XMR mining app, built with Vue.js, D3 and CoinHive
github.com
github.com
Another option is to build your own. I published one of the more unapproachable aspects, which is an Emscripten-compiled implementation of the Cryptonight hash function [0]. One could slap a basic WebSocket proxy on top of existing mining server, and the adding the coordination logic in Javascript in the client.
There are already malicious websites using hidden windows to mine XMR, but to the benefit of the person in control of the site rather than the people who pay the electricity bills:
https://arstechnica.com/information-technology/2017/11/sneak...
Extremely unlikely. Even GPU mining with good hardware cuts it close with energy consumption depending on your energy costs.
But then there's the cost of the hardware which may be difficult to recoupe.
What? This is seriously wrong. ROI fluctuates between 200-600% for XMR and its derivatives.
Regardless, I find it hard to believe CPU mining using JavaScript in a browser is even remotely energy efficient.
This is not the most power efficient setup (as I said, there are far, far more efficient cards, especially when run in tandem) but it is the most sought-after card due to density. Regardless, it's exceptionally profitable to mine if you already own the card.
JS mining only takes a slight performance hit compared to native, actually; asm.js and others provide very good results since the problem is memory-hard, not computationally bound. It is definitely energy efficient and worth doing if all you care about is ROI vs. marginal utility rates in most American cities (perhaps not some of California). Nicehash built their business model around exactly that, which is the real reason people like libraries like the OP's - it's a distributed way to get people mining, not for the individual person themselves.
The answer to the question "should I mine [coin x]" in order to make money is usually "no". You should mine that coin because you care about the network's security and decentralization or not at all. If you have access to next-generation mining hardware or cheaper-than-normal electricity, you might have a case for "yes". Or, as you indicate, if you have a malicious way to run the miner or mostly-malicious-"not-too-clearly-disclosed-to-end-user", that is almost certain to make money.
Hundreds of trillions in global wealth and $100 trillion in annual economic output are powered by very predictable self-interest. You can build trust networks around it and you can build regulations based on it, precisely because it's extraordinarily predictable and universal to the extent necessary for the whole system to function with billions of participants.
I stopped as I was unhappy with the effects of proof of work on electricity supply and the wear on my GPU, but the amount I mined at current market price is worth around 3x that, making it quite a bit more profitable.
Of course, if you believe the value will increase at some future point you're most likely better off just buying the coin and hodling it :)
I think this is the key point. If it costs more in electricity than the current value it is cheaper and easier to just buy some.
Option 1: Spend $10 to mine $5 worth of BTC
Option 2: Spend $10 to obtain $10 worth of BTC
If the market goes up, you are better served by the latter option.
Im using nanopool right now.
It's an equilibrium.
Currently, it will cost around $2bn to buy the hashing power to control Bitcoin - that's the price of one Stealth Bomber.
So what if the bitcoin hash rate drops to say even 10% of current levels. Yes, it'll be way easier for other actors to come back and control 51% but you made my point: that can be done right now for $2bn.
No one ever talks about the fallout effects if a 51% attack does occur.
First of all, we can detect double spends. We have the complete history and just because the head chain was changed doesn't mean the old chain was forgotten.
The mere act of performing a 51% attack becoming public knowledge will crash the price and now the attacker gets devalued coins. Might not even be worth it.
Secondly, 51% attacks are hard. I don't know where you got the $2bn number above but I'm guessing its the equivalent of the current network hash rate.
To double spend a transaction 6 blocks back that means you need to mine 7 blocks before the other 49% of the network mines 1 block.
I choose 6 blocks back as thats the number of blocks most software/people consider needed to consider a transaction confirmed. With bitcoin's target of 10mins/block that is one hour of transactions.
It seems that 51% attack really requires a 7/8 = 87.5% attack. *
* Technically this only needs to be sustained until caught up with the current head chain length and then you can resume 51%.
Your attack scenario assumes an attacker who wants to extract a financial gain from his advantage while keeping a long position.
However, there are scenarios where an attack might benefit from a crashing bitcoin or the ability to deliver a plausible threat to trigger that crash
An example could be a nation state who would like to remind its negotiating partner, how easily they could establish control over a network that holds a substantial amount of foreign wealth. China obviously. Another one would be an investor who wants to short bitcoin in a massive scale (This has been done before, think of George Soro's 10bn GBP bet against the Bank of England)
Crashing seems a lot easier that trying to double spend. A majority hasher could simply ignore all blocks that are generated from the minority and mine only their own blocks, containing nothing but dummy transactions between the attackers wallets. The minority miners would at a 50% chance mine a new "honest" block and at 50% mine an attackers block, giving the attackers blockchain an 75 over 25 advantage. Since there are no real transactions in the attackers blocks, there would be no way to move bitcoins around anymore, holding them literally hostage.
If there is a way to make a profit from a large scale attack, then that large scale attack will be made some day.
Difficulty curves and such cause great opportunity for smart miners, especially now that Nicehash is offline.
There seems to be a bit of disagreement over this.
Let me ask it another way, would it be worthwhile for someone too lazy to replace the dead battery in their thermostat to mine some coins to add a little heat to their apartment and make a couple bucks in the process?
Yes: https://whattomine.com/coins
Actually, I'm using a computer mining Moneros at 2000H/s in a closed room to help dry a damp wall. The rig converts 250W Power to heat (for the wall) and produces Moneros worth $200/m - leaving me $100 after paying for electricity the computer and the air dehumidifier consumed.
Assuming m = Monero I think you will be in for a good surprise.
Is there any coinhive alternative? That would be a progress.
It should take only 1% of profit instead of CoinHives 30%.
Think about it: they're hosting a WASM blob on their site for which they don't have the source code and can't tell with certainty what exactly it's doing.
With so many faces on their team page (and a dog!), you'd think they'd have the resources and competence to build something of their own.
As for privacy, that's okay too. Once you send Monero to your own wallet, Coinbase has no idea what you do with it afterwards, just like withdrawing cash from a bank.