UPDATED 23:10 EDT / OCTOBER 15 2017

INFRA

Cryptomining hijacking goes mainstream, affecting up to 500M users

More and more sites are secretly hijacking the computer processing power of visitors to mine for cryotocurrency as a report over the weekend identified Politifact among the latest sites to be targeted.

Overall, according to one ad blocking company, the process is now so widespread that hundreds of millions of people now encounter dubious cryptomining scripts daily.

Politifact, a fact-checking site run by the Tampa Bay Times, was discovered to be using the Coin Hive JavaScript injection code. That first came to light in September in a report by TechCrunch, but the site has now removed the code “and is looking into how it got there.”

That news coincided with a report from AdGuard that claims that the spread of sites using cryptominers is ballooning. Some 220 of the top 100,000 websites online now using cryptomining JavaScript injections, with those sites earning $43,000 in cryptocurrency by running the code.

Coin Hive had been the only cryptomining code provider fingered in previous examples of cryptomining hijacking, but AdGuard also detected that three new companies have entered the fray: JSECoin, Crypto Loot and MineMyTraffic. The report claimed that cryptomining has gone “viral” and that about 500 million people may have been exposed to cryptomining code to date, with the figure likely continuing to rise.

Backing the same conclusions made by RiskIQ Inc. in its report on the rise of cryptomining late September, AdGuard noted that many of the sites using cryptomining code sit in the “gray zone,” mostly pirate TV and video sites, Torrent trackers and porn websites.

Unsurprisingly, not everyone is fond of the idea that websites should be serving code to visitors, without permission, that hijacks their computing power to mine for cryptocurrency. Earlier this month, content delivery network provider Cloudflare Inc. was the first major service provider to ban sites using cryptomining scripts, saying the code could be malware and therefore a breach of its terms and conditions.

Given the growing spread of the method, anyone who uses a web browser should be concerned at this point. So far ad blockers, such as Adblock Plus, offering cryptomining blocking built in, while Google Chrome users can also obtain an add-on to block them via this link.

Photo: Pixabay

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.