Bitcoin ATM maker shuts cloud service after user hot wallets compromised

Share This Post

Bitcoin ATM manufacturer General Bytes said a hacker was able to install and run a Java application in its terminals that could access user information and send funds from hot wallets.

Bitcoin ATM manufacturer General Bytes has shuttered its cloud services after discovering a “security vulnerability” that allowed an attacker to access users’ hot wallets and gain sensitive information, such as passwords and private keys.

The company is a Bitcoin (BTC) ATM manufacturer based in Prague, and according to its website, has sold over 15,000 ATMs to over 149 countries all over the world.

In a March 18 patch release bulletin, the ATM manufacturer issued a warning explaining that a hacker has been able to remotely upload and run a Java application via the master service interface into its terminals aimed at stealing user information and sending funds from hot wallets.

General Byes founder Karel Kyovsky in the bulletin explained this allowed the hacker to achieve the following:

  • “Ability to access the database.
  • Ability to read and decrypt API keys used to access funds in hot wallets and exchanges.
  • Send funds from hot wallets.
  • Download user names, their password hashes and turn off 2FA.
  • Ability to access terminal event logs and scan for any instance where customers scanned private key at the ATM. Older versions of ATM software were logging this information.”

The notice reveals that both General Bytes’ cloud service was breached as well as other operators’ standalone severs. 

“We’ve concluded multiple security audits since 2021, and none of them identified this vulnerability,” Kyovsky said.

Hot wallets compromised

Though the company noted that the hacker was able to “Send funds from hot wallets,” it did not disclose how much was stolen as a result of the breach.

However, General Bytes released the details of 41 wallet addresses that were used in the attack. On-chain data shows multiple transactions into one of the wallets, resulting in a total balance of 56 BTC, worth over $1.54 million at current prices.

General Bytes released the details of 41 wallet addresses used in the attack. Source: General Bytes

Another wallet shows multiple Ether (ETH) transactions, with the total received amounting to 21.82 ETH, worth roughly $36,000 at current prices.

Cointelegraph reached out to General Bytes for confirmation but did not receive a reply before publication.

Related: Bitcoin ATM decline: Over 400 machines went off the grid in under 60 days

The company has urgently advised BTC ATM operators to install their own standalone server and released two patches for their Crypto Application Server (CAS), which manages the ATM’s operation.

General Bytes is a Bitcoin ATM manufacturer based in Prague that has sold over 15,000 ATMs worldwide. Source: General Bytes

“Please keep your CAS behind a firewall and VPN. Terminals should also connect to CAS via VPN,” Kyovsky wrote.

“Additionally consider all your user’s passwords, and API keys to exchanges and hot wallets to be compromised. Please invalidate them and generate new keys & password.”

General Bytes previously had its servers compromised via a zero-day attack in September last year that enabled hackers to make themselves the default administrators and modify settings so that all funds would be transferred.

Read Entire Article
spot_img

Related Posts

Toncoin Tsunami: $1 Billion Whale Activity Shakes Up Price – What’s Next?

Despite a recent surge in activity from large investors, often referred to as “whales,” the price of Toncoin (TON) appears headed for choppier waters This comes as analysts raise concerns

Despite FTX’s Collapse, FTT’s $535M Market Cap Highlights Crypto Absurdity

Ten days ago, the FTX estate overseeing the bankrupt company’s proceedings informed customers they would receive more than 100% repayment Following this announcement, the exchange token FTT

Tether CEO Hints at Development of Global P2P Financial Markets Terminal

Tether CEO Paolo Ardoino stated that the stablecoin company might put “significant resources” into developing a global peer-to-peer (P2P) financial markets terminal Ardoino explained that

Yuval Harari Criticizes Bitcoin, Naira Becomes World’s Worst-Performing Currency, and More — Week in Review

Historian Yuval Noah Harari criticized bitcoin, calling it a “currency of distrust” The Nigerian naira has become the world’s worst-performing currency after erasing its early April

Western Banks Face Major Asset Seizure in Russia Amid Gazprom Subsidiary Dispute

In a significant move against western banks, a St Petersburg court has seized over $763 million of assets from Unicredit, Deutsche Bank, and Commerzbank, following a dispute with a subsidiary of

Fantom Price Continues To Shine – What’s Behind The Latest 15% Surge?

Fantom price has been such a joy to watch for investors in recent days, as a much-needed breath of fresh air continues to spread throughout the crypto market Bitcoin and other large-cap assets seem
- Advertisement -spot_img