/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

YouTube served ads containing Coinhive's cryptocurrency-mining, CPU-draining JavaScript, likely via Google's DoubleClick ad server; Google says ads now blocked

Ad campaign lets attackers profit while unwitting users watch videos.  —  YouTube was recently caught displaying ads …

Ars Technica Dan Goodin

Context & Ripple Effects

In January 2018, viewers on YouTube were served ads laced with Coinhive's JavaScript, which quietly commandeered their CPUs to mine cryptocurrency — with delivery traced to Google's own DoubleClick ad server, meaning the malicious code rode in through the platform's trusted ad pipeline rather than a compromised page. Google's response was to block the campaign after the fact, not before it ran.

The incident is an early data point in a longer erosion of confidence in web advertising: five years later, YouTube's escalating fight against ad blockers — from pop-up experiments urging users to allow ads or subscribe to Premium, through a crackdown that drove record ad-blocker uninstalls while unaffected users installed blockers at record rates — shows how much platform energy now goes into defending the ad experience itself.

First-order effects

  • Viewers watching YouTube bore the direct cost: their devices' CPUs were drained mining cryptocurrency for attackers while ads played, with no consent and no visible sign beyond performance degradation.
  • Google had to scramble to block the Coinhive campaign inside its own DoubleClick-served inventory, exposing that its ad-serving stack had passed malicious creative through its review process.

Second-order effects

  • Advertisers buying through DoubleClick face a trust problem: if the server itself can deliver CPU-draining malware, brand-safety vetting has to extend to the code in the creative, not just its content.
  • Every confirmed malvertising incident hands ammunition to the ad-blocking ecosystem, hardening user resolve just as YouTube's later crackdown on ad blockers shows the platform fighting to keep that channel open.

Third-order effects

  • If malvertising keeps slipping through major ad servers, the industry drifts toward heavier pre-serve scanning and tighter platform control over ad code — raising costs for the whole programmatic chain.
  • The long arc runs from incidents like this to today's standoff: platforms policing both sides of the ad experience, blocking bad creatives at the source while forcing users past blockers, because each failure pushes audiences toward tools that cut ads out entirely.

The trend: Ad-supported platforms are being pushed into ever-tighter policing of their own ad pipelines — filtering malicious creatives upstream while battling the ad blockers that every pipeline failure helps popularize.

Discussion

  • @drevilgames Doctor ‘Russian Bot’ Evil on x
    Just another reason to use adblock and noscript extensions for your browser. They're not just for removing advertising annoyances, they're a security measure. http://twitter.com/...