A Critical 9.8/10 Vulnerability in macOS Is Quietly Funding Hackers With Your Computing Power
Hackers have been exploiting a critical flaw in macOS Screen Sharing, rated a jaw-dropping 9.8 out of 10 on the CVSS severity scale, to silently install Monero miners on victims' machines, the Dutch cyber agency confirmed this week.
This is not a theoretical threat. This is active. This is already running on unpatched Macs right now.
Why Crypto Holders Should Be More Worried Than Anyone Else
Monero, the privacy-first cryptocurrency favored by bad actors precisely because its transactions are untraceable, is the coin of choice for cryptojacking operations. But here is the part most coverage is missing: if hackers have enough access to your machine to install a Monero miner, they have enough access to look for everything else on it.
That means seed phrases saved in Notes. Browser extensions connected to MetaMask or Phantom. Exchange credentials stored in password managers. Hardware wallet PIN backups sitting in a folder you thought was private.
Cryptojacking is often just the visible layer. The data exfiltration is the real play.
Historical Precedent: When Mining Malware Signals a Broader Threat
This is not the first time macOS vulnerabilities have been weaponized against the crypto community. In 2023, the BlueNoroff group, linked to North Korea, used fake job offer documents to compromise Macs and target crypto wallets directly. Before that, the XCSSET malware strain specifically hunted for cryptocurrency wallet data on Apple devices.
Each time a high-severity macOS exploit surfaces in the wild, the pattern is consistent: the initial payload is something low-stakes like a miner, and the follow-up campaign goes after wallets. Crypto holders who ignored the miner warnings in past cycles paid for it later.
What the Market Should Watch
Monero itself has historically seen brief volume spikes when cryptojacking campaigns gain media attention, as awareness cuts both ways. Traders who tracked Monero on-chain during the 2021 cryptojacking wave saw elevated activity for weeks after disclosure. Watch XMR volume and mempool activity over the next 48 hours.
More broadly, any confirmed spike in compromised crypto wallets tied to this exploit would be a short-term sentiment hit for the market, particularly for assets held in software wallets on desktop devices.
What You Should Do Right Now
Update macOS immediately. Disable Screen Sharing if you do not actively use it. Move any meaningful crypto holdings to a hardware wallet if they are currently sitting in a browser extension or desktop app. Audit your machine for unexpected CPU usage spikes, the clearest sign a miner is running in the background.
The vulnerability is rated 9.8. Treat it like it is.