webfilteringdatabase.com
Home Find Your Solution
Features
Domain Categorization API Real-Time Classification 59 Filtering Categories Offline Database (100M) ML Classification Content Classification
Industries
K-12 Schools Corporate Healthcare Government ISPs
Tools
Domain Lookup Bulk Categorization Category Explorer
Resources
Pricing API Documentation Login / Sign Up
Security Category

Cryptomining Domain Filtering

Stop unauthorised cryptomining from stealing compute and inflating energy bills. Over 480,000 mining-pool and cryptojacking domains classified with multi-signal detection for endpoint protection, DNS filtering, and workplace policy enforcement.

How Cryptomining Domains Are Detected

Cryptomining abuse comes in two flavours. Browser-based cryptojacking injects JavaScript miners into web pages so that a visitor's CPU quietly mines cryptocurrency for someone else. Malware-based mining installs a persistent process on a compromised host that connects to a mining pool. Both patterns depend on reaching known infrastructure — pool endpoints, stratum servers, and script CDNs — and both are blocked by classifying that infrastructure. Our category covers more than 480,000 such domains.

Detection begins with the mining protocols themselves. Stratum, the dominant pool-communication protocol, has recognisable connection patterns, and pool domains advertise themselves through public listings, wallet-tracking services, and sandbox observation. Browser miners are identified by fingerprinting the WebAssembly and JavaScript payloads of known mining libraries such as CoinHive descendants, CryptoLoot, and their many forks, even when the code is obfuscated or self-hosted.

Because mining is fundamentally a resource-theft problem rather than a data-theft one, the signals differ from other malware. High-entropy WebAssembly modules, persistent WebSocket connections to pool proxies, and CPU-throttling logic embedded in page scripts are all indicators. We combine these behavioural fingerprints with hosting and registration reputation to catch both commercial mining services and covert cryptojacking campaigns.

The Cryptojacking Threat Landscape

Cryptomining abuse rose to prominence when in-browser mining libraries made it trivial to monetise other people's processors. The economics are simple and seductive to attackers: unlike ransomware, cryptojacking needs no victim interaction and no payment negotiation. It simply steals a slice of every visitor's or every server's compute and converts it directly into cryptocurrency. The victim pays in electricity, degraded performance, and shortened hardware life, often without ever realising anything is wrong.

The threat has two faces. Browser-based cryptojacking injects a miner into a web page — sometimes on a malicious site, increasingly on a legitimate site that has been compromised or is running a rogue advertisement. Malware-based mining installs a persistent process, and cloud environments have become a favourite target because their elastic compute can be scaled up on the attacker's behalf, producing eye-watering bills before anyone notices. In both cases the miner is worthless unless it can reach a mining pool.

That dependency is the control point. Every miner, whether a few lines of obfuscated JavaScript or a compiled binary on a hijacked server, must connect to pool infrastructure to submit work and receive payouts. By mapping pool endpoints, fingerprinting mining libraries, and detecting the stratum protocol at the network level, the connection can be blocked regardless of how the miner arrived. Cut the link to the pool and the mining stops being profitable, which removes the incentive entirely.

For organisations, the case for blocking is as much financial as it is security-driven. Cloud cryptojacking can turn a compromised container into thousands of dollars of billed compute in days. Endpoint cryptojacking quietly raises energy costs and support tickets about sluggish machines. Because the category distinguishes covert mining from legitimate cryptocurrency services, it lets an organisation stop the abuse without cutting employees off from exchanges, wallets, or blockchain information they may legitimately need.

Detection Methodology

Behavioural and infrastructure signals combine to identify mining pools and cryptojacking scripts

Mining Pool Mapping

Public and private mining pools expose stratum endpoints that miners connect to. We enumerate pool infrastructure across major and minor cryptocurrencies, mapping domains, subdomains, and proxy front-ends so that both direct pool connections and proxied traffic are classified.

Script Fingerprinting

Browser-mining libraries share recognisable WebAssembly modules and JavaScript entry points. Fingerprinting these payloads detects cryptojacking even when scripts are self-hosted, renamed, or obfuscated, catching the injected miner rather than relying on a domain blocklist alone.

Protocol Detection

The stratum mining protocol and its variants have distinctive handshake and job-distribution patterns. Network-level detection of stratum traffic identifies mining activity regardless of the domain used, flagging previously unknown pool proxies by their protocol behaviour.

Resource-Abuse Signals

Cryptojacking scripts throttle CPU to avoid detection, spin up persistent WebSocket connections, and run continuously in the background. Behavioural analysis of page execution surfaces these resource-abuse patterns even for custom miners with no known signature.

Wallet & Payout Tracing

Mining operations are linked to cryptocurrency wallet addresses and payout infrastructure. Correlating domains with wallet-tracking data and shared payout endpoints connects disparate mining domains to the same operator, expanding coverage across a campaign.

Continuous Re-scanning

Compromised legitimate sites are a common cryptojacking vector: a site may be clean today and injected tomorrow. Continuous re-scanning detects newly injected miners on otherwise-legitimate domains and removes classifications when the injection is cleaned up.

Policy & Use Cases

Cryptomining filtering protects compute resources, controls energy costs, and enforces acceptable-use policy

Endpoint Protection

Endpoint and browser-security products block mining scripts before they consume CPU. Users are protected from drive-by cryptojacking on compromised or malicious sites without any noticeable impact on legitimate browsing.

  • Blocks browser-based cryptojacking in real time
  • Prevents CPU and battery drain on user devices
  • Covers self-hosted and obfuscated miners
  • Integrates with browser extensions and endpoint agents
  • Minimal false positives on legitimate WebAssembly apps

Workplace Policy

Employers block mining domains to prevent both external cryptojacking and insider misuse of corporate hardware for personal mining. Unauthorised mining inflates energy costs, shortens hardware lifespan, and can breach acceptable-use policy.

  • Enforces acceptable-use policy on company devices
  • Prevents insider resource abuse for personal mining
  • Reduces energy costs and hardware wear
  • Logs mining attempts for policy investigation
  • Applies across all devices via DNS filtering

DNS-Level Blocking

Protective DNS services block pool and script domains for the entire network at the resolution layer. Because miners must reach their pool to be profitable, blocking the lookup neutralises the operation regardless of how the miner was installed.

  • Blocks pool connections at the DNS layer
  • Protects unmanaged and IoT devices
  • No endpoint agent required
  • Sinkholing reveals infected hosts
  • RPZ feeds for standard resolver integration

Cloud & Server Protection

Cloud workloads and servers are prime cryptojacking targets because of their compute capacity. Blocking mining infrastructure at the egress layer stops compromised containers and virtual machines from mining at the organisation's expense.

  • Prevents cryptojacking of cloud compute resources
  • Reduces cloud billing spikes from mining abuse
  • Egress filtering for containers and VMs
  • Detects compromised workloads via pool callbacks
  • Supports automated remediation workflows

Cryptomining Category Statistics

Coverage and accuracy metrics for mining pools and cryptojacking infrastructure

480K+
Mining Domains Tracked
99.2%
Detection Accuracy
<0.15%
False Positive Rate
15 min
Feed Refresh Interval

Distinguishing Abuse From Legitimate Use

Not all cryptocurrency activity is abuse. Exchanges, wallet services, blockchain explorers, and legitimate mining businesses that operate with consent all belong in separate categories. The cryptomining abuse category targets unauthorised mining and covert cryptojacking, not the broader cryptocurrency economy, so that a policy blocking cryptojacking does not inadvertently block an employee from checking a legitimate exchange.

The classification engine distinguishes an in-page miner running without consent from a mining-pool operator's own website, and separates both from exchanges and informational crypto sites. Sub-categorisation lets administrators block covert mining while permitting legitimate cryptocurrency services, or apply a stricter policy that blocks the entire ecosystem where that is appropriate.

Confidence scores and behavioural evidence accompany each classification, so security teams can verify that a flagged domain is genuinely running or serving a miner before enforcing a block, and can tune sensitivity for different network segments.

Integration Guide for Cryptomining Filtering

Deploy mining protection across DNS, endpoint, and egress layers

Deployment Options

DNS-layer filtering blocks pool and script domains for every device without client software, making it the simplest way to stop cryptojacking network-wide. Point resolvers at the RPZ feed or query the API in-line, and connections to mining infrastructure fail to resolve.

Endpoint and browser integration adds script-level blocking, catching in-page miners on sites that have not yet been classified at the domain level. Egress filtering on firewalls and cloud security groups prevents compromised servers and containers from reaching mining pools.

The real-time API returns classification, mining subtype, and confidence in a single call, while batch feeds support bulk enrichment of existing domain inventories and continuous synchronisation with security tooling.

  • DNS RPZ feeds refreshed every 15 minutes
  • Script-fingerprint indicators for endpoint and browser tools
  • REST API with sub-10ms response times
  • SDKs for Python, Node.js, Go, Java, and C#

Domain Classification API

// Check cryptomining classification
curl -X GET "https://api.webfilteringdb.com/v1/lookup" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"domain": "example-domain.com"}'

// Response
{
  "domain": "example-domain.com",
  "categories": ["cryptomining"],
  "subcategory": "cryptojacking",
  "confidence": 0.98,
  "action": "block"
}

Egress Block-List Config

# Squid proxy ACL for cryptomining domains
acl cryptomining dstdomain "/etc/squid/cryptomining.txt"
http_access deny cryptomining

# Refresh the list from the classification feed
# curl -H "Authorization: Bearer KEY" \
#   https://api.webfilteringdb.com/v1/feed/cryptomining \
#   -o /etc/squid/cryptomining.txt && squid -k reconfigure

Frequently Asked Questions

Common questions about deployment, coverage, and policy

What is cryptojacking?

Cryptojacking is the unauthorised use of someone's computer or server to mine cryptocurrency. It can happen through a script injected into a web page (browser-based) or through malware installed on a device (host-based). The victim's processor does the mining work, and the attacker collects the proceeds while the victim absorbs the electricity and performance costs.

Does this block legitimate cryptocurrency sites?

No. The cryptomining abuse category targets mining pools and cryptojacking scripts, not the broader cryptocurrency economy. Exchanges, wallets, and blockchain explorers are classified separately, so you can block covert mining while still permitting legitimate crypto services — or block the whole ecosystem if your policy requires it.

How does DNS-level blocking stop mining?

A miner is only profitable if it can reach its pool to submit work and receive payouts. Blocking the pool domain at the DNS layer means the miner's connection never resolves, so no work is submitted and no reward is earned. This works regardless of whether the miner is a browser script or installed malware.

Why should cloud teams care about cryptomining?

Cloud workloads have large, elastic compute capacity, which makes them a prime cryptojacking target. A compromised container can generate substantial mining revenue for an attacker while producing a large, unexpected cloud bill for the victim. Egress-blocking mining pools stops this abuse and can reveal compromised workloads via their blocked pool callbacks.

Can it detect self-hosted or obfuscated miners?

Yes. In addition to a domain feed, we fingerprint the WebAssembly and JavaScript payloads of known mining libraries and detect the stratum mining protocol at the network level. This catches miners that are self-hosted, renamed, or obfuscated, which a domain blocklist alone would miss.

What delivery formats are available?

The category is offered as DNS RPZ feeds, script-fingerprint indicators for endpoint and browser tools, a real-time REST API with sub-10ms responses, and bulk feeds for offline enrichment, with SDKs for Python, Node.js, Go, Java, and C#.

Related Categories

Combine cryptomining protection with related threat categories for full coverage

Stop Cryptojacking and Resource Theft

Protect compute resources and control energy costs by blocking mining pools and cryptojacking scripts. 480,000 domains classified and continuously refreshed.