Once hailed as a revolutionary way to monetize websites without ads, Coinhive became one of the most controversial names in crypto history. What started as a clever JavaScript tool for mining Monero through visitors' browsers quickly spiraled into a global cryptojacking epidemic — and ultimately ended with its creators shutting the whole thing down.
What Was Coinhive and How Did It Work?
Coinhive was a JavaScript-based mining service launched in 2017 that allowed website owners to earn cryptocurrency by using their visitors' CPU power. Instead of relying on banner ads or paywalls, publishers could embed a small script that would run the Cryptonight hashing algorithm — the same algorithm used by Monero — directly in the browser.
The pitch was simple: drop a few lines of code, and your site mines XMR in the background while users browse. Visitors didn't need to install anything, and the mining intensity could be throttled. For many small publishers tired of intrusive advertising, Coinhive looked like the future of web monetization.
Under the hood, the service pooled hashing power from thousands of sites, paid out in Monero, and charged a small fee for the convenience. It was technically impressive — and legally murky from day one.
The Rise of Browser Mining and Its Appeal
Before Coinhive, browser-based mining existed only as a curiosity. The arrival of a polished, easy-to-deploy service changed the conversation overnight. Several legitimate publishers experimented with it as an ad alternative, framing it as a fair trade: you get free content, the site gets a tiny slice of your CPU.
Key reasons it caught on so quickly:
- Zero friction — no wallets, installs, or signups required for end users.
- Monero's privacy features made mining payouts untraceable, which attracted both legitimate and shady operators.
- Ad fatigue drove publishers to look for less intrusive revenue models.
- Easy integration — a single script tag was enough to get started.
For a brief window in late 2017 and early 2018, Coinhive felt like a glimpse of a new web economy — one where users paid with compute instead of attention. The reality, however, got ugly fast.
Cryptojacking: When Coinhive Went Rogue
Almost immediately, cybercriminals began injecting the Coinhive script into compromised websites without owners' knowledge. Visitors would notice their fans spinning, batteries draining, and CPUs pinned at 100% — all to mine Monero for someone else. This malicious practice earned its own name: cryptojacking.
High-profile victims included government sites, university portals, and even a Los Angeles Times page. Security researchers eventually uncovered massive campaigns using Coinhive's code to mine millions of dollars worth of XMR across millions of infected browsers.
Coinhive single-handedly popularized cryptojacking — and also became the symbol of everything wrong with consent-less browser mining.
Even when the script ran with partial consent, users often had no idea their hardware was being used. Critics argued the opt-in model was deliberately obscure, with mining sliders hidden deep in settings pages. Antivirus vendors began flagging Coinhive as a trojan, and browsers scrambled to throttle or block the service entirely.
The Shutdown and What Replaced It
In February 2019, the Coinhive team announced it would shut down the service, citing the collapse of Monero's price, the flood of abuse, and the hammering blow of a 2018 hack that drained a significant chunk of its payout wallet. By March 2019, the mining script stopped working entirely.
The closure didn't end cryptojacking — it just sent it underground. New variants emerged using modified code, private mining pools, and proxy services designed to evade detection. Today, browser-based mining has largely fragmented into:
- Open-source alternatives built by smaller communities for niche use cases.
- Malware strains that borrow the same concept but operate covertly.
- Web3 experiments that repackage the idea under user-consent frameworks.
Coinhive's legacy is twofold: it proved that browser mining can work technically, and it showed the crypto industry just how easily a good idea can be weaponized at scale.
Key Takeaways
Coinhive was a genuinely innovative product that got buried by its own abuse problem. It pushed the conversation around user consent, CPU economics, and ad-free monetization — but it also armed cybercriminals with an easy tool for mass cryptojacking.
- Coinhive launched in 2017 and shut down in March 2019.
- It mined Monero using a JavaScript snippet embedded in websites.
- It fueled the first major wave of browser-based cryptojacking attacks.
- The closure reflected both market pressure and the cost of running an abuse-prone service.
- Its concept lives on in Web3 monetization experiments and modern malware.
Even years after the servers went dark, Coinhive remains a cautionary tale for any crypto project that scales faster than its safeguards.
Zyra