Your laptop is sitting on a desk, doing nothing more dramatic than displaying a webpage. Yet its fan suddenly sounds like a small aircraft preparing for takeoff, the battery percentage drops by the minute, and every click arrives with the enthusiasm of a sleepy snail. You may be dealing with browser-based cryptocurrency mining, commonly called cryptojacking.
Despite the popular phrase “Bitcoin mining in your browser,” most browser miners do not literally mine Bitcoin. Bitcoin mining requires specialized hardware and enormous computing power. Browser-based miners have historically targeted cryptocurrencies that are friendlier to ordinary CPUs. However, the practical problem is the same: a website or malicious extension quietly uses your processor, electricity, and battery to generate cryptocurrency for someone else.
The good news is that you do not need to wrap your computer in aluminum foil or interrogate every JavaScript file personally. Modern browsers, content blockers, security software, and a few sensible habits can stop most mining scripts before they turn your device into an unpaid digital pickaxe.
What Is Browser-Based Cryptocurrency Mining?
Browser mining uses code delivered through a webpage to perform cryptocurrency calculations on a visitor’s device. The workload may run through JavaScript, WebAssembly, background workers, or related web technologies. It generally continues while the affected page remains open, although malicious extensions and installed malware can keep mining after the original tab is closed.
Not every use of browser mining is automatically malicious. A website could theoretically ask visitors for clear permission and offer mining as an alternative to advertising. The problem is consent. When a site hides the activity, buries it in vague terms, or continues consuming resources after you leave, it crosses into cryptojacking.
Security agencies and researchers describe cryptojacking as the unauthorized use of another person’s device to mine cryptocurrency. Browser-based miners commonly arrive through compromised websites, malicious advertising, unsafe extensions, or attacker-controlled pages. More serious campaigns may also install persistent mining software on the operating system.
How To Tell Whether a Website Is Mining Cryptocurrency
A noisy fan is not enough to convict a website. Video calls, browser games, animation-heavy pages, streaming services, and approximately fourteen open spreadsheets can all increase CPU use. Look for a combination of symptoms instead.
Sudden CPU Usage
Your processor usage may jump sharply as soon as a particular page loads. On a computer that was previously idle, a suspicious tab might consume 50%, 80%, or nearly all available CPU capacity.
Heat and Fan Noise
Mining calculations produce sustained processor activity. That creates heat, which causes the cooling fans to speed up. A laptop that becomes unusually hot while displaying a simple article deserves investigation.
Rapid Battery Drain
CPU-intensive tasks consume far more power than ordinary browsing. If your battery begins disappearing faster than free snacks in an office kitchen, close suspicious tabs and check system activity.
Browser Lag
Scrolling may become choppy, videos may stutter, and switching tabs may take longer. The entire computer can feel sluggish because the miner is competing with legitimate applications for processor time.
The Problem Stops When a Tab Closes
If CPU usage returns to normal immediately after closing one webpage, the activity was probably connected to that page. If high usage continues after the browser is completely closed, you may have a malicious extension, unwanted program, or system-level miner.
How To Block Bitcoin Mining In Your Browser
1. Turn On Your Browser’s Built-In Protection
Start with the protection already included in your browser. It requires no extra installation and provides a useful first layer of defense.
Firefox
Firefox includes cryptominer blocking in Enhanced Tracking Protection. Open Settings, select Privacy & Security, and confirm that Enhanced Tracking Protection is enabled.
The Standard setting already blocks known cryptominers. Strict mode blocks additional tracking content in regular windows, although it can occasionally interfere with login forms, embedded videos, payments, or comments. Use Strict mode when you want broader protection, but be prepared to create an exception for a trusted site that stops working correctly.
Microsoft Edge
Open Settings, choose Privacy, search, and services, and make sure Tracking prevention is turned on. Edge says its tracking prevention system detects potentially harmful trackers, including resources classified as cryptomining or fingerprinting.
Balanced is the recommended everyday setting. Strict blocks more resources but may break certain site features. Avoid adding broad exceptions because an exception can also permit potentially harmful trackers on that website.
Google Chrome
Chrome does not present a simple switch labeled “Block cryptocurrency miners.” Instead, combine its security checks, site permissions, and a trustworthy content-blocking extension.
Go to Settings > Privacy and security and run Safety Check. Chrome can identify security problems involving updates, extensions, permissions, and other browser settings. You can also open Site settings to review which websites have stored data or received permissions.
For a site you do not trust, block JavaScript specifically for that domain. Disabling JavaScript globally will stop most browser miners, but it will also break menus, forms, video players, shopping carts, and much of the modern web. Per-site blocking is the less chaotic option.
Safari
Safari supports content-blocking extensions that can prevent unwanted scripts and resources from loading. After installing a reputable blocker, open Safari’s website settings and make sure content blocking is enabled for suspicious sites.
Apple users should also keep Safari and the operating system updated. Safari updates are normally distributed through macOS, iOS, or iPadOS updates rather than through a separate browser updater.
Current vendor documentation confirms that Firefox blocks known cryptominers by default, Edge detects cryptomining trackers, Chrome provides site-permission and Safety Check controls, and Safari supports content blockers for unwanted resources.
2. Install a Reputable Content Blocker
A maintained content blocker is one of the most effective ways to stop browser mining scripts. It compares network requests against filter lists containing known mining services, malicious domains, trackers, and abusive scripts.
For Firefox, the official uBlock Origin extension blocks coin miners through its default filter lists. For current versions of Chrome, uBlock Origin Lite is the Manifest V3-compatible edition and states that it blocks miners immediately after installation. Edge users can install compatible content blockers from the Edge Add-ons store or supported extension stores. Safari users can choose a reputable Safari content blocker.
Check the extension’s developer, store listing, permissions, update history, and official project page before installing it. Similar names do not guarantee that two extensions come from the same developer. A fake or abandoned “security” extension can be worse than having no extension at all.
A content blocker is most effective when its lists update automatically. Hard-coding a few famous mining domains into your hosts file may stop yesterday’s miner while cheerfully allowing tomorrow’s. Maintained lists adapt as domains and scripts change.
3. Remove Suspicious Browser Extensions
Extensions can read webpage content, alter traffic, inject scripts, and run in the background. Those abilities are useful for legitimate password managers and accessibility tools, but they are also attractive to attackers.
Open your browser’s extension-management page and remove anything you do not recognize, no longer use, or installed from an unofficial source. Pay particular attention to extensions that appeared shortly before the fan noise or CPU spikes began.
Do not assume that an extension is safe simply because it worked normally for several years. An abandoned extension can be sold, compromised, or updated with unwanted behavior. Keep the smallest extension collection that meets your needs. Your browser toolbar should not look like a digital flea market.
4. Block JavaScript on Suspicious Websites
Most browser miners require active scripting. Blocking JavaScript for an untrusted site can prevent the mining code from running at all.
Use this approach selectively. A news article might remain readable without JavaScript, while a banking portal or web application may become unusable. Add known and trusted sites to your allowed list rather than disabling protection everywhere because one page complains.
Advanced users can use a script-control extension to allow first-party scripts while blocking unfamiliar third-party code. This provides powerful protection, but it requires patience. Expect some websites to resemble furniture delivered without assembly instructions until you approve the resources they genuinely need.
5. Use DNS Filtering as an Additional Layer
A security-focused DNS service can block requests to known malicious or cryptomining domains before the browser connects to them. DNS protection can cover multiple browsers and, when configured at the router level, every device on the network.
However, DNS filtering is not a complete replacement for browser filtering. DNS systems generally see domains, not individual scripts or URL paths. They may miss mining code hosted on the same domain as legitimate website content. Use DNS filtering as a second fence, not the entire castle wall.
6. Update the Browser and Operating System
Browser updates contain security patches, improved malicious-site detection, extension-platform changes, and performance fixes. Turn on automatic updates and restart the browser when an update is ready. A browser that has downloaded an update but has not restarted is like a firefighter who reached the building but stayed in the truck.
Update the operating system as well. Cryptojacking is not limited to webpage scripts. Attackers may exploit software vulnerabilities or persuade users to install fake utilities containing persistent mining malware.
7. Run a Trusted Malware Scan
Close the browser completely and watch CPU usage for several minutes. If the computer remains hot or busy, run a full scan with the security software built into your operating system or another established security product.
Persistent cryptojackers may disguise themselves as utilities, scheduled tasks, background services, browser helpers, or fileless processes. A 2026 campaign documented by Microsoft used lookalike download sites impersonating familiar system and hardware tools. Some infections also established remote access, creating risks beyond cryptocurrency mining.
8. Clear Site Data and Revoke Permissions
After identifying a suspicious site, clear its cookies, cached files, service-worker data, and stored permissions. This step removes local data that could reload unwanted behavior or preserve intrusive settings.
Also review notification permissions. Malicious sites often pressure visitors to click “Allow” and then send deceptive alerts that lead to fake updates, questionable downloads, or additional scam pages.
How To Identify the Tab Using Your CPU
Guessing is entertaining in game shows, but less helpful in security troubleshooting. Use process-monitoring tools to find the actual resource hog.
- Chrome and Edge: Press Shift + Esc to open the browser task manager. Sort processes by CPU usage.
- Firefox: Enter about:processes in the address bar to inspect tab and extension activity.
- Windows: Open Task Manager and sort the Processes list by CPU.
- macOS: Open Activity Monitor and sort by the % CPU column.
Close the suspicious tab and observe the result. An immediate CPU drop is strong evidence that the page caused the load, although it does not prove the activity was mining. Poorly written advertisements, broken animations, and runaway application code can produce similar symptoms.
Protection for Website Owners
Website operators can unknowingly distribute mining code after a compromised plugin, advertising partner, analytics script, or content-management account is abused.
Use a strict Content Security Policy to restrict which domains may deliver scripts, frames, workers, and network connections. Remove unused third-party code, update plugins promptly, secure administrator accounts with multifactor authentication, and monitor pages for unexpected script changes.
Subresource Integrity can help verify eligible third-party files, while automated security scanning can flag unauthorized modifications. A clean server is important, but so is the supply chain of scripts loaded after the main page arrives. Modern web-security guidance recommends HTTPS, carefully controlled cross-origin requests, and a restrictive Content Security Policy.
Practical Experience: What a Browser-Mining Cleanup Usually Looks Like
Consider a realistic troubleshooting session. A user reports that a relatively new laptop becomes hot whenever a particular streaming directory is open. The page itself contains no video; it merely lists links. The fan begins running within seconds, battery drain accelerates, and scrolling becomes jerky.
The first useful move is not installing five security suites at once. It is isolation. The browser task manager shows that one tab is consuming most of the CPU. Closing that tab immediately returns processor usage to normal. That tells us the load is tied to the page rather than a permanent system process.
Next, the page is opened again in a browser profile with a reputable content blocker enabled. CPU usage remains low, and the blocker reports several denied third-party requests. This does not automatically prove every blocked request was malicious, but it demonstrates that an external resource was responsible for the unusual workload.
The extension list is then reviewed. Two old coupon extensions and a forgotten video downloader are still installed. Neither is necessary, so both are removed. This is an important lesson: even when the immediate cause is a webpage, reducing unnecessary extensions shrinks the browser’s overall attack surface.
The suspicious site’s stored data and notification permissions are cleared. The browser is updated and restarted, followed by a malware scan. The scan finds nothing, and CPU usage stays normal after the browser closes. At that point, the evidence supports a browser-based resource-abuse incident rather than installed mining malware.
A different outcome would require a different response. Suppose CPU usage remained high after every browser window was closed. In that case, repeatedly adding browser filters would be like changing the locks while the intruder was already in the basement. The next steps would be checking startup programs, scheduled tasks, installed applications, security alerts, and background processes. A full system scan would become essential.
Another common experience is overblocking. A user installs several script blockers, activates every filter list available, and then discovers that payment pages, embedded maps, and login buttons no longer work. Frustrated, the user disables all protection permanently. That creates a worse result than using a balanced configuration.
The practical approach is layered and measured: enable the browser’s built-in protections, install one trustworthy blocker, remove unnecessary extensions, update software, and investigate unusual CPU activity. Create narrow exceptions only for trusted sites and only when a feature genuinely needs them.
Finally, watch for patterns rather than panicking over a single noisy fan. Sustained high CPU on a simple page, repeated behavior on the same domain, unexpected background processes, and rapid battery drain together justify concern. A brief spike while a page loads may be completely normal. Good security depends on observation, not on declaring every animated banner an international cryptocurrency conspiracy.
Frequently Asked Questions
Can a website mine Bitcoin without permission?
A website can execute computational code in your browser when scripting is allowed, but directly mining Bitcoin in a normal browser is generally impractical. The broader threat is unauthorized cryptocurrency mining involving coins and algorithms suitable for CPUs or compromised GPUs.
Will an ad blocker stop all cryptojacking?
No single tool guarantees complete protection. A good blocker can stop known mining scripts and malicious domains, but it may miss new, first-party, obfuscated, or installed miners. Combine blocking with updates, extension reviews, and malware protection.
Does private browsing prevent browser mining?
No. Private browsing mainly limits local history, cookies, and stored session data. A webpage can still use processor resources while it is open unless the browser or a content blocker stops the relevant code.
Can cryptojacking damage a computer?
Modern systems are designed to manage heat by increasing fan speed or reducing performance. Nevertheless, sustained mining can increase electricity use, battery wear, heat, noise, and hardware stress. It also signals that an unauthorized party is controlling part of your device’s workload.
Should I disable JavaScript completely?
Global JavaScript blocking offers strong protection but breaks many websites. Most users will have a better experience using per-site JavaScript controls, built-in tracking protection, and a maintained content blocker.
Conclusion
To block Bitcoin mining in your browser, begin with the tools closest to the problem. Enable built-in cryptominer or tracking protection, use a reputable content blocker, remove questionable extensions, and deny JavaScript to suspicious websites. Keep the browser and operating system updated, and run a malware scan when high CPU usage continues after the browser closes.
Browser cryptojacking is less mysterious once you know where to look. A task manager can identify the hungry tab, a blocker can stop abusive requests, and a careful extension cleanup can remove unwanted background behavior. Your computer should work for younot spend the afternoon generating pocket change for a stranger.
Note: Browser menus and extension support can change over time. Use current browser versions, verify extension developers carefully, and avoid disabling security protections globally merely to repair one broken website.