• Home
  • Bitcoin
  • Crypto
  • Altcoins
  • NFT
  • Defi
  • Ripple
  • Ethereum
What's Hot

Solana’s staking metric has some good news for SOL holders

October 8, 2022

Binance Coin: How BNB buyers can capitalize on this breakout rally

October 8, 2022

Crypto Analyst Issues Warning to Traders on Binance Coin (BNB), Predicts Timeline for Ethereum’s Next Big Move

October 7, 2022
Facebook Twitter Instagram
  • Home
  • Bitcoin

    Bitcoin price has hit bottom; coldest days of Crypto Winter are over – Ran Neuner and Steven Sidley

    August 21, 2022

    Uniswap Blocked 253 Crypto Addresses, Here’s Why

    August 21, 2022

    Runfy and Decentraland – Crypto Projects That Deliver Unique Blockchain-Based Services To Their Users

    August 20, 2022

    Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug

    August 20, 2022

    Why Bitcoin traders holding long positions may expect BTC’s downfall to be short-lived

    August 20, 2022
  • Crypto

    Why Bitcoin Is Digital Real Estate – Bitcoin Magazine

    August 21, 2022

    Bitcoin [BTC] traders must sit tight without expecting short-term gains because…

    August 21, 2022

    FDIC Issues Crypto-Related Cease and Desist Orders to 5 Companies Including FTX US Exchange – Regulation Bitcoin News

    August 21, 2022

    The Most Profitable Buy Signal In Bitcoin Just Triggered

    August 20, 2022

    3 reasons why the Bitcoin price bottom is not in

    August 20, 2022
  • Altcoins

    Solana’s staking metric has some good news for SOL holders

    October 8, 2022

    Binance Coin: How BNB buyers can capitalize on this breakout rally

    October 8, 2022

    Crypto Analyst Issues Warning to Traders on Binance Coin (BNB), Predicts Timeline for Ethereum’s Next Big Move

    October 7, 2022

    Crypto Price Today: Bitcoin barely holds $20,000 mark; altcoins trade lower

    October 7, 2022

    3 Altcoins that could be profitable: Cardano, Avalanche & Big Eyes Coin

    October 7, 2022
  • NFT

    Liquidation Fears Mount as BAYC NFTs Floor Price Drops

    August 21, 2022

    Service by NFTs, Disclosure Orders Against Crypto Exchanges, and Potential Constructive Trustee Liability

    August 21, 2022

    What are They and Why are They So Popular?

    August 21, 2022

    How NFTs are giving everyone the chance to be an art collector

    August 21, 2022

    VeeFriends Drop Surprise NFTs: Iconics With Gilang Bogy

    August 21, 2022
  • Defi

    Top Three DeFi Cryptocurrency To Buy Now – Solana, Uniswap, and HachiFi

    August 22, 2022

    Meet the Sleuthing Firm Helping DeFi Projects Stay Compliant With Tornado Cash Sanctions

    August 21, 2022

    KyberSwap Integrating Chainlink Price Feeds for DAO and DeFi

    August 21, 2022

    Africa fintech and crypto leaders to connect in Ghana-1

    August 21, 2022

    Stellar-Based DeFi Lumenswap (LSP) Activates Smart Order Routing System. Why Is This Important?

    August 21, 2022
  • Ripple

    Ukraine: Six months in, IFRC warns of ripple effects and mounting humanitarian needs

    August 23, 2022

    Ripple to Pakistani Rupee on August 23, 2022

    August 23, 2022

    Crikey’s Lachlan Murdoch move ripples around the world

    August 23, 2022

    Beware the ripple effects from Europe’s new energy crisis and China’s economic slowdown

    August 23, 2022

    Top 3 Price Prediction Bitcoin, Ethereum, Ripple: Knife Catching 102

    August 22, 2022
  • Ethereum

    SWIFT considered ‘neutral’ on sanctions; debate sparked on whether Ethereum is the same

    August 22, 2022

    Ronin Hackers Move The Stolen Ethereum And Bitcoin Using Mixers

    August 22, 2022

    Ethereum Classic’s hashrate reached an all-time high, should you buy ETC?

    August 22, 2022

    Crypto markets scramble for recovery before the next crash

    August 22, 2022

    Ethereum Killers Avalanche, BNB Set to Soar More Than 112%, Could Proprivex Follow Suit?

    August 22, 2022
Facebook Twitter Instagram
Crypto Investment Watch
  • Home
  • Bitcoin

    Bitcoin price has hit bottom; coldest days of Crypto Winter are over – Ran Neuner and Steven Sidley

    August 21, 2022

    Uniswap Blocked 253 Crypto Addresses, Here’s Why

    August 21, 2022

    Runfy and Decentraland – Crypto Projects That Deliver Unique Blockchain-Based Services To Their Users

    August 20, 2022

    Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug

    August 20, 2022

    Why Bitcoin traders holding long positions may expect BTC’s downfall to be short-lived

    August 20, 2022
  • Crypto

    Why Bitcoin Is Digital Real Estate – Bitcoin Magazine

    August 21, 2022

    Bitcoin [BTC] traders must sit tight without expecting short-term gains because…

    August 21, 2022

    FDIC Issues Crypto-Related Cease and Desist Orders to 5 Companies Including FTX US Exchange – Regulation Bitcoin News

    August 21, 2022

    The Most Profitable Buy Signal In Bitcoin Just Triggered

    August 20, 2022

    3 reasons why the Bitcoin price bottom is not in

    August 20, 2022
  • Altcoins

    Solana’s staking metric has some good news for SOL holders

    October 8, 2022

    Binance Coin: How BNB buyers can capitalize on this breakout rally

    October 8, 2022

    Crypto Analyst Issues Warning to Traders on Binance Coin (BNB), Predicts Timeline for Ethereum’s Next Big Move

    October 7, 2022

    Crypto Price Today: Bitcoin barely holds $20,000 mark; altcoins trade lower

    October 7, 2022

    3 Altcoins that could be profitable: Cardano, Avalanche & Big Eyes Coin

    October 7, 2022
  • NFT

    Liquidation Fears Mount as BAYC NFTs Floor Price Drops

    August 21, 2022

    Service by NFTs, Disclosure Orders Against Crypto Exchanges, and Potential Constructive Trustee Liability

    August 21, 2022

    What are They and Why are They So Popular?

    August 21, 2022

    How NFTs are giving everyone the chance to be an art collector

    August 21, 2022

    VeeFriends Drop Surprise NFTs: Iconics With Gilang Bogy

    August 21, 2022
  • Defi

    Top Three DeFi Cryptocurrency To Buy Now – Solana, Uniswap, and HachiFi

    August 22, 2022

    Meet the Sleuthing Firm Helping DeFi Projects Stay Compliant With Tornado Cash Sanctions

    August 21, 2022

    KyberSwap Integrating Chainlink Price Feeds for DAO and DeFi

    August 21, 2022

    Africa fintech and crypto leaders to connect in Ghana-1

    August 21, 2022

    Stellar-Based DeFi Lumenswap (LSP) Activates Smart Order Routing System. Why Is This Important?

    August 21, 2022
  • Ripple

    Ukraine: Six months in, IFRC warns of ripple effects and mounting humanitarian needs

    August 23, 2022

    Ripple to Pakistani Rupee on August 23, 2022

    August 23, 2022

    Crikey’s Lachlan Murdoch move ripples around the world

    August 23, 2022

    Beware the ripple effects from Europe’s new energy crisis and China’s economic slowdown

    August 23, 2022

    Top 3 Price Prediction Bitcoin, Ethereum, Ripple: Knife Catching 102

    August 22, 2022
  • Ethereum

    SWIFT considered ‘neutral’ on sanctions; debate sparked on whether Ethereum is the same

    August 22, 2022

    Ronin Hackers Move The Stolen Ethereum And Bitcoin Using Mixers

    August 22, 2022

    Ethereum Classic’s hashrate reached an all-time high, should you buy ETC?

    August 22, 2022

    Crypto markets scramble for recovery before the next crash

    August 22, 2022

    Ethereum Killers Avalanche, BNB Set to Soar More Than 112%, Could Proprivex Follow Suit?

    August 22, 2022
Crypto Investment Watch
Home»Bitcoin»Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug
general-bytes-bitcoin-atm.jpg
Bitcoin

Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug

adminBy adminAugust 20, 2022No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal cryptocurrency from customers.

When customers would deposit or purchase cryptocurrency via the ATM, the funds would instead be siphoned off by the hackers

General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow people to purchase or sell over 40 different cryptocurrencies.

The Bitcoin ATMs are controlled by a remote Crypto Application Server (CAS), which manages the ATM’s operation, what cryptocurrencies are supported, and executes the purchases and sales of cryptocurrency on exchanges.

Hackers exploit CAS zero-day

Yesterday, BleepingComputer was contacted by a General Bytes customer who told us that hackers were stealing bitcoin from their ATMs.

According to a General Bytes security advisory published on August 18th, the attacks were conducted using a zero-day vulnerability in the company’s Crypto Application Server (CAS).

“The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user,” reads the General Bytes advisory.

“This vulnerability has been present in CAS software since version 20201208.”

General Bytes believes that the threat actors scanned the internet for exposed servers running on TCP ports 7777 or 443, including servers hosted at Digital Ocean and General Bytes’ own cloud service.

The threat actors then exploited the bug to add a default admin user named ‘gb’ to the CAS and modified the ‘buy’ and ‘sell’ crypto settings and ‘invalid payment address’ to use a cryptocurrency wallet under the hacker’s control.

Once the threat acts modified these settings, any cryptocurrency received by CAS was forwarded to the hackers instead.

“Two-way ATMs started to forward coins to the attacker’s wallet when customers sent coins to ATM,” explains the security advisory.

General Bytes is warning customers not to operate their Bitcoin ATMs until they have applied two server patch releases, 20220531.38 and 20220725.22, on their servers.

They also provided a checklist of steps to perform on the devices before they are put back into service.

It is important to remember that the threat actors would not have been able to perform these attacks if the servers were firewalled only to allow connections from trusted IP addresses.

Therefore, it is vital to configure firewalls only to allow access to the Crypto Application Server from a trusted IP address, such as from the ATM’s location or the customer’s offices.

According to information provided by Binary Edgethere are currently eighteen General Bytes Crypto Application Servers still exposed to the Internet, with the majority located in Canada.

It is unclear how many servers were breached using this vulnerability and how much cryptocurrency was stolen.

BleepingComputer contacted General Bytes yesterday with further questions about the attack but did not receive a response.

ATMs Bitcoin bug crypto exploiting hackers Steal zeroday
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Crypto Analyst Issues Warning to Traders on Binance Coin (BNB), Predicts Timeline for Ethereum’s Next Big Move

October 7, 2022

Crypto Price Today: Bitcoin barely holds $20,000 mark; altcoins trade lower

October 7, 2022

3 Altcoins that could be profitable: Cardano, Avalanche & Big Eyes Coin

October 7, 2022

Tracking the crypto asset market

October 7, 2022
Add A Comment

Leave A Reply Cancel Reply

Top Posts

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Advertisement
Demo

Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

We're social. Connect with us:

Facebook Twitter Instagram Pinterest YouTube
Top Insights

Solana’s staking metric has some good news for SOL holders

October 8, 2022

Binance Coin: How BNB buyers can capitalize on this breakout rally

October 8, 2022

Crypto Analyst Issues Warning to Traders on Binance Coin (BNB), Predicts Timeline for Ethereum’s Next Big Move

October 7, 2022
Get Informed

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook Twitter Instagram Pinterest
© 2023 Crypto Investment Watch.

Type above and press Enter to search. Press Esc to cancel.