Security News > 2022 > August > Hackers Stole Crypto from Bitcoin ATMs by Exploiting Zero-Day Vulnerability
Bitcoin ATM manufacturer General Bytes confirmed that it was a victim of a cyberattack that exploited a previously unknown flaw in its software to plunder cryptocurrency from its users.
"This vulnerability has been present in CAS software since version 2020-12-08.".
CAS is short for Crypto Application Server, a self-hosted product from General Bytes that enables companies to manage Bitcoin ATM machines from a central location via a web browser on a desktop or a mobile device.
The zero-day flaw, which concerned a bug in the CAS admin interface, has been mitigated in two server patch releases, 20220531.
General Bytes said the unnamed threat actor identified running CAS services on ports 7777 or 443 by scanning the DigitalOcean cloud hosting IP address space, followed by abusing the flaw to add a new default admin user named "Gb" to the CAS. "The attacker modified the crypto settings of two-way machines with his wallet settings and the 'invalid payment address' setting," it said.
"Two-way ATMs started to forward coins to the attacker's wallet when customers sent coins to [the] ATM.".
News URL
https://thehackernews.com/2022/08/hackers-stole-crypto-from-bitcoin-atms.html
Related news
- North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin (source)
- Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners (source)
- Radiant links $50 million crypto heist to North Korean hackers (source)
- U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls (source)
- Bitcoin ATM firm Byte Federal hacked via GitLab flaw, 58K users exposed (source)
- Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools (source)
- North Korean hackers stole $1.3 billion worth of crypto this year (source)
- FBI links North Korean hackers to $308 million crypto heist (source)
- Brazilian Hacker Charged for Extorting $3.2M in Bitcoin After Breaching 300,000 Accounts (source)
- Zero-Day Vulnerability in Ivanti VPN (source)