Miner Malware
Malware on ASICs exists, and it earns the simple way: your electricity, their wallet. Infection almost always arrives with firmware from a random source or through an open port.
How ASICs get infected and what it looks like
Two main routes. The first is an "improved firmware" from a chat or a forum: inside there is real tuning plus a stowaway that sends part of your hashrate to someone else's pool or swaps the payout wallet. The second is a web interface or SSH exposed to the internet with the factory password: bots scan addresses around the clock and walk right in.
The infection looks unremarkable. Hashrate on your pool sits steadily below the miner's own number beyond the declared DevFee. The log shows connections to pools you never configured. The config has an extra pool or an altered wallet. Sometimes the malware hides deeper and survives a settings reset, because it lives in the firmware itself.
You can check all this in one evening: compare the pool's hashrate with the ASIC's own over a day, read the connection list, reread the payout config with your own eyes. A gap larger than the declared DevFee with no explanation is a diagnosis already.
The cure is radical and reliable: a clean flash from an SD card with the official image, new passwords, closed ports. Half measures like deleting the extra pool from the config do not work: the malware puts it back after a reboot.
The short version
| Infection routes | firmware from chats, open ports, passwords |
| Main symptom | pool hashrate below the ASIC's beyond DevFee |
| Where to look | connection log and payout config |
| The cure | clean flash from SD, passwords, closed ports |
| What fails | spot-cleaning the config |
How to stay clean
Firmware only from the developer's site or from a supplier you pay money to and can ask questions of.
Not a single ASIC port facing the internet: remote access goes through a VPN, not through port forwarding.
Change the factory passwords on every miner, SSH included, the day you buy it.
Once a month, compare pool hashrate against your miners' own: this catches breakdowns too, not only malware.
A case from practice
A farm of eight miners started earning about ten percent less after an "overclocked firmware" from a Telegram chat. The owner's pool looked fine, but the log of every ASIC showed a connection to an unfamiliar address once an hour. A clean flash from an SD card, new passwords, a VPN instead of forwarding, and the income came back in a single evening.
Related terms
Where to go next on the site
Software
- Software firmware
- Bitmain Stock Firmware firmware
Hardware
- ASIC Miner knowledge base
Questions and answers
Does malware happen on stock firmware
Through open ports and factory passwords, yes: the malware installs on top of stock like an update. Stock itself from the manufacturer's site is clean.
Is there an antivirus for ASICs
No, and you do not need one. Hygiene is simpler: official images, closed ports, your own passwords and a regular hashrate check.
I bought a secondhand ASIC, how do I check it
Treat it as infected by default: clean flash from an SD card, your own passwords, your own config. Half an hour of work closes the question for good.
How the terms connect
Every link in the chain is clickable. Orange marks where you are now.
Looking for an ASIC miner
The catalog holds 212 models. You can compare them by hashrate and by joules per terahash, then plug your own rate into the calculator and see what stays in your pocket.
Page written and checked by Denys Klimchuk. Updated .