Skip to main content
Category: Cyber Threats & Attacks

Cryptojacking

Also known as: Malicious cryptomining, Cryptomining malware
Simply put

Cryptojacking is a type of cyberattack in which attackers secretly use someone else's computer or device to mine cryptocurrency without permission. The victim typically does not know it is happening, while their device's processing power and electricity are consumed to generate cryptocurrency for the attacker. It can occur through malware installed on a device or through code embedded in websites.

Formal definition

Cryptojacking is the unauthorized exploitation of a victim's computing resources to mine cryptocurrency, carried out against the user's will or without their awareness. Delivery vectors typically include malware that infects endpoints, servers, or cloud infrastructure, as well as browser-based scripts executed when a user visits a compromised or malicious website. The attacker hijacks CPU, GPU, or broader compute capacity to perform mining operations, imposing costs on the victim in the form of degraded performance, increased resource consumption, and, in cloud environments, elevated infrastructure charges. This entry addresses cryptojacking as a security threat concept and does not by itself determine whether resulting losses are insurable; coverage would depend on the specific policy wording, applicable exclusions, and jurisdiction.

Why it matters

Cryptojacking is often characterized as a lower-severity threat than ransomware or data theft because it does not typically destroy data or extort payment. That framing can be misleading. The unauthorized consumption of computing resources imposes real, ongoing costs: degraded device and application performance, increased power consumption, accelerated hardware wear, and, in cloud environments, elevated infrastructure charges that can accrue quickly and quietly. Because the attacker's goal is to remain hidden and keep mining, cryptojacking can persist undetected for extended periods, compounding those costs over time.

For organizations, cryptojacking also functions as an indicator of a deeper security problem. The presence of mining malware on an endpoint, server, or cloud workload means an attacker found a way in and can execute unauthorized code, an access path that could be used for more damaging activity. Treating a cryptojacking finding as a minor nuisance rather than as evidence of a control failure can leave the underlying vulnerability unaddressed.

From a risk-transfer perspective, cryptojacking illustrates why the existence of a threat does not settle the question of coverage. Whether resulting losses, such as unexpected cloud compute charges or costs to investigate and remediate an infected environment, fall within a cyber policy depends on the specific policy wording, applicable exclusions, conditions, and jurisdiction. Insurance does not reduce the likelihood of a device being compromised in the first place; managing that likelihood remains a matter of security controls and mitigation.

Who it's relevant to

Chief information security officers and security teams
For security leaders, a cryptojacking detection is both a cost issue and a signal of unauthorized code execution within the environment. It points to an access path that an attacker could exploit for more damaging activity, so findings warrant investigation of how the intrusion occurred rather than simple removal of the mining process. Cloud workloads and internet-facing servers are of particular concern given their compute capacity and the potential for elevated infrastructure charges.
Risk managers and resilience planners
Cryptojacking is a mitigation and detection challenge before it is an insurance question. Because insurance does not reduce the likelihood of compromise, controls that prevent unauthorized code execution and monitoring that surfaces abnormal resource consumption are the primary defenses. Planners should also consider how prolonged, undetected mining could degrade performance of business-critical systems.
Insurance brokers and underwriters
Whether cryptojacking-related losses, such as unexpected cloud compute charges or the cost of investigation and remediation, are covered depends on the specific policy wording, endorsements, exclusions, and jurisdiction. These outcomes should not be assumed to fall within any given form. Underwriters may also view a cryptojacking incident as evidence about the strength of an insured's controls and monitoring.
Finance and cloud operations teams
In cloud environments, unauthorized mining consumes billable compute, so cryptojacking can appear first as unexplained cost increases rather than as a security alert. Anomalous spend can therefore serve as an early indicator, making close coordination between finance, cloud operations, and security valuable for timely detection.

Inside Cryptojacking

Unauthorized cryptocurrency mining
The core of cryptojacking: an attacker covertly uses a victim's computing resources (servers, endpoints, cloud instances, or browsers) to mine cryptocurrency without consent, diverting processing power, electricity, and cloud capacity for the attacker's benefit.
Resource consumption impact
The primary harm is degraded performance, increased power and cooling demands, accelerated hardware wear, and, especially in cloud environments, inflated compute bills from auto-scaling triggered by the attacker's workload.
Delivery and persistence mechanisms
Cryptojacking can arrive via malware on endpoints or servers, malicious or compromised scripts running in browsers, exploited cloud misconfigurations, or stolen cloud credentials. Attackers often seek persistence to keep mining over time.
Stealth objective
Unlike ransomware, cryptojacking is typically designed to remain undetected, since the attacker's return depends on prolonged, quiet use of resources rather than a disruptive extortion event.
Insurance relevance (conditional)
Whether cryptojacking losses are recoverable depends on the specific policy. First-party heads such as unexpected cloud/compute cost, business interruption from degraded performance, or costs of investigation and remediation may be relevant, but coverage is subject to policy wording, sublimits, retentions, waiting periods, and exclusions. This description is not a coverage determination.

Common questions

Answers to the questions practitioners most commonly ask about Cryptojacking.

Is cryptojacking automatically covered under a cyber insurance policy?
Not automatically. Whether losses arising from cryptojacking respond depends on the specific policy wording, applicable endorsements, exclusions, and conditions precedent. Cryptojacking involves the unauthorized use of an organization's computing resources to mine cryptocurrency, so any recovery typically turns on how the policy defines a covered event and which loss categories apply. Some first-party losses that could theoretically be implicated, such as increased cloud compute or electricity costs, or business interruption from degraded performance, may or may not fall within covered perils depending on the form. There is no general rule that cryptojacking is a covered loss; it must be assessed against the actual contract and jurisdiction.
Is cryptojacking a harmless nuisance because it doesn't steal or destroy data?
It should not be treated as harmless simply because its primary aim is to hijack processing power rather than exfiltrate or destroy data. Even where data confidentiality is not the direct target, cryptojacking indicates that an attacker has achieved unauthorized access or code execution, which is itself a security failure that may signal broader exposure. It can also cause operational effects such as degraded system performance and increased resource consumption. Characterizing it as trivial can lead an organization to under-investigate the underlying access vector. The scope of actual harm varies by incident and is a factual question rather than an assumption.
How should an organization detect cryptojacking activity?
Detection commonly focuses on the operational symptoms and the underlying unauthorized access. Indicators can include unexplained increases in CPU or GPU utilization, elevated cloud compute or electricity consumption, degraded system performance, and outbound connections associated with mining activity. Monitoring resource usage baselines, reviewing cloud billing anomalies, and using endpoint and network detection tooling are frequently used approaches. Detection is a security and resilience function; it is separate from any insurance question of whether resulting losses respond under a policy.
What internal teams should be involved when responding to suspected cryptojacking?
Response typically involves the incident response function to contain and investigate the unauthorized access, along with IT and cloud operations to address resource consumption and restore normal performance. Depending on findings, legal, compliance, and risk management may become involved, particularly if the access vector suggests broader compromise. If the organization intends to seek coverage, early engagement with the insurer or broker consistent with the policy's notice conditions is often important. Incident response here is distinct from crisis management, which would engage only if the event escalated to that level.
What documentation is useful if an organization wants to present a cryptojacking loss to an insurer?
Because whether a loss responds depends on the specific wording, contemporaneous records help substantiate any claim. Useful documentation can include evidence of the unauthorized access and its timeline, records of increased cloud compute or electricity costs attributable to the mining activity, measures of any performance degradation or interruption, and remediation actions and costs. Aligning this evidence with the policy's definitions, sublimits, retentions, and any waiting periods for business interruption is important. Whether such costs qualify as a covered first-party loss is subject to the policy terms and should be confirmed with the insurer or broker.
How does cryptojacking relate to broader security controls versus risk transfer through insurance?
Preventing and limiting cryptojacking is primarily a matter of risk mitigation through security controls, such as access management, patching, workload monitoring, and restricting execution of unauthorized code. Insurance is a risk transfer mechanism and does not reduce the likelihood of a cryptojacking incident or by itself constitute resilience. An organization relying on a policy still needs mitigation to reduce exposure, and some policies condition coverage on maintaining certain standards, meaning weak controls could affect whether a loss responds. The two functions are complementary rather than substitutes.

Common misconceptions

Cryptojacking is harmless because no data is stolen or encrypted.
Even without data theft or encryption, cryptojacking can cause measurable financial harm through elevated cloud and electricity costs, degraded system performance affecting operations, and hardware strain. It also often indicates that an attacker has gained a foothold that could be used for more damaging activity.
A cyber insurance policy will automatically cover the runaway cloud costs from cryptojacking.
Coverage is not automatic. Whether inflated compute charges, business interruption, or remediation costs are payable depends on the specific policy wording, applicable sublimits and retentions, waiting periods, and exclusions (for example, provisions addressing failure to maintain security standards or utility/infrastructure charges). Each claim must be assessed against its own policy language and jurisdiction.
Having insurance means the organization is protected against cryptojacking.
Insurance is a risk-transfer mechanism that may fund certain losses after the fact; it does not reduce the likelihood of an intrusion or constitute resilience. Preventing and detecting cryptojacking requires security controls and monitoring, which are distinct from and complementary to any coverage.

Best practices

Monitor for anomalous resource use, sustained high CPU/GPU utilization, unexpected cloud auto-scaling, and unusual outbound connections to mining pools, so covert mining is detected early.
Set cloud cost alerts and spending guardrails, and harden cloud configurations and credential management to limit the impact of compromised accounts or misconfigurations.
Maintain endpoint and server protection, timely patching, and browser/script controls to reduce common delivery paths for mining code.
Treat detected cryptojacking as a potential indicator of broader compromise and route it through incident response procedures rather than simply removing the miner.
Review your cyber policy with a broker to understand how it treats first-party losses such as unexpected compute costs, business interruption, and investigation/remediation, including relevant sublimits, retentions, waiting periods, and exclusions.
Recognize that insurance complements but does not replace mitigation; invest in prevention, detection, and response controls alongside any risk-transfer arrangements.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps