Researcher publishes CoffeeMiner to show how public Wi-Fi users' traffic can be hijacked to mine cryptocurrency, weeks after similar project was spotted in wild
A new attack called CoffeeMiner can exploit public Wi-Fi services to secretly mine cryptocurrencies.
Context & Ripple Effects
By early 2018, cryptojacking had already moved from novelty to epidemic: miners were found hiding on Politifact and hundreds of other sites, and Symantec counted an 8,500% jump in Q4 2017, driven by easy-to-operate tools like Coinhive. Those attacks all shared one delivery mechanism — JavaScript running inside a browser page.
First-order effects
- CoffeeMiner removes that dependency: by intercepting traffic on public Wi-Fi, an attacker can inject mining code into any unencrypted page a café or airport visitor loads, turning every connected laptop and phone into a Monero miner without the site owner's involvement.
- Public Wi-Fi operators now face a reputational and liability exposure they did not have when cryptojacking was confined to compromised websites — their network is the attack vector.
Second-order effects
- The same logic scales beyond hand-run hotspots: the later discovery of 415K+ infected routers, mostly MikroTik shows attackers automating exactly this move — compromising the network device once and mining from every client behind it.
- Browser vendors' crackdowns on in-page miners push attackers toward network-layer injection instead, since CoffeeMiner-style interception does not depend on a page's own JavaScript surviving.
Third-order effects
- Wi-Fi itself becomes the durable weak layer: the 2023 flaw in the IEEE 802.11 protocol enabling malicious TCP packet injection, and the AirSnitch attacks that bypass client isolation, show the protocol's assumptions keep yielding machine-in-the-middle openings long after individual tools like CoffeeMiner are patched around.
- If hijacking other people's compute stays this cheap, cryptojacking consolidates as the low-risk monetization path for network attackers — no ransom negotiation, no file destruction, just silent harvesting of electricity someone else pays for.
The trend: Cryptojacking is migrating up the stack from website scripts to network infrastructure, with Wi-Fi's protocol weaknesses becoming the recurring entry point.