+34 641 10 27 16

Miner Malware

Knowledge base

Who mines on your hardware besides you

· Updated

Malware on ASICs exists, and it earns the simple way: your electricity, their wallet. Infection almost always arrives with firmware from a random source or through an open port.

How ASICs get infected and what it looks like

Two main routes. The first is an "improved firmware" from a chat or a forum: inside there is real tuning plus a stowaway that sends part of your hashrate to someone else's pool or swaps the payout wallet. The second is a web interface or SSH exposed to the internet with the factory password: bots scan addresses around the clock and walk right in.

The infection looks unremarkable. Hashrate on your pool sits steadily below the miner's own number beyond the declared DevFee. The log shows connections to pools you never configured. The config has an extra pool or an altered wallet. Sometimes the malware hides deeper and survives a settings reset, because it lives in the firmware itself.

You can check all this in one evening: compare the pool's hashrate with the ASIC's own over a day, read the connection list, reread the payout config with your own eyes. A gap larger than the declared DevFee with no explanation is a diagnosis already.

The cure is radical and reliable: a clean flash from an SD card with the official image, new passwords, closed ports. Half measures like deleting the extra pool from the config do not work: the malware puts it back after a reboot.

The short version

Infection routesfirmware from chats, open ports, passwords
Main symptompool hashrate below the ASIC's beyond DevFee
Where to lookconnection log and payout config
The cureclean flash from SD, passwords, closed ports
What failsspot-cleaning the config

How to stay clean

Firmware only from the developer's site or from a supplier you pay money to and can ask questions of.

Not a single ASIC port facing the internet: remote access goes through a VPN, not through port forwarding.

Change the factory passwords on every miner, SSH included, the day you buy it.

Once a month, compare pool hashrate against your miners' own: this catches breakdowns too, not only malware.

firmware from a chatstowaway insideMiner Malwareforeign pool in the logclean flash from SD

A case from practice

A farm of eight miners started earning about ten percent less after an "overclocked firmware" from a Telegram chat. The owner's pool looked fine, but the log of every ASIC showed a connection to an unfamiliar address once an hour. A clean flash from an SD card, new passwords, a VPN instead of forwarding, and the income came back in a single evening.

Related terms

Where to go next on the site

Software

Hardware

Questions and answers

Does malware happen on stock firmware

Through open ports and factory passwords, yes: the malware installs on top of stock like an update. Stock itself from the manufacturer's site is clean.

Is there an antivirus for ASICs

No, and you do not need one. Hygiene is simpler: official images, closed ports, your own passwords and a regular hashrate check.

I bought a secondhand ASIC, how do I check it

Treat it as infected by default: clean flash from an SD card, your own passwords, your own config. Half an hour of work closes the question for good.

How the terms connect

Every link in the chain is clickable. Orange marks where you are now.

Back to the term list

Looking for an ASIC miner

The catalog holds 212 models. You can compare them by hashrate and by joules per terahash, then plug your own rate into the calculator and see what stays in your pocket.

Page written and checked by Denys Klimchuk. Updated .