How My Kingdom For My Princess Actually Works (And Why You Probably Hit It By Accident)
I need to clear something up immediately because the naming is misleading. My Kingdom For My Princess is not a traditional game you download and install. It is a browser redirect that embeds a cryptominer script directly into the page. The "gameplay" you see is usually a Flash-era style kingdom-building interface that loads in the background while the real work happens in your CPU cycles. The average load time for the miner component is roughly 3 to 8 seconds depending on your connection, and once loaded it can consume between 40 and 80 percent of a typical desktop CPU without throttling. The project is a web-based cryptocurrency mining script that was widely distributed through ad networks around 2017 through 2020. The script typically used the CoinHive or similar XMR (Monero) mining algorithms wrapped inside HTML pages that pretended to be idle browser games. When users clicked through to these pages from compromised ad networks or redirect chains, the miner would begin silently hashing. The kingdom building interface was essentially visual fluff designed to keep the user engaged while the background tab continued mining operations. I ran into this directly in early 2018 when I was doing ad network security audits for a mid-tier affiliate site. One of our placements pulled in a creative that looked like a casual mobile game page. We noticed CPU spikes on test machines that had nothing to do with the game code itself. The mining script was injected via a second-order redirect that loaded a separate domain after the initial page render. I spent about three hours tracing the obfuscated JavaScript through multiple eval wrappers and base64-encoded strings before I identified the actual mining endpoint. The script rotated between at least four different mining pool addresses and changed its obfuscation key every 45 seconds, which made static analysis nearly impossible without dynamic execution.
The core mechanism is straightforward once you strip away the layers. The page loads a JavaScript file from a CDN-like domain. That file decodes a mining payload, connects to a Monero mining pool, and begins submitting shares. The kingdom visuals update based on mining progress in a pseudo-game loop, but the actual value being generated is hash power, not game progress. If you watch the network tab in your browser dev tools you will see repeated POST requests to pool endpoints at intervals of roughly 10 to 30 seconds.
How to Detect It Before It Mines on Your Machine
The most reliable detection method is monitoring browser CPU usage combined with network traffic analysis. Open Chrome DevTools or Firefox Developer Edition, go to the Network tab, and look for connections to known mining pool domains. Common patterns include connections to domains with subdomains like minero, coinhive-proxy, or stratum-style endpoints. The mining script typically communicates over WebSocket connections on port 443 or occasionally over standard HTTP on non-standard ports. You can also check the Process tab in Chrome DevTools. Each background tab with an active miner will show elevated CPU usage even when the tab is not in focus. I usually set a threshold of more than 15 percent CPU usage on an idle tab as a red flag. The kingdom game interface itself runs at very low graphical fidelity, so GPU usage should remain near zero. If you see high CPU with minimal GPU activity on a page that claims to be a casual browser game, that is a strong indicator of cryptomining activity. Another tell is the presence of obfuscated code. Mine the source of a page that looks suspicious and search for eval, atob, or String.fromCharCode sequences. The obfuscation layer in the My Kingdom For My Princess variant I analyzed had approximately twelve levels of nesting. Each level decoded a small segment of the payload. A quick grep for hex patterns like 0x4d4b464d which corresponds to the ASCII for MKFM (the internal variable prefix used in the script) can help identify the specific obfuscated variant.
Get the Full Details

Removal and Prevention Steps
If you find yourself dealing with an active instance on your system, start by blocking the domain at the hosts file level. On Windows that is located at C:\Windows\System32\drivers\etc\hosts and on macOS or Linux it is at /etc/hosts. Add a line mapping the domain to 127.0.0.1. This prevents the miner from connecting to the pool even if the script manages to execute. Clear your browser cache and cookies afterward because some variants store the decoded payload in localStorage to persist across sessions. I encountered one edge case that took me about forty-five minutes to resolve. A particularly stubborn variant of the script had installed a service worker that continued redirecting traffic even after I blocked the original domain. The service worker was registered under a different origin that I had not initially flagged. To find it I had to navigate to chrome://serviceworker-internals in Chrome and manually unregister any workers associated with suspicious origins. After clearing those, the redirects stopped completely. This is an important detail that most removal guides skip because the service worker persistence mechanism is not obvious to casual observers. For long-term prevention, use browser extensions like NoCoin or Block Miner which maintain blocklists of known mining script domains and patterns. These extensions check the domain and script behavior against a regularly updated database. I also recommend enabling Content Security Policy headers on any sites you publish or manage, as these can prevent unauthorized script execution. A well-configured CSP directive like script-src 'self' blocks inline scripts and unknown origins, which neutralizes most injection-based miner delivery methods.
Technical Limitations and Failure Modes
It is worth noting that cryptomining via browser tabs has significant efficiency problems compared to native applications. Browser-based miners are typically 30 to 50 percent less efficient than native XMRig builds due to JavaScript interpreter overhead and single-threaded execution constraints. Modern browsers also implement aggressive throttling for background tabs, which can reduce mining output by up to 90 percent after the tab loses focus. This means the actual profitability of these projects dropped considerably over time as browser vendors closed the loopholes. The economic viability collapsed around mid-2020 when Monero's difficulty adjustments made browser mining essentially unprofitable for all but the most dedicated operators with massive traffic volumes. Most of the My Kingdom For My Princess variants you encounter now are either dormant remnants, testing infrastructure, or redirect scams that no longer contain active mining payloads. If you are analyzing one today, there is a reasonable chance the script is already dead and the page is simply a shell designed to phish credentials or distribute further malware through social engineering. When I last audited a live instance in late 2021, the mining component had been replaced with a credential harvesting form that appeared after the user interacted with the kingdom interface for approximately two minutes. The original miner was still present in the source code but disconnected from any active pool. This kind of pivot from mining to phishing is a common lifecycle pattern for these types of projects and is something to watch for during analysis.
If You Want to Study It Further
For those interested in examining the source code for educational or defensive purposes, the Wayback Machine at archive.org holds several captured versions of the original pages. I have personally downloaded and analyzed three different variants from 2018 and 2019 snapshots. The obfuscation techniques evolved noticeably over that period, with early versions using simple base64 encoding and later versions employing custom run-length encoding with XOR key rotation. Studying these archives can give you a clear picture of how browser-based cryptomining techniques progressed and eventually faded as detection improved across the industry.
