Cryptocurrency [loss] $2M+

"General Bytes Bitcoin ATMs hacked using zero-day, $1.5M stolen"

2023-03-18 [vendor] General Bytes Bitcoin ATM [chain] bitcoin, ethereum
Primary Source ↗
Financial Loss $1.6M (1,628,000 USD)
Blockchain(s) Bitcoin, Ethereum

Incident Details

The largest manufacturer of Bitcoin ATMs, General Bytes, disclosed that attackers had stolen more than $1.6 million by exploiting a vulnerability in their software. The company released a statement on March 18 disclosing the breach, and urging operators of their ATMs to immediately upgrade their software to patch the devices.In addition to standalone servers, General Bytes’ cloud service was impacted, and the company announced that it would be permanently shuttering it. “It is theoretically (and practically) impossible to secure a system granting access to multiple operators at the same time where some of them are bad actors,” wrote the company in their statement explaining the decision, apparently unaware that this is something software companies find themselves doing all the time.This exploit was the second breach suffered by General Bytes this year, after hackers exploited a vulnerability in August 2022 that allowed them to steal customer funds. It’s unknown how much was stolen in that attack. The company also patched multiple hardware and software issues in their ATMs in September 2021, after Kraken Security Labs discovered issues including poor security practices that would allow attackers to “walk up to an ATM and compromise it”.

Total loss estimated at $1,628,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
General Bytes Bitcoin ATM

Timeline

  1. 2023-03-18 Breach occurred
  2. 2023-03-18 Publicly disclosed