Hackers Target ComfyUI to Hijack GPU Resources for Cryptocurrency Mining
ComfyUI is a widely used open-source, node-based interface for building AI image-generation workflows with models such as Stable Diffusion. Its service is designed by default for trusted local networks. If administrators expose the interface directly to the internet without authentication, attackers can install malicious custom nodes through ComfyUI-Manager, turning high-end GPUs and other computing resources into cryptocurrency-mining targets.
Censys ARC discovered the campaign in March 2026 and disclosed on April 7 that more than 1,000 publicly accessible ComfyUI instances were being targeted. The hackers used XMRig to mine Monero with CPUs and lolMiner to mine Conflux with GPUs, while also enrolling hosts in a Hysteria V2 proxy botnet. Censys has not disclosed victim losses or mining proceeds.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.