At least 5% of all Monero currently in circulation has been mined using malware, based on an analysis of 629,126 malware samples from coin mining operations
Catalin Cimpanu / BleepingComputer.com :
Context & Ripple Effects
This analysis lands mid-boom: Symantec had just documented an 8,500% quarterly surge in cryptojacking driven by easy-to-run coin miners, and the Smominru botnet had shown how EternalBlue could enslave half a million Windows servers for Monero. What was missing was a supply-side number — how much of the coin's actual circulation criminal operations account for.
By crunching 629,126 malware samples, the answer is at least 5% of all Monero in existence — a striking figure for a coin whose market cap sat near $165M after a year in which its price rose roughly 2,760%. It converts anecdotal botnet reports into a measurable claim about who holds the asset.
First-order effects
- Monero's circulating supply is now demonstrably tainted at scale: at least one in twenty coins traces to malware operators, meaning criminal mining is a material share of the coin's issuance rather than a fringe nuisance.
- For enterprises running Windows servers — Smominru's primary target — the finding confirms that hijacked compute was being converted into lasting criminal holdings, not just temporary electricity theft.
Second-order effects
- The economics keep working: because Monero resists ASICs via its protocol forks and mines efficiently on ordinary CPUs, every subsequent campaign — from the Golang worm dropping XMRig on Windows and Linux servers to the perfctl malware hitting millions of Linux servers years later — defaults to Monero as the payout rail.
- Exchanges and compliance teams face pressure to treat malware-tainted Monero as a real custody risk, since a measurable slice of supply originates from botnets rather than legitimate miners.
Third-order effects
- If the pattern holds, Monero's combination of CPU-mineability and strong privacy cements a self-reinforcing loop: malware proceeds fund ransomware operations that increasingly demand Monero payments, deepening the law-enforcement tracing problem the coin's design creates.
- The durability of this pipeline — visible from the 2018 botnet wave through perfctl's multi-year Linux campaign — suggests privacy coins will remain structurally attractive to server-targeting malware as long as they stay CPU-mineable.
The trend: Monero's CPU-friendly, privacy-first design has made malware mining a durable criminal revenue stream, persisting from the 2018 botnet era through today's large-scale server infections.