Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that a browser is…
Cyber Security

What are the signs that a browser is being used for hidden cryptocurrency mining?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Common indicators include a fan spinning up unexpectedly, sustained high CPU usage while visiting certain sites, sluggish device performance, and browser activity that continues after the visible tab or window is closed. Those symptoms do not prove mining on their own, but together they are strong signals that a site may be running scripts that are abusing local processing power.

What browser mining looks like in practice

Hidden browser mining is usually detected by behaviour, not by a single definitive alert. The clearest pattern is a browser that behaves as if it is doing sustained work when the page itself appears idle: the device warms up, the fan accelerates, tabs feel slow to switch, and CPU use stays elevated after the content should have stopped loading. Those symptoms matter most when they begin on one site and persist across navigation, backgrounding, or tab closure.

Another useful signal is mismatch. A news page, blog, or simple form should not normally pin the processor for long periods or keep a laptop noisy under light browsing. If the browser is the main source of load, the issue is often a script running in the page context, using local compute rather than obvious network-heavy behaviour. That makes the impact look like a performance problem first, even though the underlying issue is unauthorised resource use.

When browser mining is suspected, the practical question is whether the browser is the only process driving the spike or whether another workload is also involved. A suspicious site can be part of the trigger, but the browser process, renderer subprocesses, or a particular tab usually show the pressure. In some cases, the load continues because the script is designed to keep operating in the background, even when the visible content is gone.

Signs that are worth treating as suspicious

A single symptom is not enough. Fans can spin up for legitimate reasons, and high CPU can come from many non-malicious causes. What makes browser mining more plausible is a cluster of indicators: repeated high CPU while viewing the same site, unexpected battery drain, poor responsiveness that improves after closing the page, and browser activity that seems inconsistent with the content on screen. If those signs recur across sessions, the suspicion becomes stronger.

It is also worth watching for browser-level persistence tricks. Some mining code is embedded in ad scripts, third-party widgets, or malicious injected code that survives simple page interaction. That means closing the visible tab may not immediately stop the activity if another page, service worker, or browser process is still active. For that reason, investigators should look at process behaviour and not rely only on what the user can see.

For a broader identity-and-access context around abuse of credentials and downstream compromise, NHIMG’s Ultimate Guide to Non-Human Identities is a useful reference point, especially where mining activity is part of a larger abuse chain involving exposed access paths. NHIMG’s Amazon AWS Hacked Accounts Crypto-Mining shows how mining campaigns can also depend on compromised credentials outside the browser itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM — Continuous MonitoringBrowser mining is identified through sustained anomalous resource use and process behaviour.
DE.AE — Anomalies and EventsUnexpected CPU spikes and lingering browser activity are anomalous events worth triage.
Recommendation — Monitor endpoint and browser process anomalies to detect persistent resource abuse. Triage browser performance anomalies as potential abuse of local compute.
CIS Controls v88 — Audit Log ManagementBrowser mining investigations benefit from logs showing which site, process, or extension initiated the load.
7 — Continuous Vulnerability ManagementMalicious scripts and vulnerable browser components can be part of the mining path.
Recommendation — Retain and review endpoint and browser telemetry to reconstruct the initiating activity. Keep browsers and extensions patched to reduce script and exploit exposure.
OWASP Agentic AI Top 10A2 — Prompt Injection and Tool MisuseThe question involves browser-executed code abusing client resources, which maps to misuse of execution context.
Recommendation — Constrain browser-executed scripts and third-party content to prevent misuse of execution resources.
MITRE ATT&CKT1496 — Resource HijackingHidden cryptocurrency mining is a direct example of local resource hijacking.
Recommendation — Detect and block unexpected compute consumption consistent with resource hijacking.
OWASP Non-Human Identity Top 10NHI-01 — Secret SprawlWhen mining is part of broader compromise, exposed credentials can enable the abuse path.
NHI-03 — Excessive PrivilegesIf mining follows broader compromise, overprivileged access increases blast radius.
Recommendation — Reduce exposed secrets that can enable downstream abuse beyond the browser session. Limit privileges so a browser-originated compromise cannot expand into wider system abuse.

Practitioner Guidance

What to verify: Correlate the browser symptom with process and tab activity. If CPU remains high after one site loads, close that site first, then watch whether the load drops immediately; a rapid drop is a strong clue that the page was the trigger.

Decision rule: If the browser is consuming sustained CPU on content that should be lightweight, treat it as a resource-abuse investigation rather than a simple performance complaint. If the issue stops only after killing the browser process, inspect the affected site, extensions, and any recently added scripts or widgets.

Common mistake: Assuming "no obvious popup" means nothing malicious is happening. Browser mining is often quiet, opportunistic, and designed to look like ordinary slowness, so the absence of a visible warning is not reassuring.

Practitioner takeaway: The most reliable signal is a repeatable load pattern tied to a specific browsing context, especially when the browser keeps working after the page should be idle. That combination is stronger evidence than user frustration alone and is the right point to escalate.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org