en
Back to the list

Is Your Mac Secretly Mining Cryptocurrency? Here’s How to Find Out

source-logo  coinedition.com 1 h
image

Apple Macs have long carried a reputation as the safer choice. But that reputation just took a hit.

On August 6, 2026, Apple patched a critical flaw in macOS Screen Sharing, its built-in remote-control feature. Days later, the Netherlands’ National Cyber Security Centre (NCSC) confirmed the bug, tracked as CVE-2026-65400, was already being used in the wild. Attackers on multiple internet-exposed Macs gained full root access and quietly installed Monero cryptominers.

The flaw itself is an authentication bypass. Screen Sharing normally runs on port 5900 and requires a username and password. Apple traced the issue to a state-management error, meaning the software failed to properly track and verify session data, letting an attacker connect without any credentials at all.

Machines most at risk are those with port 5900 exposed directly to the internet, often through a router port-forward or a public IP setup. Once in, the attacker doesn’t just mine crypto. Root access opens the door to persistence, data theft, credential harvesting, and further malware deployment.

Is This part of a Bigger shift?

Cryptomining malware has historically clustered on Windows machines, Linux servers, and cloud infrastructure, environments with cheap, abundant compute and a low chance of detection.

But the evidence suggests attackers are branching out. Security firm Moonlock’s mid-2026 threat report found that criminal groups now run the same campaign infrastructure, servers, domains, and droppers across both Windows and Mac targets, simply swapping the final payload.

Earlier this year, endpoint security firm Mosyle uncovered what it called one of the first Mac malware samples built with help from generative AI.

Crypto users themselves have also become a specific target. Mac-focused campaigns tied to North Korea’s Lazarus Group have gone after crypto and fintech employees, while separate operations have swapped legitimate wallet apps for tampered versions that steal recovery phrases.

Why Monero, and Why Macs

Attackers prefer Monero because it can be mined on ordinary CPUs and GPUs without specialized mining hardware. And its built-in privacy features make stolen proceeds more difficult to trace than Bitcoin. This means almost any hacked device, including a MacBook, can be used for mining.

Moreover, Macs are attractive because many are used by executives, developers, designers, and crypto holders, people who may have valuable data or crypto assets on their devices.

There is also a “confidence gap”: some Mac users believe their devices are safer from hacking, so they may be more likely to ignore security warnings or give suspicious apps too many permissions. Cryptojacking attacks take advantage of exactly these mistakes.

How to Tell If Your Mac Is Secretly Mining Cryptocurrency

A hacked Mac shows signs through poor performance, not pop-ups. Watch for:

  • Loud fans when you’re not doing anything demanding
  • A Mac that feels unusually hot
  • Battery life that suddenly drops
  • Browsing, typing, or other everyday tasks becoming slow

You can also check Activity Monitor. Open it through Spotlight or Applications > Utilities, then sort processes by CPU usage. If you see an unfamiliar process using a lot of CPU while your Mac is idle, that is a warning sign.

Staying Protected

The simplest fix is to update your Mac to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9. If you can’t update right away, turn off Screen Sharing and Remote Management under System Settings > General > Sharing until you can.

The bigger lesson is that Macs aren’t automatically safe from attacks, especially if you keep cryptocurrency on them.

Related: Apple Faces Lawsuit After Fake Bitcoin Wallet Allegedly Stole $1.8 Million

coinedition.com