on the device and workload; the cited reports establish the possibility of severe CPU use, not a fixed electricity cost or a universal performance impact.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Coinhive’s shutdown and what remained afterward
Coinhive ceased operation on March 8, 2019, after the service said it was no longer economically viable, according to Check Point Research. (Check Point Research, 2019) The shutdown ended Coinhive’s service, but it did not immediately remove every copy of its script from websites or network devices.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Malwarebytes observed that some websites and routers still contained Coinhive-related JavaScript after the closure. Their requests were blocked, but failed connections meant those remnants were not actively mining through Coinhive. (Malwarebytes)
Cryptojacking did not disappear with Coinhive. ENISA reported a 78% drop in web-based cryptojacking hits during the second half of 2019 after the service closed, indicating a sharp decline rather than an end to the broader practice. (ENISA, 2020)
Quick Recap
Best Value
What to take away from Coinhive’s history
- Coinhive was browser-based JavaScript for Monero mining; its code was frequently abused to mine without meaningful visitor consent.
- Its top-prevalence status was reported in 2018 and persisted in Check Point’s index through February 2019; it is not a current ranking.
- The mining could consume extreme CPU resources, affecting device performance and electricity use.
- The service closed on March 8, 2019, while other miners and residual scripts continued to exist afterward.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




