• Home
  • Privacy Policy
  • Contact
EURO Finance Hub
  • Bitcoin
  • Cryptocurrency
  • Forex Broker
  • Forex Trading
  • Investing
  • Mica crypto
No Result
View All Result
EURO Finance Hub
No Result
View All Result
Home Bitcoin

Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug

August 20, 2022
in Bitcoin
Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug

General Bytes Bitcoin ATMs

Hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal cryptocurrency from customers.

When customers would deposit or purchase cryptocurrency via the ATM, the funds would instead be siphoned off by the hackers

General Bytes is the manufacturer of Bitcoin ATMs that, depending on the product, allow people to purchase or sell over 40 different cryptocurrencies.

The Bitcoin ATMs are controlled by a remote Crypto Application Server (CAS), which manages the ATM’s operation, what cryptocurrencies are supported, and executes the purchases and sales of cryptocurrency on exchanges.

Hackers exploit CAS zero-day

Yesterday, BleepingComputer was contacted by a General Bytes customer who told us that hackers were stealing bitcoin from their ATMs.

According to a General Bytes security advisory published on August 18th, the attacks were conducted using a zero-day vulnerability in the company’s Crypto Application Server (CAS).

“The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user,” reads the General Bytes advisory.

“This vulnerability has been present in CAS software since version 20201208.”

General Bytes believes that the threat actors scanned the internet for exposed servers running on TCP ports 7777 or 443, including servers hosted at Digital Ocean and General Bytes’ own cloud service.

The threat actors then exploited the bug to add a default admin user named ‘gb’ to the CAS and modified the ‘buy’ and ‘sell’ crypto settings and ‘invalid payment address’ to use a cryptocurrency wallet under the hacker’s control.

Once the threat actos modified these settings, any cryptocurrency received by CAS was forwarded to the hackers instead.

“Two-way ATMs started to forward coins to the attacker’s wallet when customers sent coins to ATM,” explains the security advisory.

General Bytes is warning customers not to operate their Bitcoin ATMs until they have applied two server patch releases, 20220531.38 and 20220725.22, on their servers.

They also provided a checklist of steps to perform on the devices before they are put back into service.

It is important to remember that the threat actors would not have been able to perform these attacks if the servers were firewalled only to allow connections from trusted IP addresses.

Therefore, it is vital to configure firewalls only to allow access to the Crypto Application Server from a trusted IP address, such as from the ATM’s location or the customer’s offices.

According to information provided by BinaryEdge, there are currently eighteen General Bytes Crypto Application Servers still exposed to the Internet, with the majority located in Canada.

It is unclear how many servers were breached using this vulnerability and how much cryptocurrency was stolen.

BleepingComputer contacted General Bytes yesterday with further questions about the attack but did not receive a response. 

Source link

ShareTweetPin
Previous Post

Broker’s fee hits nearly $20K for one-bedroom NYC apartment

Next Post

One Indicator Is Likely To Determine Whether Bitcoin Stays in a Bear Market, Says Crypto Analyst Benjamin Cowen

Next Post
One Indicator Is Likely To Determine Whether Bitcoin Stays in a Bear Market, Says Crypto Analyst Benjamin Cowen

One Indicator Is Likely To Determine Whether Bitcoin Stays in a Bear Market, Says Crypto Analyst Benjamin Cowen

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs

February 2, 2023
2 Beaten-Down Tech Stocks to Buy in 2023

3 Dividend Aristocrats to Buy Now

February 2, 2023
Financial Accounting Standards Board votes to release draft cryptocurrency in March

Financial Accounting Standards Board votes to release draft cryptocurrency in March

February 2, 2023
Ethereum Looks Better Than Bitcoin Here (ETH-USD)

Ethereum Looks Better Than Bitcoin Here (ETH-USD)

February 2, 2023

Random Updates

Marks Art Gallery

The next ‘Banksy’ on the Horizon Marks Art Kensington DWizz

by Miller
January 28, 2023
0

Marks Art Kensington - DWizz is an up-and-coming street artist whose real identity is yet to still remain anonymous. Unlike...

Crypto Reg Weekly: MiCA Hits Stablecoins

EU Crypto Regulation May Need Clarification

by Miller
March 8, 2022
0

The European Parliament’s Monetary Committee will soon vote on a directive, Markets in Crypto Assets (MiCA), that will regulate crypto...

Sections

  • Bitcoin
  • Cryptocurrency
  • Forex Broker
  • Forex Trading
  • Investing
  • Mica crypto

Follow Us

Recent News

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs

Bitcoin pro traders warm up the $24K level, suggesting that the current BTC rally has legs

February 2, 2023
2 Beaten-Down Tech Stocks to Buy in 2023

3 Dividend Aristocrats to Buy Now

February 2, 2023
Financial Accounting Standards Board votes to release draft cryptocurrency in March

Financial Accounting Standards Board votes to release draft cryptocurrency in March

February 2, 2023
  • Contact
  • Home
  • Privacy Policy

© 2022 Euro Finance Hub

No Result
View All Result
  • Bitcoin
  • Cryptocurrency
  • Forex Broker
  • Forex Trading
  • Investing
  • Mica crypto

© 2022 Euro Finance Hub