Security News > 2022 > August > Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug
Hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal cryptocurrency from customers.
General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow people to purchase or sell over 40 different cryptocurrencies.
The Bitcoin ATMs are controlled by a remote Crypto Application Server, which manages the ATM's operation, what cryptocurrencies are supported, and executes the purchases and sales of cryptocurrency on exchanges.
Yesterday, BleepingComputer was contacted by a General Bytes customer who told us that hackers were stealing bitcoin from their ATMs. According to a General Bytes security advisory published on August 18th, the attacks were conducted using a zero-day vulnerability in the company's Crypto Application Server.
Once the threat actos modified these settings, any cryptocurrency received by CAS was forwarded to the hackers instead. "Two-way ATMs started to forward coins to the attacker's wallet when customers sent coins to ATM," explains the security advisory.
General Bytes is warning customers not to operate their Bitcoin ATMs until they have applied two server patch releases, 20220531.
News URL
Related news
- Hackers target critical zero-day vulnerability in PTZ cameras (source)
- North Korean hackers employ new tactics to compromise crypto-related businesses (source)
- North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS (source)
- North Korean hackers use new macOS malware against crypto firms (source)
- Bitfinex Hacker Sentenced to 5 Years, Guilty of Laundering $10.5 Billion in Bitcoin (source)
- Bitfinex hacker gets 5 years in prison for 120,000 bitcoin heist (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
- RomCom hackers chained Firefox and Windows zero-days to deliver backdoor (source)
- Firefox and Windows zero-days exploited by Russian RomCom hackers (source)
- Radiant links $50 million crypto heist to North Korean hackers (source)