Coinhive Hacked: A Hacker Took Everything Mined for Hours
Coinhive

The popularity of Coinhive exploded thanks to The Pirate Bay's decision to activate a background miner. Hundreds of portals decided to follow the same path, either legitimately or completely covering their intentions. However, the service's administrators have learned the hard way that they need to strengthen their security. An attacker managed to get into Coinhive's DNS provider using an old password that was never changed, and redirected hashes to a private server for a period of six hours. It is unknown how much money was stolen.

Adopting online services has its risks. A security error by administrators, and millions of passwords appear on the Web. One of the most recent and striking examples is the attack on Yahoo!. All of the provider's accounts were compromised, and the worst part is that users found out several years later. Basically, no service is safe, and that includes the new generation of JavaScript miners. The victim this time is Coinhive, chosen by portals like The Pirate Bay to obtain Monero.

Coinhive Hacked: A Hacker Took Everything Mined for Hours
The hash theft lasted six hours

On the night of October 23, Coinhive's administrators detected unauthorized access to their DNS provider's account, CloudFlare. The attacker manipulated coinhive.com's domain records, with the aim of redirecting all requests for coinhive.min.js to an external server. That server held a malicious version of the JavaScript file that essentially enabled hash theft for a period of six hours. How did the hacker get into Cloudflare? Very simple: Coinhive's administrators reused the same credentials that were leaked in the Kickstarter attack a couple of years ago. The passwords from that leak were encrypted, so the hypothesis points to a particularly weak password, vulnerable to a brute force process.

Coinhive insists that no personal information was stolen, and the next step is to implement a compensation system for affected users, issuing a 12-hour credit based on their average daily hashrate. It might be enough, but there is no doubt left: Online miners are a target.

Official announcement: Coinhive blog