Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

Prediction markets are ditching the 'casino' label to become a regular part of how people track the news

May 2, 2026

Altura Enables On-chain Lending With AVLT on Morpho

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»General Bytes Bitcoin ATMs Hacked to Steal Funds
General Bytes Bitcoin ATMs Hacked to Steal Funds
Security

General Bytes Bitcoin ATMs Hacked to Steal Funds

October 6, 2023No Comments3 Mins Read

A leading provider of Bitcoin ATMs is urging clients to upgrade their systems immediately after revealing hackers exploited a zero-day vulnerability in its software last weekend to steal funds.

General Bytes explained in an advisory that the bug itself was found in the master service interface used by Bitcoin ATMs to upload videos to the server.

“The attacker scanned the Digital Ocean cloud hosting IP address space and identified running CAS [Crypto Application Server] services on ports 7741, including the General Bytes Cloud service and other GB ATM operators running their servers on Digital Ocean (our recommended cloud hosting provider),” it continued.

“Using this security vulnerability, [the] attacker uploaded his own application directly to [an] application server used by [the] admin interface. Application server was by default configured to start applications in its deployment folder.”

After uploading the Java app to the master service interface used by the ATMs, the threat actor was able to perform a range of actions including:

  • Accessing the database
  • Reading and decrypting API keys used to access funds in hot wallets and exchanges
  • Sending funds from hot wallets
  • Downloading usernames and password hashes and switching off two-factor authentication
  • Accessing terminal event logs and scanning for any instance where customers scanned private keys at the ATM

General Bytes said that, as well as other operators’ standalone servers, its own cloud service was breached by its attackers.

It urged any ATM operator to immediately patch their CAS software and consider all users’ CAS passwords and API keys to exchanges and hot wallets to have been compromised. As a result, they should reset passwords and generate new API keys/invalidate the old ones.

See also  Bitcoin Hashrate Reclaims 1 ZH/s as Hashprice Slides Lower

Read more on cryptocurrency ATMs: FCA: Crypto ATMs Are Illegal in the UK.

General Bytes is shutting its cloud service as a result of the attack.

“It is theoretically (and practically) impossible to secure a system granting access to multiple operators at the same time where some of them are bad actors. You’ll need to install your own standalone server. GB support will provide you with help you to migrate your data from the GB Cloud to your own standalone server,” it explained.

“Please keep your CAS behind a firewall and VPN. Terminals should also connect to CAS via VPN.  With VPN/Firewall, attackers from [the] open internet cannot access your server and exploit it. If your server was breached please reinstall the whole server including operation system.”

General Bytes missed the zero-day bug despite claiming to have conducted “multiple security audits” since 2021.

Source link

ATMs Bitcoin Bytes funds General hacked Steal

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

A new narrative for bitcoin that will last

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Pope Leo Says ‘I Am Not Afraid Of Trump’ – Amid War Of Words Over Iran Conflict

April 13, 2026

RubberVerseX Partners With Rocket-IDO to Propel Rubber RWAs Access And Usability in DeFi

February 22, 2026

German Police Shutter Country’s Largest Dark Web Market

February 26, 2026

Type above and press Enter to search. Press Esc to cancel.