Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Make Crypto Mining through a Browser a Legal Business current page
Link copied

Make Crypto Mining through a Browser a Legal Business

Mar 12, 2018
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
Make Crypto Mining through a Browser a Legal Business
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Crypto Mining

Threat actors are making millions by stealing your CPU cycles for crypto mining when you visit an infected or malicious website. In fact, the trend is growing and users may not even be aware that their resources are being leveraged against them for someone else’s financial gain. So why not make this practice legal and have legitimate browser extensions or software perform this work in lieu of the methods websites make money today through banners, ads, and subscriptions? This might be the next big thing for content rich sites that use your computer to make money versus selling space and paying search engines. Think it is crazy, read on.

How Content on the Internet Works

Think of your favorite websites – anything from social media apps to news sites. Now, think of your streaming websites and sports. The former are laced with sponsors, ads, and promotions that are paid for by businesses and individuals to support the development and security of the platform and ultimately the business itself. As a user, these sites are typically free but in order to make money, they have to sell real estate in order to function. Streaming content providers (including entertainment and sports) however make their money from subscriptions. This is generally an annual or monthly rate to subsidize the royalties they pay for content or production of their own material. This is how the content on the Internet works. We pay to review the material or someone else pays to advertise material. I think there is room for another option.

Crypto Mining Defined

First, let us define crypto mining. Crypto mining is the process of solving complex problems to verify digital transactions or other mathematical problems using computer hardware and dedicated computational software. Miners can either create a cryptocurrency or get paid for their processing power in a cryptocurrency once mathematical problems have been solved and verified using affiliate technology like Blockchains. In order to be successful, micro processing (CPU or preferred graphical processing power) is needed and the average computer, phone, and streaming device sits idle throughout the day or is not fully utilized when services are rendered. This leaves room for spare CPU cycles to be implemented for this type of project.

The Value of CPU Cycles

Now, let us continue with the value of CPU cycles. A single CPU cycle represents a financial loss or gain based on the on the work processed. If you consider the cost of the initial system, amortized depreciation, maintenance costs, and monthly electric and cooling costs, each CPU cycle literally can be translated into some dollar value. While this would be infinitely small based on modern CPU clock speeds, the cost realization per hour, day, or month is something we reconcile every day; especially when licensing CPU power from shared and cloud resources. Therefore, CPU time has a value and the goal of legal crypto mining is to offset the purchase and operational cost of the CPU and to perform the work in the background of legitimate services.

The result to the consumer is a free or discounted subscription fee or the need for the provider not to market and sell advertisements. If the initial costs are not in a mining farm, but rather from someone else’s environment, the profit ratio can be easily be biased towards the mining and content operator.

Why Illegal Crypto Mining is Popular

This is why illegal crypto mining is becoming so popular – because threat actors are making money using some else’s investment. The real objective is to turn this around and allow for real services to perform the same work while consumers use their resources. Large scale crypto mining for the provider and no subscription fees or advertisements (commercials) for the consumer. A win – win situation for both and crypto mining might just be the first step for other businesses to leverage spare CPU cycles from idle devices. In addition, the more time you spend using the service (like binge watching a TV show), the more CPU time the provider gets in the background to support the model.

All it would take is enabling an application to use background CPU for a purpose and the consumer to accept an end user license agreement (EULA) that grants the content provide to use a fraction of their resources for an additional purpose.

A Real Example of How This Could Work

If you think this entire scenario is far-fetched, the technology already exists to make this work. The University of Berkley has open source software for volunteer computing called BOINC. The technology uses the idle time (or spare time) on your computer to cure diseases, study global warming, discover pulsars, look for alien radio signals, and do many other types of mathematically intensive scientific research. There is no reason the same approach cannot be used for crypto mining or adopted by content providers to use spare resources along with their services to solve many of these humanitarian problems the world faces today. Imagine streaming a movie and spare CPU cycles are looking for a cure to a genetic disease or predicting the weather. Sitting on the couch could actually be proven to be productive.

Whether this concept actually becomes reality is to be seen. It might be another form of digital transformation or maybe it is just a glimpse into the future. In either case, organizations will still need to determine if CPU cycles are being used for legitimate business purposes, for someone else’s financial gain, or for potential malicious activity. A vulnerability assessment is a good way to determine if your assets are at risk for malicious activity and if your browsers could be hijacked today for illegal crypto mining. For more information on how Retina CS could help perform these assessments, contact us. Otherwise, stay tuned. The services you utilize today might end up solving some of the world’s most mathematically challenging problems while you sit on the couch.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Active Directory Security Explained & 7 Active Directory Best Practices 
    Dec 9, 2018 Active Directory Security Explained & 7 Active Directory Best Practices 
    Blog
    1m
  • Identity Management is Best in Enterprise Security
    Mar 14, 2012 Identity Management is Best in Enterprise Security
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.