/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

YouTube served ads containing Coinhive's cryptocurrency-mining and CPU-draining JavaScript, likely via Google's DoubleClick; Google says ads now blocked

Ars Technica Dan Goodin

Context & Ripple Effects

The day before this report, Ars Technica had already flagged YouTube serving ads laced with Coinhive's mining JavaScript, and this follow-up adds Google's response: the offending ads are now blocked, with DoubleClick the likely delivery path. That makes this a supply-chain failure inside Google's own ad stack — the malicious code reached YouTube viewers through the same infrastructure Google sells as brand-safe.

The episode also foreshadows the trust dynamics that defined YouTube's later years: by 2023 the platform was running a global pop-up experiment pushing ad-blocker users toward Premium, and after expanding its crackdown saw record ad-blocker uninstalls. A platform asking users to accept more ads has a vested interest in proving those ads are safe.

First-order effects

  • Viewers loading YouTube pages were having their CPUs silently drained to mine cryptocurrency for whoever placed the ads, until Google blocked the creatives.
  • Google now has to explain how mining JavaScript cleared DoubleClick's review pipeline and reached one of its highest-traffic properties.

Second-order effects

  • Advertisers buying through DoubleClick face fresh questions about what else slips past automated vetting, pressuring Google to tighten creative screening across the network.
  • For YouTube, every incident like this hands ammunition to the ad-blocking community it was simultaneously trying to suppress, complicating its push toward Premium subscriptions.

Third-order effects

  • If programmatic ad delivery keeps doubling as a malware channel, ad verification shifts from a nice-to-have for advertisers to a baseline security requirement for platforms — and regulators may treat ad networks as attack infrastructure rather than mere media pipes.

The trend: Ad-serving infrastructure is becoming a security surface in its own right, forcing platforms to police the code they deliver as aggressively as the content around it.

Discussion

  • @hrbrmstr @hrbrmstr on x
    PSA: If you do nothing else b/c of me this year, *pls* use an ad blocker and good — regularly updated — blocker hosts file. Digital currency miners are now in Double Click (i.e. Google/Alphabet — so much for their “amazing” AI cyber experts) http://blog.trendmicro.com/...
  • @bad_packets Bad Packets Report on x
    “We started seeing an increase in traffic to five malicious domains on January 18. After closely examining the network traffic, we discovered that the traffic came from DoubleClick (Google) advertisements.” http://blog.trendmicro.com/...
  • @drevilgames Doctor ‘Russian Bot’ Evil on x
    Just another reason to use adblock and noscript extensions for your browser. They're not just for removing advertising annoyances, they're a security measure. http://twitter.com/...