Data Breaches

Hackers steal more than $1.5M in crypto from General Bytes ATMs

0

Cryptocurrency ATM manufacturer General Bytes suffered a security breach in which threat actors stole $1.5M worth of cryptocurrency from hot wallets by exploiting a zero-day security flaw in its software.

General Bytes is the world’s largest Bitcoin, Blockchain, and Cryptocurrency ATM manufacturer. The company revealed that the threat actors exploited a zero-day vulnerability, tracked as BATM-4780.

The attacker identified a security vulnerability in the master service interface used by Bitcoin ATMs to upload videos to server.

The attacker scanned the Digital Ocean cloud hosting IP address space and identified running CAS services on ports 7741, including the General Bytes Cloud service and other GB ATM operators running their servers on Digital Ocean. Using this security vulnerability, attacker uploaded his own application directly to application server used by admin interface.

Once executing the uploaded script, the attackers gained access to the database and were able to read and decrypt API keys used to access funds in hot wallets and exchanges.

The attackers then send funds from hot wallets and download user names and password hashes. The hackers were also able to turn off the two-factor authentication (2FA).

The threat actors also managed to gain access to terminal event logs and scan for any instance where customers scanned private key at the ATM.

The company provided information on how to secure GB ATM servers (CAS) and recommends all its customers to implement the recommended measures.

The company urges customers to keep their crypto application servers (CASs) behind a firewall and a VPN, it’s also recommending to rotate all users’ passwords and API keys to exchanges and hot wallets.

The CAS security fix is provided in two server patch releases, 20221118.48 and 20230120.44.

The notice provides a list of crypto addresses used in the attack along with three IP addresses used by attackers.

The analysis of the wallets included in the notice revealed that the attackers stole more than $1.5 million worth of Bitcoin (56 BTC) from roughly 15 operators. Attackers also stole funds in other cryptocurrencies.

The ATM hack is the second breach targeting General Bytes in less than a year, with another zero-day flaw in its ATM servers exploited to steal crypto from its customers in August 2022.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Ferrari discloses data breach after getting ransom demand

Previous article

Chinese hackers breach Middle East Telecom providers

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *