# Node Red starts mining Monero coins without my consent!

**URL:** <https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344>\
**Category:** General\
**Tags:** security\
**Created:** [28 July 2025 07:05 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344 "2025-07-28T07:05:06Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![devifast](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@devifast](https://discourse.nodered.org/u/devifast)\
**Post date:** [28 July 2025 07:05 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/1 "2025-07-28T07:05:06Z")

</div>

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/d/cdc72c7ee2ea08e3bfa013f8e5f4ad717e11c804.png)  
I noticed that Node red has started mining Monero cryptocurrency without my knowledge and permission. I remove the process in htop but after deploying the flow in Node red it reappears. How did this happen?

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [28 July 2025 07:10 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/2 "2025-07-28T07:10:26Z")

</div>

> [@devifast](#):
>
> How did this happen?

Your node-red instance is accessible from the internet ?

---

<div class="post-metadata">

**Author:** ![devifast](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@devifast](https://discourse.nodered.org/u/devifast)\
**Post date:** [28 July 2025 07:16 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/3 "2025-07-28T07:16:19Z")

</div>

Yes, it is available. But there is a password to access it.

---

<div class="post-metadata">

**Author:** ![Bobo](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bobo/32/8401_2.png) [@Bobo](https://discourse.nodered.org/u/Bobo)\
**Post date:** [28 July 2025 07:19 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/4 "2025-07-28T07:19:06Z")

</div>

That would have to be the slowest mining op in history.

---

<div class="post-metadata">

**Author:** ![Trying\_to\_learn](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/trying_to_learn/32/28400_2.png) [@Trying\_to\_learn](https://discourse.nodered.org/u/Trying_to_learn)\
**Post date:** [28 July 2025 07:23 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/5 "2025-07-28T07:23:22Z")

</div>

Although off topic:  
WHY is your Node-Red accessible from the internet?

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [28 July 2025 07:31 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/6 "2025-07-28T07:31:12Z")

</div>

> yes, it is available. But there is a password to access it.

Was it ever exposed to the internet before you added the username/password?

Is the username and password guessable?

You need to search your flows for exec nodes (probably need to scroll down and to the right a lot),

Better yet, probably delete the flows.json file and start again from scratch.

---

<div class="post-metadata">

**Author:** ![SwedishMike](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/swedishmike/32/101548_2.png) [@SwedishMike](https://discourse.nodered.org/u/SwedishMike)\
**Post date:** [28 July 2025 07:49 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/7 "2025-07-28T07:49:18Z")

</div>

From a security PoV, it would be interesting to see what they actually implemented in your environment @devifast.

If you have the time/willingness - could you please share what they set up in your flow(s?)

---

<div class="post-metadata">

**Author:** ![devifast](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@devifast](https://discourse.nodered.org/u/devifast)\
**Post date:** [28 July 2025 07:53 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/8 "2025-07-28T07:53:07Z")

</div>

That's exactly what I'm going to do, I'm going to do it from scratch.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [28 July 2025 07:54 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/9 "2025-07-28T07:54:42Z")

</div>

Although the hack may have gained access via Node-red, it will have attempted to spread beyond there.  
You should consider the entire Node-red machine compromised and possibly other devices on your network, perhaps even your router.

When you rebuild the machine, use a different, not common, Node-red user name and a properly secure password.  
**Do Not** allow the Node-red user access to sudo without a password.  
Only access from the internet via some sort of VPN, eg Zerotier or Tailscale. Don't use port forwarding.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [28 July 2025 08:13 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/10 "2025-07-28T08:13:30Z")

</div>

Added the security tag to this thread.

@devifast - please read the security FAQ's and security documentation regarding node-red.

Rule #1 is NEVER connect your Node-RED Editor endpoints direct to the Internet. Regardless of how secure you think you've made it.

Rule #2 is never connect your server direct to the Internet if you can possibly avoid it.

There are plenty of ways to avoid exposing your local network and servers to the Internet while still securely allowing access to specific endpoints.

* * *

Also, don't forget to change all passwords AFTER securing/resetting things. And make sure that you are using strong passcodes and not re-using them for different things.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [28 July 2025 08:26 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/11 "2025-07-28T08:26:12Z")

</div>

> [@devifast](#):
>
> Yes, it is available. But there is a password to access it.

Are you using https?

---

<div class="post-metadata">

**Author:** ![devifast](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@devifast](https://discourse.nodered.org/u/devifast)\
**Post date:** [28 July 2025 08:29 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/12 "2025-07-28T08:29:25Z")

</div>

No, I don't use https. I haven't been able to do it. If there's an article somewhere I'd be happy to read it.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [28 July 2025 08:41 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/13 "2025-07-28T08:41:29Z")

</div>

Using user/pwd without https is pretty much pointless.

But as others have said, don't rely on user/pwd even with https. Read, and understand, the docs pointed to earlier.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [28 July 2025 08:43 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/14 "2025-07-28T08:43:04Z")

</div>

> [@devifast](#):
>
> I don't use https

Without HTTPS (wire-level encryption), passwords are worse than useless, especially if you used just HTTP Basic security.

If you don't understand Internet security basics, you are strongly recommended to use a 3rd-party solution to protect everything. There are plenty around and a number are listed in the security threads already mentioned as well as more detailed implementation guides that you can search for on the forum.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [28 July 2025 09:00 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/15 "2025-07-28T09:00:43Z")

</div>

> [@jbudd](#):
>
> use a different, not common, Node-red user name

> [@Colin](#):
>
> Using user/pwd without https is pretty much pointless.

Just out of interest, what was your Node-red user name?

If it was anything even vaguely uncommon, the odds are that your name and password were sniffed out of your network traffic at the coffee shop, or wherever.

---

<div class="post-metadata">

**Author:** ![devifast](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@devifast](https://discourse.nodered.org/u/devifast)\
**Post date:** [28 July 2025 09:53 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/16 "2025-07-28T09:53:17Z")

</div>

I don't understand the question correctly.

---

<div class="post-metadata">

**Author:** ![Trying\_to\_learn](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/trying_to_learn/32/28400_2.png) [@Trying\_to\_learn](https://discourse.nodered.org/u/Trying_to_learn)\
**Post date:** [28 July 2025 09:54 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/17 "2025-07-28T09:54:43Z")

</div>

The question is:  
You said you have to log into Node-Red's editor.

What name / password did you use?  
(Given that it is now academic, as you WILL be changing it now anyway.)

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [28 July 2025 10:10 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/18 "2025-07-28T10:10:15Z")

</div>

Perhaps I misunderstood your posts.  
You can setup a username and password for the Node-red editor.  
Then at login you should see this screen

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/3/c3810a5edf1d388dc98f12fb822bfd7894bd99d0.png)

I think that most cases we have seen of hacked Node-red did not have this setup.

A hacker who gets this far knows you have Node-red but they have to guess user names and passwords.  
There is nothing in Node-red to respond to many failed login attempts, so they _could_ keep trying different combinations over an extended period.

So I wondered if your user name was one commonly guessed eg "root", "admin", "nodered".  
If not, it seems likely that the attacker already knew your user name and password.

I only asked about the user name, I don't think it's good to reveal passwords, even expired ones.

---

<div class="post-metadata">

**Author:** ![devifast](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@devifast](https://discourse.nodered.org/u/devifast)\
**Post date:** [28 July 2025 10:14 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/19 "2025-07-28T10:14:23Z")

</div>

Don't ask so we don't expose ourselves. 🙂

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [28 July 2025 10:16 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344/20 "2025-07-28T10:16:15Z")

</div>

> [@devifast](#):
>
> Don't ask

Fair enough!

> [@devifast](#):
>
> so we don't expose ourselves

How's that going for you? 🙃

[Next page](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344.md?page=2)
