- Hackers are targeting Macs to mine Monero and steal access to valuable data.
- A macOS flaw lets attackers gain root access without a password and install crypto miners.
- Find out how to spot cryptojacking on your Mac and protect it from similar attacks.
Apple Macs have long carried a reputation as the safer choice. But that reputation just took a hit.
On August 6, 2026, Apple patched a critical flaw in macOS Screen Sharing, its built-in remote-control feature. Days later, the Netherlands’ National Cyber Security Centre (NCSC) confirmed the bug, tracked as CVE-2026-65400, was already being used in the wild. Attackers on multiple internet-exposed Macs gained full root access and quietly installed Monero cryptominers.
The flaw itself is an authentication bypass. Screen Sharing normally runs on port 5900 and requires a username and password. Apple traced the issue to a state-management error, meaning the software failed to properly track and verify session data, letting an attacker connect without any credentials at all.
Machines most at risk are those with port 5900 exposed directly to the internet, often through a router port-forward or a public IP setup. Once in, the attacker doesn’t just mine crypto. Root access opens the door to persistence, data theft, credential harvesting, and further malware deployment.
Is This part of a Bigger shift?
Cryptomining malware has historically clustered on Windows machines, Linux servers, and cloud infrastructure, environments with cheap, abundant compute and a low chance of detection.
But the evidence suggests attackers are branching out. Security firm Moonlock’s mid-2026 threat report found that criminal groups now run the same campaign infrastructure, servers, domains, and droppers across both Windows and Mac targets, simply swapping the final payload.
Earlier this year, endpoint security firm Mosyle uncovered what it called one of the first Mac malware samples built with help from generative AI.
Crypto users themselves have also become a specific target. Mac-focused campaigns tied to North Korea’s Lazarus Group have gone after crypto and fintech employees, while separate operations have swapped legitimate wallet apps for tampered versions that steal recovery phrases.
Why Monero, and Why Macs
Attackers prefer Monero because it can be mined on ordinary CPUs and GPUs without specialized mining hardware. And its built-in privacy features make stolen proceeds more difficult to trace than Bitcoin. This means almost any hacked device, including a MacBook, can be used for mining.
Moreover, Macs are attractive because many are used by executives, developers, designers, and crypto holders, people who may have valuable data or crypto assets on their devices.
There is also a “confidence gap”: some Mac users believe their devices are safer from hacking, so they may be more likely to ignore security warnings or give suspicious apps too many permissions. Cryptojacking attacks take advantage of exactly these mistakes.
How to Tell If Your Mac Is Secretly Mining Cryptocurrency
A hacked Mac shows signs through poor performance, not pop-ups. Watch for:
- Loud fans when you’re not doing anything demanding
- A Mac that feels unusually hot
- Battery life that suddenly drops
- Browsing, typing, or other everyday tasks becoming slow
You can also check Activity Monitor. Open it through Spotlight or Applications > Utilities, then sort processes by CPU usage. If you see an unfamiliar process using a lot of CPU while your Mac is idle, that is a warning sign.
Staying Protected
The simplest fix is to update your Mac to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9. If you can’t update right away, turn off Screen Sharing and Remote Management under System Settings > General > Sharing until you can.
The bigger lesson is that Macs aren’t automatically safe from attacks, especially if you keep cryptocurrency on them.
Related: Apple Faces Lawsuit After Fake Bitcoin Wallet Allegedly Stole $1.8 Million
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.