/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

YouTube served ads containing Coinhive's cryptocurrency-mining and CPU-draining JavaScript, likely via Google's DoubleClick; Google says ads now blocked

Ad campaign lets attackers profit while unwitting users watch videos.  —  YouTube was recently caught displaying ads …

Ars Technica Dan Goodin

Context & Ripple Effects

Across January 27–29, 2018, reports converged on the same finding: ads shown on YouTube carried Coinhive's cryptocurrency-mining JavaScript, most likely delivered through Google's DoubleClick ad-serving pipeline, so simply watching a video put the viewer's CPU to work mining for an attacker. Google says the ads are now blocked, but the compromise sat inside the ad chain itself, not on any single video page.

The episode reads differently against what came after: by late 2023 YouTube was deep in an escalating battle with ad blockers, having driven record ad-blocker uninstalls in October with its crackdown. Each step that forces ads onto viewers raises the stakes on whether those ads can be trusted — and this incident is the canonical example of when they couldn't.

First-order effects

  • Viewers watching affected videos had their CPUs drained to mine cryptocurrency without consent, and Google's immediate fix was blocking the Coinhive campaign on YouTube.
  • Because the malicious code arrived via DoubleClick, the failure point was Google's own ad-serving infrastructure — the same system advertisers rely on for placement.

Second-order effects

  • Advertisers buying through DoubleClick absorb brand-safety risk from the incident, since their spend can end up funding hostile creative, pressuring Google to vet ad content more aggressively.
  • A documented case of ads actively harming viewers gives ad-blocker holdouts a security argument, stiffening resistance to YouTube's later pop-up experiments urging users to allow ads or subscribe to Premium.

Third-order effects

  • If YouTube keeps tightening enforcement against ad avoidance while the ad supply remains attackable, its push toward Premium subscriptions doubles as a trust hedge — steering viewers off an ad pipe the platform cannot fully vouch for.
  • Programmatic advertising may drift toward mandatory creative-level verification at the ad-server layer, concentrating compliance cost and gatekeeping power with intermediaries like Google.

The trend: As video platforms escalate enforcement against ad avoidance, the integrity of the ad supply chain itself becomes the next front in the standoff between platforms and viewers.

Discussion

  • @diegobetto Diego Betto on x
    Hey @avast_antivirus seems that you are blocking crypto miners (#coinhive) in @YouTube #ads Thank you :) https://diegobetto.com/...
  • @drevilgames Doctor ‘Russian Bot’ Evil on x
    Just another reason to use adblock and noscript extensions for your browser. They're not just for removing advertising annoyances, they're a security measure. http://twitter.com/...