Bitcoin ATM manufacturer General Bytes had its servers compromised via a zero-day attack on Aug. 18, which enabled the hackers to make themselves the default admins and modify settings so that all funds would be transferred to their wallet address.
The amount of funds stolen and number of ATMs compromised has not been disclosed but the company has urgently advised ATM operators to update their software.
The hack was confirmed by General Bytes on Aug. 18, which owns and operates 8827 Bitcoin ATMs that are accessible in over 120 countries. The company is headquartered in Prague, Czech Republic, which is also where the ATMs are manufactured. ATM customers can buy or sell over 40 coins.
The vulnerability has been present since the hacker’s modifications updated the CAS software to version 20201208 on Aug. 18.
General Bytes has urged customers to refrain from using their General Bytes ATM servers until they update their server to patch release 20220725.22, and 20220531.38 for customers running on 20220531.
Customers have also been advised to modify their server firewall settings so that the CAS admin interface can only be accessed from authorized IP addresses, among other things.
Before reactivating the terminals, General Bytes also reminded customers to review their ‘SELL Crypto Setting’ to ensure that the hackers didn’t modify the settings such that any received funds would instead be transferred to them (and not the customers).
General Bytes stated that several security audits had been conducted since its inception in 2020, none of which identified this vulnerability.
How the attack happened
General Bytes’ security advisory team stated in the blog that the hackers conducted a zero-day vulnerability attack to gain access to the company’s Crypto Application Server (CAS) and extract the funds.
The CAS server manages the ATM’s entire operation, which includes the execution of buying and selling of crypto on exchanges and which coins are supported.
The company believes the hackers “scanned for exposed servers running on TCP ports 7777 or 443, including servers hosted on General Bytes’ own cloud service.”
From there, the hackers added themselves as a default admin on the CAS, named ‘gb’, and then proceeded to modify the ‘buy’ and ‘sell’ settings such that any crypto received by the Bitcoin ATM would instead be transferred to the hacker’s wallet address:
"The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user."
Hackers exploit zero day bug to steal from General Bytes Bitcoin ATMs
Cointelegraph发布于2022-08-22更新于2022-08-22
文章摘要
Bitcoin ATM manufacturer General Bytes had its servers compromised via a zero-day attack on Aug. 18.
热门币种推荐
你可能也喜欢
交易
现货
合约
热门文章
加密市场宏观研报:《GENIUS Act》法案取得重大进展,BTC突破历史新高,后市全新展望
2025年5月22日,比特币价格正式突破11万美元大关,创下历史新高。在政策面、宏观经济、资金面与投资者结构共同作用下,一场结构性牛市浪潮正在展开。而此轮上涨背后的核心驱动,是美国《GENIUS稳定币法案》的实质性进展以及多项利好的叠加。本文将从政策端突破、宏观环境转向、链上与ETF资金结构、交易行为演化,以及重点受益赛道五大维度,全面解析此轮BTC再创新高的深层逻辑,并前瞻下半年市场的潜在趋势。
1.7k人学过发布于 2025.05.22更新于 2025.05.22

Fractal Bitcoin:为比特币原链打开无限扩展的大门
Fractal Bitcoin 是一种基于比特币核心代码的扩容方案,通过递归方式实现无限层级的扩展。
9.3k人学过发布于 2025.06.30更新于 2025.06.30

成长学院:学习“ Fractal Bitcoin“ ,瓜分价值 5000 USDT代币奖励
为了让您了解Fractal Bitcoin是什么,成长学院推出多种学习赚币活动。
4.8k人学过发布于 2025.06.30更新于 2025.07.01

相关讨论





