BTC $68279.0927
ETH $3629.5433
BNB $418.8260
SOL $133.0943
XRP $0.6497
stETH $3620.7348
ADA $0.7707
DOGE $0.1827
AVAX $43.0376
DOT $9.8988
wstETH $4204.4051
TRX $0.1402
LINK $20.4333
WETH $3627.8562
MATIC $1.1461
WBTC $68015.7231
UNI $12.3628
BCH $469.5171
LTC $88.8112
IMX $3.1360
ICP $13.3800
CAKE $3.3523
ETC $35.9657
FIL $10.0244
LEO $4.8744
ATOM $12.4782
TON $2.7811
HBAR $0.1174
RNDR $7.3750
KAS $0.1614
INJ $40.6866
DAI $0.9990
OKB $56.8390
VET $0.0495
PEPE $0.0000
XLM $0.1458
FDUSD $0.9965
STX $3.0333
XMR $148.4317
WEMIX $2.7041
LDO $3.2821
NEAR $4.3354
GRT $0.3080
ARB $1.9787
THETA $2.3471
APEX $2.6824
BSV $115.5449
BTC $68279.0927
ETH $3629.5433
BNB $418.8260
SOL $133.0943
XRP $0.6497
stETH $3620.7348
ADA $0.7707
DOGE $0.1827
AVAX $43.0376
DOT $9.8988
wstETH $4204.4051
TRX $0.1402
LINK $20.4333
WETH $3627.8562
MATIC $1.1461
WBTC $68015.7231
UNI $12.3628
BCH $469.5171
LTC $88.8112
IMX $3.1360
ICP $13.3800
CAKE $3.3523
ETC $35.9657
FIL $10.0244
LEO $4.8744
ATOM $12.4782
TON $2.7811
HBAR $0.1174
RNDR $7.3750
KAS $0.1614
INJ $40.6866
DAI $0.9990
OKB $56.8390
VET $0.0495
PEPE $0.0000
XLM $0.1458
FDUSD $0.9965
STX $3.0333
XMR $148.4317
WEMIX $2.7041
LDO $3.2821
NEAR $4.3354
GRT $0.3080
ARB $1.9787
THETA $2.3471
APEX $2.6824
BSV $115.5449
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • General Bytes Bitcoin ATMs Hacked: $1.5 Million Stolen

    The company regularly conducted security audits, but the attackers found the vulnerability earlier.

    Leading Bitcoin ATM maker General Bytes said that hackers managed to steal cryptocurrency from the company and its customers using a zero-day vulnerability in the BATM management platform.

    General Bytes makes bitcoin ATMs that allow people to buy or sell over 40 virtual crypto coins. The company's corporate customers can deploy their ATMs using standalone management servers or the General Bytes cloud service.

    The company said over the weekend that hackers exploited a zero-day vulnerability tracked as BATM-4780 to remotely download a malicious Java application through the ATM's main service interface.

    “The attacker scanned the Digital Ocean cloud hosting IP space and found running CAS services on ports 7741, including the General Bytes cloud service,” General Bytes explained.

    The company issued an emergency statement on Twitter to urge customers to "take immediate action" and install the latest updates to protect their servers and funds from cybercriminals.

    As reported by the company itself, after downloading a malicious Java application, attackers were able to perform the following actions on compromised devices:

    the ability to access the company's database;
    the ability to read and decrypt API keys used to access funds in crypto wallets and exchanges;
    transfer of funds from crypto wallets;
    downloading usernames, their password hashes and disabling 2FA;
    the ability to access terminal event logs and search for cases where customers scanned private keys at an ATM.

     

    “The General Bytes cloud service was hacked in the same way as the standalone servers of other operators,” the company said in a statement.

    General Bytes also provided a long list of cryptocurrency addresses used by the hackers during the attack. According to the company, cyberthugs began stealing cryptocurrencies from bitcoin ATM servers on March 17, with the hackers' bitcoin address receiving 56.28570959 BTC worth about $1,589,000 and 21.79436191 Ethereum worth about $39,000.

    Although the attackers Bitcoin wallet still contains the stolen cryptocurrency, it seems that the cybercriminals used Uniswap to convert the stolen Ethereum into USDT.

    General Bytes recommended CAS (Crypto Application Server) administrators to check log files for any suspicious activity, and users to change passwords from their crypto wallets without fail.

    The company said it is shutting down its cloud service because it finds it "theoretically and practically impossible" to protect it from attackers. In the near future, the company will transfer the entire infrastructure to another cloud provider.

    General Bytes has also released two CAS security patches that fix the vulnerability exploited by the hackers. It is quite interesting that since 2021, the hacked system has been subjected to multiple security checks, but none of them have revealed a vulnerability due to which the attackers hit the jackpot.

    The company says it plans to conduct numerous security audits of its products with the help of several third-party cybersecurity companies in the near future. So General Bytes is going to find and fix other potential vulnerabilities before they are discovered and exploited by hackers.

    Author DeepWeb
    Mutual attacks of hackers: Lazarus Group against Euler Finance cracker
    CrowdStrike has discovered the first-ever Dero cryptojacking operation targeting Kubernetes infrastructure

    Comments 0

    Add comment