Why antivirus flags miners, and what to do
The honest reason mining software triggers antivirus warnings, how to exclude a miner you chose to run, and how to stay safe doing it.
The honest reason
Antivirus products flag miners as "PUA" (potentially unwanted application) or even as malware, and the reason is honest: criminals really do hide miners in cracked software to mine on victims' machines. The scanner cannot tell whether YOU chose to run the miner or a trojan planted it, so it flags the category. A flagged miner is not proof the file is malicious; it is proof the file mines.
Download only from the source
The protection you actually need is provenance: download miners only from the developer's official releases page, never from a forum re-upload, a YouTube link or a "fixed" build. Check the release's checksum where the developer publishes one. A miner from anywhere else can genuinely carry exactly the payload the antivirus warns about.
Excluding the miner properly
Add an exclusion for the miner's own folder (not a whole drive) in your antivirus settings, ideally before the first unzip so the scanner does not quarantine files out of the archive. On Windows Defender that is Virus and threat protection, Manage settings, Exclusions. Re-download the miner after setting the exclusion if files were already removed.
Stay honest with yourself
An exclusion is a hole in your shield: keep only the miners you use, in one dedicated folder, and never exclude download folders or the whole system. If a machine you did NOT set up is mining, that is not a false positive; investigate it as the infection it probably is.