Hackers drain bitcoin ATMs of $1.5 million by exploiting 0-day bug

BATM sold by General Bytes.
Expanding / BATM sold by General Bytes.

General byte

Hackers exploited a zero-day vulnerability to exfiltrate millions of dollars in digital coins from cryptocurrency ATMs, causing irreparable damage to customers, the kiosk maker said.

The robbery targeted ATMs sold by General Bytes, a company with multiple locations around the world. Short for Bitcoin ATMs, these his BATMs are installed in convenience stores and other businesses to allow people to exchange Bitcoins for other currencies and vice versa. A customer connects her BATM to a cryptographic application server (CAS). CAS can be managed by the customer or until now it was managed by General Bytes. For reasons that are not entirely clear, BATM offers the option of allowing customers to upload videos from their terminals to CAS using a mechanism known as the Master Server Interface.

go, go, disappear

Last weekend, General Bytes revealed that more than $1.5 million in bitcoin was exfiltrated from CAS operated by the company and its customers. To succeed in the robbery, an unknown threat actor exploited a previously unknown vulnerability that allows malicious Java applications to be uploaded and executed using this interface. The attackers then exfiltrated various hot wallets worth approximately 56 BTC worth approximately $1.5 million. General Bytes discovered the vulnerability and he patched it 15 hours later, but due to the way cryptocurrencies work, the loss was irreversible.

A General Bytes official wrote:

The night of March 17-18 was the most difficult time for us and some of our clients. Our entire team is working around the clock to collect all data on security breaches and continuously work to resolve all cases so that our clients can get back online and their ATMs operational as soon as possible. I’m in. We apologize for what happened, have reviewed all security procedures and are currently doing everything we can to keep affected customers.

The post described the flow of the attack as follows:

1. The attackers identified a security vulnerability in the master service interface used by BATM to upload videos to CAS.

2. The attackers scanned the IP address space managed by cloud host DigitalOcean Ocean to identify the CAS service running on port 7741. This includes the General Bytes Cloud service and other his BATM operators running servers at Digital Ocean.

3. Exploiting the vulnerability, the attacker uploaded a Java application directly to the application server used by the management interface. Application servers are configured by default to launch applications in the deployment folder.

Once the malicious application is running on the server, the attacker can (1) access the database and (2) read and decrypt the encoded API keys needed to access funds in hot wallets and exchanges. (3) from hot wallets to threat actor controlled wallets, (4) turning off 2FA by downloading usernames and password hashes, (5) accessing the terminal event log and confirming that the customer has private keys at the ATM. Scan the instance that scanned the . The sensitive data in step 5 was logged by older versions of the ATM software.

BATM Customers Do It Yourself Now

Going forward, General Bytes will no longer manage CAS on behalf of its customers, according to a post this weekend. This means that the terminal owner must manage the server itself. The company is also in the process of collecting data from its customers to verify any losses related to the hack, conducting internal investigations and working with authorities to identify threat actors.

According to General Bytes, the company has undergone “multiple security audits since 2021” and no exploited vulnerabilities were detected. The company is now seeking further assistance to protect BATM.

The incident highlights the risks of storing cryptocurrencies in internet-accessible wallets, commonly referred to as hot wallets. Over the years, huge amounts of money have been stolen from hot wallets by attackers exploiting various vulnerabilities in the cryptocurrency infrastructure, or by tricking wallet owners into providing the cryptographic keys required for withdrawals. Digital coins have been leaked illegally.

Security practitioners have long advised people to keep their funds in cold wallets. This means that the funds cannot access the internet directly. Unfortunately, BATM and other types of cryptocurrency ATMs generally cannot follow this best practice, as they require terminals to be connected to hot wallets in order to be able to trade in real time. This means that BATM will likely continue to be a prime target for hackers.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *