It was the first day of freshmen year at Penn State’s State College campus, and along with bed sheets, clothing and books, Patrick Cines had an unusual looking computer. He did not plan to write term papers or do research on it.
Source: Patrick Cines
Patrick Cines’s homemade cryptocurrency miner that was in his dorm room at Penn State’s State College Campus.
“What they are not thinking about is the pivot where that attacker could then use that machine to then attack the organization. And then it becomes something that they do worry about,” he added.
Cines is not alone. Vectra did a study of mining on 11 college campuses and found instances on mining at every school. In fact, the universities were seeing students set up mining operations between one to four times every day.
Yet many types of mining software communicate with computers across the globe, making it easier for them to be attacked by hackers. That breach can then spread from a student’s personal computer across the university’s network, according to Banic.
Cines said he heard of computers, but not at Penn State, that had been taken over by malware, but thinks the risk is low. “I think that’s a separate vulnerability, and it goes more to the security that the schools have, or should have. I think mining itself does not open up schools.”
Source: Patrick Cines
Sticker shock for electricity
Still, malware is not the only risk to universities. Mining by itself can send electricity bills soaring.
“I think there are a lot of universities that don’t know this is happening. I don’t think that they would want it to happen either, considering it costs $4,700 to mine one bitcoin. That’s about 10 percent of the annual tuition at a private university,” Banic said.
Cines was not paying his electric bill — Penn State was.
“I think students should be allowed to” mine for crypto, he told CNBC. “They’re paying tuition. Their parents are paying tuition. That’s covering electricity,” he said. Cines was open about his mining activity and never hid it, but he never asked if it was allowed.
In a statement sent to CNBC via email, Penn State said it has “policies in place to oversee use of our campus’ network, Internet and other IT resources, including the following policy: AD96 Acceptable Use of University Information Resources. All members of the University community have individual and shared responsibilities to protect the University’s information assets and comply with applicable federal and state laws and regulations, and University policies.”
However, the policy Penn State pointed out CNBC to does not mention cryptocurrency. With that in mind, other universities are more specific with their goal of stopping miners.
“We have an acceptable usage policy, which all students and employees have to view and agree to. And in the policy it says that you can’t use institutional resources for personal gain, or for a crypto currency,” said Patricia Patria, the vice president for information technology and chief information officer at Massachusetts’ Worchester Polytechnic Institute (WPI).
Patria declined to say how often WPI detects cryptominers, but said “we see an increase in frequency as the value of Bitcoin increases.”
WPI has sophisticated software that can detect mining down to the I.P. address of the computer it is coming from. When a student mining operation is detected, “We have a process to bring them into our IT office, they sit down with our security officer, we explain what they might’ve done wrong, because this is a university, so we educate here,” Patria said.
“Sometimes they wonder why they can’t do it, and we explain what a resource drain it is to our equipment and to electricity.”
Omar Marques, SOPA Images | LightRocket | Getty Images
The Bitcoin logo is seen on a mobile phone.
Additionally, the mining problem is not just happening on campus.
“Cryptomining is up 4.5 to 5 times. And it’s across every place. Forty percent of those locations are enterprise businesses.” Vectra’s Banic said. “There are probably employees who, as you walk up to their desk, they switch what they’re doing because maybe what they were doing was mining bitcoin.”
In order to detect the mining, businesses need to look at their internal network, instead of just looking at outside threats.
“Most businesses are looking at what’s happening from the internet to protect them from threats from the outside,” Banic said. “You can actually kill the bitcoin mining process on the machine with the right kind of endpoint software.”
As for Penn State graduate Cines, he said his dorm room mining made him approximately $10,000, and helped make him who he is today, working for a major tech company.
“[Mining] was my personal introduction to tech and being in the Blockchain space. So I was really excited to just see every single thing that I did afterwards definitely shaped my college career,” he said.
On the Money airs on CNBC Saturday at 5:30 am ET, or check listings for air times in local markets.