CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

General Bytes Bitcoin ATMs compromised by threat actors

August 22, 2022
in Crypto News
Reading Time: 3 mins read
A A
0
Bold! New “shameless” crypto malware puzzles security experts
0
SHARES
5
VIEWS
ShareShareShareShareShare

Source: gualtiero boffi – shutterstock

  • Bitcoin ATM manufacturer General Bytes has asked all ATM operators to update their software after its server was compromised through a zero-day attack.
  • This attack comes almost a year after Kraken Security Labs disclosed the vulnerability of most Bitcoin ATMs as their default admin QR code has never been changed.

Bitcoin ATM manufacturer General Bytes has asked all ATM operators to update their software after its server was compromised through a zero-day attack. According to the company’s security advisory team, the threat actors hacked into its Crypto Application Server (CAS) and stole funds. 

The hackers scanned for exposed servers running on TCP ports 7777 or 443, including servers hosted on General Bytes’ cloud service.

It is important to note that the CAS controls its entire operation including the buying and selling of cryptos. After gaining control, the hackers modified the settings to add themselves as default administrators on the CAS, named gb. From there, the hackers compromised the buy and sell settings, to ensure that all assets sent to the ATMs are redirected to the wallet addresses controlled by them. They also reportedly made away with some funds.

The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user.

Regardless of the information given, the company has not disclosed the amount stolen and the ATMs affected. 

Kraken Security Labs pointed out vulnerabilities in General Bytes

It is important to note that General Bytes own and operate over 8827 Bitcoin ATMs across 120 countries. Customers can as well access over 40 crypto assets on its various ATMs. As part of its effort to mitigate the impact, the company has advised customers to not use its ATM servers till they are updated to “patch releases 20220725.22, and 20220531.38 for customers running on 20220531.”

Customers are also reminded to review their “Sell Crypto Settings” before reactivating the terminals. This is to cross-check whether hackers modified their settings to redirect all received funds into their wallet addresses. To ensure that the CAS admin interface is only accessed from authorized IP addresses, customers have also been asked to modify their server firewall settings. In response to criticisms that the company did not invest enough in security audits to prevent this attack, it has stated that several audits have been conducted since 2020. 

This attack comes almost a year after Kraken Security Labs disclosed the vulnerability of most Bitcoin ATMs as their default admin QR code has never been changed. In the report, the security firm observed that General Bytes’ BATMTwo ATM range had several hardware and software vulnerabilities. According to Kraken, it is easier for hackers to compromise any ATM if they get access to the administrative code. In response, General Bytes reportedly informed ATM operators of the vulnerabilities.

Kraken Security Labs reported the vulnerabilities to General Bytes on April 20, 2021, they released patches to their backend system (CAS) and alerted their customers, but full fixes for some of the issues may still require hardware revisions.


Credit: Source link

RELATED POSTS

European Authorities Bust $815M Crypto Fraud Ring, Arrest Nine Across Border

Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala

Polish PM Claims Russia Influence Blocked Crypto Bill

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

ETH Below $1,600, BTC Under $21,000 to Start the Week – Market Updates Bitcoin News

Next Post

Australia plans to implement token mapping amid intensified efforts to regulate crypto industry

Related Posts

62 People Arrested in Turkey, Allegedly Connected to the Thodex Exchange Heist
Crypto News

European Authorities Bust $815M Crypto Fraud Ring, Arrest Nine Across Border

December 8, 2025
Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala
Crypto News

Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala

December 8, 2025
Polish PM Claims Russia Influence Blocked Crypto Bill
Crypto News

Polish PM Claims Russia Influence Blocked Crypto Bill

December 8, 2025
Next Post
Australia plans to implement token mapping amid intensified efforts to regulate crypto industry

Australia plans to implement token mapping amid intensified efforts to regulate crypto industry

Cardano’s Charles Hoskinson Criticizes ConsenSys, Claims JPMorgan Has No Stakes In Cardano

Cardano Founder Criticizes Tornado Cash Sanctions

Recommended Stories

No Content Available

Popular Stories

  • BRICS Unites 40 Nations at Leaders’ Summit — Russia Pushes for Global Partnerships

    BRICS Unites 40 Nations at Leaders’ Summit — Russia Pushes for Global Partnerships

    0 shares
    Share 0 Tweet 0
  • ElevenLabs Enhances AI Audio Solutions with New Deployments

    0 shares
    Share 0 Tweet 0
  • Crypto Exchange Kraken Says Decentraland, The Sandbox and Metaverse Sector Far Outperforming Market Year-on-Year

    0 shares
    Share 0 Tweet 0
  • ATOM Hits 2-Month High, as XRP Extends Recent Gains – Market Updates Bitcoin News

    0 shares
    Share 0 Tweet 0
  • Paxful Co-Founder Pleads Guilty to AML Conspiracy — Faces up to 5 Years in US Prison

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • How crypto derivatives liquidation drove Bitcoin’s 2025 crash
  • Robinhood Charges Into Indonesia as Next Explosive Crypto Market
  • Exploring Chainlink’s Role Beyond Price Feeds in the Blockchain Ecosystem

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.