Back in 2017, a small JavaScript snippet promised to revolutionize how websites made money — and, for a while, it did. Coinhive turned ordinary visitors' CPUs into a silent cryptocurrency mining network, opening a heated debate about consent, security, and the future of web monetization that still echoes today.
What Was Coinhive?
Coinhive was a service launched in late 2017 that allowed website owners to embed a few lines of JavaScript into their pages. Instead of showing visitors ads, the script would use a portion of their device's processing power to mine Monero (XMR), a privacy-focused cryptocurrency favored for its CPU-friendly mining algorithm.
The pitch was seductive. Publishers struggling with ad-blockers and low CPMs could simply paste a snippet and start earning XMR. Coinhive took a roughly 30% cut, and operators kept the rest. For a brief moment, browser-based mining looked like a genuine alternative to the broken ad economy.
Why Monero, Not Bitcoin?
Monero's RandomX and earlier CryptoNight algorithms are designed to run efficiently on everyday CPUs, while Bitcoin mining has long since shifted to specialized ASIC hardware. That made XMR the only realistic coin for casual, in-browser mining — and Coinhive leaned into that advantage hard.
How Browser Mining Actually Worked
Technically, Coinhive was straightforward. A website would load the Coinhive miner.min.js script, allocate a percentage of the visitor's CPU (typically 20–50%), and start hashing blocks in the background. Earnings were proportional to the hashrate contributed and the time spent on the page.
For publishers, integration took minutes. For visitors, the experience was usually invisible — though anyone watching their task manager would notice a sudden spike in CPU usage. That invisible cost became the service's biggest problem.
- Zero install: No software downloads; everything ran in the browser.
- Wallet-based payouts: Earnings flowed to the operator's Monero wallet.
- Opt-in or opt-out: Coinhive offered a "captcha" mode where users could mine in exchange for skipping a CAPTCHA, a more transparent use case.
The Cryptojacking Backlash
Almost immediately, malicious actors hijacked the model. Hackers injected Coinhive scripts into compromised WordPress sites, browser extensions, and even Starbucks Wi-Fi pages, silently mining XMR on devices that never agreed to it. The practice earned a name: cryptojacking.
Security researchers watched Coinhive's network hashrate balloon, with huge chunks coming from clearly unauthorized sources. The backlash was swift:
- Major browsers and antivirus firms began flagging or blocking the script.
- The Pirate Bay, one of the most visible early adopters, faced user outrage after testing Coinhive without disclosure.
- Admins of Reddit and other platforms raced to scrub injected miners from their pages.
The fundamental issue wasn't the technology — it was consent. Mining on someone else's hardware without permission is closer to theft than innovation.
The Shutdown and Lasting Legacy
In March 2019, Coinhive announced it was shutting down, citing the collapse of Monero's price, a 50% network hashrate drop after the last algorithm change, and the broader damage to its reputation from cryptojacking abuse. The team urged users to withdraw their balances before the service went offline.
Coinhive's death didn't end browser-based mining, but it did end the mainstream experiment. Today, the concept survives mostly in two forms:
- Opt-in alternatives like Brave's Basic Attention Token, which reward users rather than the other way around.
- Malware-grade cryptojackers, which still occasionally surface in cracked plugins, pirated software, and vulnerable servers.
The episode also sharpened regulatory and legal thinking around unauthorized resource use. Several lawsuits and advisories referenced Coinhive directly, helping define what "consent" means in a Web3-shaped internet.
Key Takeaways
Coinhive was a short-lived but hugely influential chapter in crypto history. It showed that browser mining was technically possible, commercially fragile, and ethically dangerous when deployed without clear consent. For anyone building or investing in web monetization today, the lesson is clear: users will accept new revenue models only when the trade-off is transparent — and never at the cost of their device, their battery, or their trust.
Zyra