Bitcoin ATM bug let thieves siphon off crypto withdrawals

Bitcoin mining
(Image credit: Pixabay)

A security vulnerability in a series of bitcoin ATM machines allowed cybercriminals to steal valuable tokens from users, it has been revealed.

In an announcement, General Bytes, the maker of the ATMs in question, said that unknown threat actors discovered a zero-day vulnerability in the devices and used it to siphon cryptocurrencies from user accounts.

As the company explained, these ATMs are controlled by a remote Crypto Application Server (CAS), and whoever was behind the theft found a hole in the CAS. 

"The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user," General Bytes said. "This vulnerability has been present in CAS software since version 20201208."

Diverting the coins

After that, whenever someone tried to deposit or withdraw cryptocurrency using the ATM, the funds would simply be diverted to a wallet belonging to the hackers.

"Two-way ATMs started to forward coins to the attacker's wallet when customers sent coins to ATM," the company further explained.

The company was tipped off by a user whose funds had been stolen. It is unclear how many people were affected by the flaw, or how much in cryptocurrencies the thieves managed to steal. 

Since then, though, a patch has been released. The company has updated the CAS to versions 20220531.38 and 20220725.22 and urged ATM service providers to pull the devices out until they apply the patch. Most of the unpatched devices, roughly two dozen of them, are located in Canada, it was said.

Furthermore, as BleepingComputer reported, the attack would not have been possible in the first place, had the servers been firewalled to only allow trusted IP addresses to establish a connection.

Via BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
North Korean flag with a hooded hacker
FBI says North Korean Lazarus hackers were behind $1.5 billion Bybit crypto hack
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand