/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

At least 5% of all Monero currently in circulation has been mined using malware, based on an analysis of 629,126 malware samples from coin mining operations

Catalin Cimpanu / BleepingComputer.com :

BleepingComputer.com Catalin Cimpanu

Context & Ripple Effects

This analysis lands mid-boom: Symantec had just documented an 8,500% quarterly surge in cryptojacking driven by easy-to-run coin miners, and the Smominru botnet had shown how EternalBlue could enslave half a million Windows servers for Monero. What was missing was a supply-side number — how much of the coin's actual circulation criminal operations account for.

By crunching 629,126 malware samples, the answer is at least 5% of all Monero in existence — a striking figure for a coin whose market cap sat near $165M after a year in which its price rose roughly 2,760%. It converts anecdotal botnet reports into a measurable claim about who holds the asset.

First-order effects

  • Monero's circulating supply is now demonstrably tainted at scale: at least one in twenty coins traces to malware operators, meaning criminal mining is a material share of the coin's issuance rather than a fringe nuisance.
  • For enterprises running Windows servers — Smominru's primary target — the finding confirms that hijacked compute was being converted into lasting criminal holdings, not just temporary electricity theft.

Second-order effects

Third-order effects

  • If the pattern holds, Monero's combination of CPU-mineability and strong privacy cements a self-reinforcing loop: malware proceeds fund ransomware operations that increasingly demand Monero payments, deepening the law-enforcement tracing problem the coin's design creates.
  • The durability of this pipeline — visible from the 2018 botnet wave through perfctl's multi-year Linux campaign — suggests privacy coins will remain structurally attractive to server-targeting malware as long as they stay CPU-mineable.

The trend: Monero's CPU-friendly, privacy-first design has made malware mining a durable criminal revenue stream, persisting from the 2018 botnet era through today's large-scale server infections.