Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug (2024)

Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug (1)

Hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal cryptocurrency from customers.

When customers would deposit or purchase cryptocurrency via the ATM, the funds would instead be siphoned off by the hackers

General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow people to purchase or sell over 40 different cryptocurrencies.

The Bitcoin ATMs are controlled by a remoteCrypto Application Server(CAS), which manages the ATM's operation, what cryptocurrencies are supported, and executes the purchases and sales of cryptocurrency on exchanges.

Hackers exploit CAS zero-day

Yesterday, BleepingComputer was contacted by a General Bytes customer who told us that hackers were stealing bitcoin from their ATMs.

According to a General Bytes security advisory published on August 18th, the attacks were conducted using a zero-day vulnerability in the company's Crypto Application Server (CAS).

"The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user," reads the General Bytes advisory.

"This vulnerability has been present in CAS software since version 20201208."

General Bytes believes that the threat actors scanned the internet for exposed servers running on TCP ports 7777 or 443, including servers hosted at Digital Ocean and General Bytes' own cloud service.

The threat actors then exploited the bug to add a default admin user named 'gb' to the CAS and modified the 'buy' and 'sell' crypto settings and'invalid payment address'to use a cryptocurrency walletunder the hacker's control.

Once the threat actos modified these settings, any cryptocurrency received by CAS was forwarded to the hackers instead.

"Two-way ATMs started to forward coins to the attacker's wallet when customers sent coins to ATM," explains the security advisory.

General Bytes is warning customers not to operate their Bitcoin ATMs until they have applied two server patch releases, 20220531.38 and 20220725.22, on their servers.

They also provided achecklist of stepsto perform on the devices before they are put back into service.

It is important to remember that the threat actors would not have been able to perform these attacks if the servers were firewalled only to allow connections from trusted IP addresses.

Therefore, it is vital toconfigure firewallsonly to allow access to the Crypto Application Server from a trusted IP address, such as from the ATM's location or the customer's offices.

According to information provided byBinaryEdge, there are currently eighteen General Bytes Crypto Application Servers still exposed to the Internet, with the majority located in Canada.

It is unclear how many servers were breached using this vulnerability and how much cryptocurrency was stolen.

BleepingComputer contacted General Bytes yesterday with further questions about the attack but did not receive a response.

Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug (2024)
Top Articles
Understanding Masternodes — Dash latest documentation
Five Reasons a Home Might Be Rejected for an FHA Mortgage
Scheelzien, volwassenen - Alrijne Ziekenhuis
Kreme Delite Menu
Uihc Family Medicine
Chelsea player who left on a free is now worth more than Palmer & Caicedo
San Diego Terminal 2 Parking Promo Code
Nc Maxpreps
Tyrunt
Tiraj Bòlèt Florida Soir
Aita Autism
Find The Eagle Hunter High To The East
Myql Loan Login
zopiclon | Apotheek.nl
Nba Rotogrinders Starting Lineups
How Much Are Tb Tests At Cvs
Bitlife Tyrone's
Morristown Daily Record Obituary
Https Paperlesspay Talx Com Boydgaming
Red Cedar Farms Goldendoodle
Best Boston Pizza Places
Netwerk van %naam%, analyse van %nb_relaties% relaties
15 Primewire Alternatives for Viewing Free Streams (2024)
Hesburgh Library Catalog
Booknet.com Contract Marriage 2
Soul Eater Resonance Wavelength Tier List
Great ATV Riding Tips for Beginners
What Sells at Flea Markets: 20 Profitable Items
Rgb Bird Flop
Jail Roster Independence Ks
Myaci Benefits Albertsons
Little Einsteins Transcript
Ucm Black Board
Swgoh Boba Fett Counter
Beaver Saddle Ark
Exploring TrippleThePotatoes: A Popular Game - Unblocked Hub
Moxfield Deck Builder
Ticketmaster Lion King Chicago
D-Day: Learn about the D-Day Invasion
Invalleerkracht [Gratis] voorbeelden van sollicitatiebrieven & expert tips
2700 Yen To Usd
Gravel Racing
Weather In Allentown-Bethlehem-Easton Metropolitan Area 10 Days
Luciane Buchanan Bio, Wiki, Age, Husband, Net Worth, Actress
Dickdrainersx Jessica Marie
This Doctor Was Vilified After Contracting Ebola. Now He Sees History Repeating Itself With Coronavirus
View From My Seat Madison Square Garden
Overstock Comenity Login
Ocean County Mugshots
Latest Posts
Article information

Author: Carlyn Walter

Last Updated:

Views: 5950

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.