Cryptojacking
Cryptojacking is a type of cyberattack in which attackers secretly use someone else's computer or device to mine cryptocurrency without permission. The victim typically does not know it is happening, while their device's processing power and electricity are consumed to generate cryptocurrency for the attacker. It can occur through malware installed on a device or through code embedded in websites.
Cryptojacking is the unauthorized exploitation of a victim's computing resources to mine cryptocurrency, carried out against the user's will or without their awareness. Delivery vectors typically include malware that infects endpoints, servers, or cloud infrastructure, as well as browser-based scripts executed when a user visits a compromised or malicious website. The attacker hijacks CPU, GPU, or broader compute capacity to perform mining operations, imposing costs on the victim in the form of degraded performance, increased resource consumption, and, in cloud environments, elevated infrastructure charges. This entry addresses cryptojacking as a security threat concept and does not by itself determine whether resulting losses are insurable; coverage would depend on the specific policy wording, applicable exclusions, and jurisdiction.
Why it matters
Cryptojacking is often characterized as a lower-severity threat than ransomware or data theft because it does not typically destroy data or extort payment. That framing can be misleading. The unauthorized consumption of computing resources imposes real, ongoing costs: degraded device and application performance, increased power consumption, accelerated hardware wear, and, in cloud environments, elevated infrastructure charges that can accrue quickly and quietly. Because the attacker's goal is to remain hidden and keep mining, cryptojacking can persist undetected for extended periods, compounding those costs over time.
For organizations, cryptojacking also functions as an indicator of a deeper security problem. The presence of mining malware on an endpoint, server, or cloud workload means an attacker found a way in and can execute unauthorized code, an access path that could be used for more damaging activity. Treating a cryptojacking finding as a minor nuisance rather than as evidence of a control failure can leave the underlying vulnerability unaddressed.
From a risk-transfer perspective, cryptojacking illustrates why the existence of a threat does not settle the question of coverage. Whether resulting losses, such as unexpected cloud compute charges or costs to investigate and remediate an infected environment, fall within a cyber policy depends on the specific policy wording, applicable exclusions, conditions, and jurisdiction. Insurance does not reduce the likelihood of a device being compromised in the first place; managing that likelihood remains a matter of security controls and mitigation.
Who it's relevant to
Inside Cryptojacking
Common questions
Answers to the questions practitioners most commonly ask about Cryptojacking.
