• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Hackers Target Bitcoin ATMs Through Zero Day Attacks

August 24, 2022
in Australian Crypto News
Reading Time: 3min read
0 0
A A
0
Hackers Target Bitcoin ATMs Through Zero Day Attacks
0
SHARES
3
VIEWS
ShareShareShareShareShare

Adding to recent consumer consternation caused by illiquid crypto exchanges and lenders, hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal funds from customers.

General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow users to purchase or sell more than 40 different cryptocurrencies. However, in recent incidents that have seriously compromised their security, when customers have deposited or purchased cryptocurrency using these ATMs, the funds were instead siphoned off by hackers.

Remote Servers to Blame

The Bitcoin ATMs are controlled by a remote Crypto Application Server (CAS) that manages the ATM’s operation, which cryptocurrencies are supported, and executes the purchases and sales of cryptos on exchanges.

According to General Bytes’ security advice, the attacks were conducted using a zero-day vulnerability in its CAS:

The attacker was able to create an admin user remotely via the CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user. This vulnerability has been present in CAS software since version 20201208.

General Bytes security advice

General Bytes believes the hackers scanned the internet for exposed servers running on TCP ports 7777 or 443, including servers hosted at Digital Ocean and General Bytes’ own cloud service.

The hackers then exploited the bug to add a default admin user named ‘gb’ to the CAS, and modified the ‘buy’ and ‘sell’ crypto settings and ‘invalid payment address’ to recognise a crypto wallet under the hackers’ control.

Funds Diverted to Hackers’ Wallet

Once they had modified these settings, any cryptocurrencies received by CAS were forwarded to the hackers instead. “Two-way ATMs started to forward coins to the attackers’ wallet when customers sent coins to the ATM,” according to the security advice.

General Bytes, one of the largest manufacturers of cryptocurrency ATMs with almost 9,000 machines installed all over the world, is warning customers not to operate Bitcoin ATMs until they have applied two server patch releases, 20220531.38 and 20220725.22, on their servers. It has also provided a checklist of steps to perform on the devices before they are put back into service.

Most Exposed Servers Are in Canada

While it remains unclear how many servers were breached using this vulnerability and how much cryptocurrency was stolen, according to information provided by security firm BinaryEdge there are currently 18 General Bytes Crypto Application Servers still exposed to the internet, with the majority located in Canada.

Last year, El Salvador led the adoption of bitcoin in Central and South America by launching 1,000 Bitcoin ATMs across the country for buying and selling BTC. However, less than three months later a bitcoin ATM was burned and defaced with anti-BTC messages as protesters demonstrated resistance towards El Salvador’s pro-crypto President Nayib Bukele.

Share this article

Join in the conversation on this article’s Twitter thread.

Disclaimer:
The content and views expressed in the articles are those of the original authors own and are not necessarily the views of Crypto News. We do actively check all our content for accuracy to help protect our readers. This article content and links to external third-parties is included for information and entertainment purposes. It is not financial advice. Please do your own research before participating.


Credit: Source link

ShareTweetSendPinShare
Previous Post

XRP Price Falls To $0.34, Will Bulls Defend Support Of $0.33?

Next Post

CryptoPunks Surges Amid $55 Million In Bored Ape NFTs At Risk Of Liquidation

Next Post
Sotheby’s To Auction 104 CryptoPunks For Estimated $20 $30 Million

CryptoPunks Surges Amid $55 Million In Bored Ape NFTs At Risk Of Liquidation

You might also like

Leading AI Claude Predicts the Price of XRP, Bitcoin and Ethereum by The End of 2026

Leading AI Claude Predicts the Price of XRP, Bitcoin and Ethereum by The End of 2026

March 16, 2026
BlackRock Signals Cautious Expansion of Crypto ETFs Despite New Staked Ether Fund

BlackRock Signals Cautious Expansion of Crypto ETFs Despite New Staked Ether Fund

March 16, 2026
Bitcoin Foundation For A Mid-Term Breakout Remains Thin, Cost Basis Data Shows

Bitcoin Foundation For A Mid-Term Breakout Remains Thin, Cost Basis Data Shows

March 14, 2026
Bitcoin ETFs Draw Inflows as Gold Funds See Outflows Amid Iran War

Bitcoin ETFs Draw Inflows as Gold Funds See Outflows Amid Iran War

March 13, 2026
XRP Faces Systematic Rigging, Major Holder Says

XRP Faces Systematic Rigging, Major Holder Says

March 15, 2026
Bitcoin Probes $73,000 Liquidity Pocket: Is The Next Leg Toward $80,000 Loading?

Bitcoin Probes $73,000 Liquidity Pocket: Is The Next Leg Toward $80,000 Loading?

March 15, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Bitcoin Price Rally Roars On — $76K Level Falls to Bulls

Bitcoin Price Rally Roars On — $76K Level Falls to Bulls

March 17, 2026
Bitcoin Hits 40-Day High As US-Iran Tensions Trigger $113M In Short Liquidations

Bitcoin Hits 40-Day High As US-Iran Tensions Trigger $113M In Short Liquidations

March 17, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.