• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Hackers Target Bitcoin ATMs Through Zero Day Attacks

August 24, 2022
in Australian Crypto News
Reading Time: 3min read
0 0
A A
0
Hackers Target Bitcoin ATMs Through Zero Day Attacks
0
SHARES
4
VIEWS
ShareShareShareShareShare

Adding to recent consumer consternation caused by illiquid crypto exchanges and lenders, hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal funds from customers.

General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow users to purchase or sell more than 40 different cryptocurrencies. However, in recent incidents that have seriously compromised their security, when customers have deposited or purchased cryptocurrency using these ATMs, the funds were instead siphoned off by hackers.

Remote Servers to Blame

The Bitcoin ATMs are controlled by a remote Crypto Application Server (CAS) that manages the ATM’s operation, which cryptocurrencies are supported, and executes the purchases and sales of cryptos on exchanges.

According to General Bytes’ security advice, the attacks were conducted using a zero-day vulnerability in its CAS:

The attacker was able to create an admin user remotely via the CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user. This vulnerability has been present in CAS software since version 20201208.

General Bytes security advice

General Bytes believes the hackers scanned the internet for exposed servers running on TCP ports 7777 or 443, including servers hosted at Digital Ocean and General Bytes’ own cloud service.

The hackers then exploited the bug to add a default admin user named ‘gb’ to the CAS, and modified the ‘buy’ and ‘sell’ crypto settings and ‘invalid payment address’ to recognise a crypto wallet under the hackers’ control.

Funds Diverted to Hackers’ Wallet

Once they had modified these settings, any cryptocurrencies received by CAS were forwarded to the hackers instead. “Two-way ATMs started to forward coins to the attackers’ wallet when customers sent coins to the ATM,” according to the security advice.

General Bytes, one of the largest manufacturers of cryptocurrency ATMs with almost 9,000 machines installed all over the world, is warning customers not to operate Bitcoin ATMs until they have applied two server patch releases, 20220531.38 and 20220725.22, on their servers. It has also provided a checklist of steps to perform on the devices before they are put back into service.

Most Exposed Servers Are in Canada

While it remains unclear how many servers were breached using this vulnerability and how much cryptocurrency was stolen, according to information provided by security firm BinaryEdge there are currently 18 General Bytes Crypto Application Servers still exposed to the internet, with the majority located in Canada.

Last year, El Salvador led the adoption of bitcoin in Central and South America by launching 1,000 Bitcoin ATMs across the country for buying and selling BTC. However, less than three months later a bitcoin ATM was burned and defaced with anti-BTC messages as protesters demonstrated resistance towards El Salvador’s pro-crypto President Nayib Bukele.

Share this article

Join in the conversation on this article’s Twitter thread.

Disclaimer:
The content and views expressed in the articles are those of the original authors own and are not necessarily the views of Crypto News. We do actively check all our content for accuracy to help protect our readers. This article content and links to external third-parties is included for information and entertainment purposes. It is not financial advice. Please do your own research before participating.


Credit: Source link

ShareTweetSendPinShare
Previous Post

XRP Price Falls To $0.34, Will Bulls Defend Support Of $0.33?

Next Post

CryptoPunks Surges Amid $55 Million In Bored Ape NFTs At Risk Of Liquidation

Next Post
Sotheby’s To Auction 104 CryptoPunks For Estimated $20 $30 Million

CryptoPunks Surges Amid $55 Million In Bored Ape NFTs At Risk Of Liquidation

You might also like

AAVE Price Prediction: Testing $240 Breakout with $280 Medium-Term Target Despite Bearish Momentum

AAVE Breakdown Targets $85 Support Before Dead Cat Bounce to $110

April 23, 2026
Bitcoin Price Wave Down To $40K Shows When Bottom Will Begin

Bitcoin Price Wave Down To $40K Shows When Bottom Will Begin

April 26, 2026
Soldier Charged After Betting on Secret Maduro Arrest Using Classified Intel

Soldier Charged After Betting on Secret Maduro Arrest Using Classified Intel

April 24, 2026
XRP Price Prediction: Ripple Conspiracy Theories and Broken NDAs

XRP Price Prediction: Ripple Conspiracy Theories and Broken NDAs

April 26, 2026
TezDev 2024 to Kick Off Next Week in Brussels

Tezos X Brings EVM Compatibility, Testnet Launches May 2026

April 27, 2026
Bitcoin Price Prediction: Florida’s Crypto Bill and $198B U.S. Surplus Boost Market Outlook

Bitcoin Price Prediction: Jack Dorsey Holds $2.2B as Strategy Ramps Up Buying

April 28, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Crypto.com Wants a National Trust Bank License – What Would a Federal License Really Change?

Kaspa Crypto Is 95% Mined With Supply Running Out by Late 2026: Is a Scarcity Rally Coming Before It’s Too Late?

April 29, 2026
$250K Bitcoin In 2026? Analyst Warns Bulls To ‘Stop With The Mushrooms’

$250K Bitcoin In 2026? Analyst Warns Bulls To ‘Stop With The Mushrooms’

April 29, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.