Skip to Content

What to Do If Your Mining Operation Gets Hacked: An Incident Response Checklist

August 7, 2026 by
What to Do If Your Mining Operation Gets Hacked: An Incident Response Checklist
admin@sustainhash.com

What to Do If Your Mining Operation Gets Hacked

An Incident Response Checklist for Medium- and Large-Scale Miners

Your mining facility is, in practical terms, a data center that also happens to hold a live claim on Bitcoin's block rewards. It runs 24/7, it's managed remotely through dashboards and APIs, and every machine on the floor is quietly contributing to a payout address. The combination of high value, constant connectivity, and often a lean operations team is exactly what makes mining farms an attractive target. Hosting providers, pools, and firmware vendors have all seen a rise in credential theft, firmware tampering, and payout-redirection attacks aimed at mining operations over the past few years.

This checklist is written for operators running fleets at meaningful scale. The kind of operation where an hour of confusion can mean a meaningful amount of lost hashrate, or worse, a drained wallet. It won't replace a formal incident response plan tailored to your environment, but it will give your team a clear, ordered sequence of actions to take the moment something looks wrong.

 

Know What You're Defending Against

Most mining-specific incidents fall into a handful of recognizable categories. Knowing the pattern helps your team recognize an attack faster:

  • Compromised remote management or fleet monitoring software, giving an attacker control over miner configuration and firmware.

  • Stolen mining pool credentials or API keys, used to redirect payouts to an unfamiliar wallet.

  • Malicious or tampered firmware pushed to ASICs, sometimes silently skimming a percentage of hashrate.

  • Exposed remote access points: VPNs, RDP, or management ports left open to the internet.

  • Insider misuse of legitimate credentials, including former employees or contractors.

  • Denial-of-service activity against your pool connection or monitoring stack, used as cover for a separate intrusion.

Triage: How Severe Is This?

Not every anomaly is a crisis, but every anomaly deserves a fast, consistent triage. Use a severity framework like the one below to decide how quickly to escalate and who needs to be pulled in.

Severity
What it looks like 
Target response time 
Low
Single miner offline, isolated alert, no evidence of unauthorized access Same business day
Medium
Unusual login activity, a rack or container flagged, unexplained hashrate dipWithin 1 hour
High
Confirmed unauthorized access, suspicious firmware, pool credentials likely exposedWithin 15 minutes
Critical
Payout address changed, wallet or pool account compromised, fleet-wide firmware tampering Immediate: treat as active theft

 


The First 60 Minutes

Once you've confirmed an incident is real, speed and order matter more than perfection. Work through these steps in sequence.

  1. Confirm it's real: Rule out benign explanations: a firmware update, a network hiccup, a pool outage, before you trigger a full response. False alarms cost far less than a slow real response, but crying wolf repeatedly will erode your team's urgency over time.

  2. Activate your incident response chain of command: Everyone on the operations team should already know who the incident commander is and how to reach them, day or night. Don't debate roles in the moment; rather, assign them in advance.

  3. Isolate affected systems: Pull compromised miners, controllers, or management servers off the network immediately. Segment first, investigate second. A machine that's still talking to the internet can still be used against you or can still be actively exfiltrating data.

  4. Freeze what can be frozen: Contact your mining pool immediately to lock the account and, if possible, pause or hold payouts. If a hot wallet is involved, move remaining funds to a secure, offline-controlled wallet if you're able to do so safely.

  5. Preserve evidence before you clean anything up: Take screenshots, export logs, and note timestamps before rebooting, reflashing, or wiping any device. Evidence you destroy in a rush to “fix it” can't be recovered later.

  6. Start a running incident log: Record what was observed, when, by whom, and what action was taken. This log becomes the backbone of your forensic review, your insurance claim, and any regulatory notification.


Containment: Stop the Spread

With the immediate danger controlled, focus on making sure the attacker can't regain a foothold or move further into your environment.

  • Rotate every credential the attacker could plausibly have touched: pool logins, API keys, monitoring dashboard accounts, wallet access, VPN certificates, and shared admin passwords.

  • Force re-authentication with multi-factor authentication everywhere it isn't already required, especially for pool and wallet access.

  • Segment your network so mining hardware, fleet management systems, and corporate IT sit on separate zones, if they aren't already.

  • Disable remote firmware update capability fleet-wide until you can confirm the update mechanism itself wasn't the entry point.

  • Physically inspect a sample of affected racks. In hosted or colocated environments, coordinate with your facility partner to confirm no unauthorized physical access occurred.


Investigate and Eradicate

Once the bleeding has stopped, the next job is understanding exactly what happened and making sure nothing malicious remains.

  • Bring in a forensic specialist: Internal if you have the expertise, third-party if you don't. Mining-specific incidents often require familiarity with ASIC firmware and pool infrastructure that generalist IT security teams may lack.

  • Trace the entry point: was it a phished credential, an exposed management port, a supply-chain issue with firmware, or something else?

  • Audit firmware integrity across the entire fleet, not just the machines that showed obvious symptoms: attackers who compromise one unit often attempt to move laterally to others.

  • Review pool payout history and any wallet transaction logs line by line for unauthorized changes to payout addresses.

  • Check whether the intrusion reached beyond the mining environment into corporate systems, financial systems, or customer data.


Recovery: Bringing Hashrate Back Online Safely

Getting machines mining again quickly is tempting, but rushing recovery is how operations get hit twice.

  • Rebuild affected machines from verified, clean firmware images. Do not use images from a backup taken before you know when the compromise actually started.

  • Bring the fleet back online in small batches rather than all at once, watching closely for repeat anomalies before scaling back up.

  • Manually re-verify pool and wallet configuration on every recovered device before it's allowed to contribute to full production.

  • Monitor hashrate, rejected shares, and payout addresses closely for the first 24 to 48 hours after recovery. A lingering compromise often resurfaces here first.


After the Dust Settles

The technical response is only part of the job. How you close out the incident shapes your legal exposure, your relationships, and your readiness for next time.

  • Meet your reporting obligations: this can include law enforcement, your cyber insurance carrier, regulators, and, if funds were stolen, the exchanges or pools that might be able to flag the destination wallet.

  • Communicate honestly and promptly with investors, partners, or customers who have a stake in the operation's uptime or security.

  • Write a post-incident report covering root cause, timeline, financial impact, and what changed as a result. Treat this as a living document, not paperwork to file away.

  • Update your incident response plan with the specific lessons from this event, and schedule a tabletop exercise to rehearse it before you need it for real.


The Best Response Plan Is One You've Already Rehearsed

Every step above works far better when it's been decided in advance rather than improvised under pressure. The operators who recover fastest from a breach are almost always the ones who had already answered the hard questions of who has authority to freeze a wallet at 3 a.m., which vendor gets the first call, and how machines get re-verified before they rejoin the fleet, long before an alert ever fired.

SustainHash Technologies works with medium- and large-scale mining operators to build incident response plans, harden fleet management infrastructure, and run tabletop exercises tailored to real mining environments. If your operation doesn't yet have a documented, rehearsed response plan, that's the single highest-leverage project you can start this quarter. Reach out to our operations & security team to get started.