Kraken Reveals Vulnerabilities in ‘Commonly Used’ Bitcoin ATMs
Kraken’s Security Labs, the cybersecurity arm of crypto exchange Kraken, has identified several vulnerabilities in the commonly used General Bytes BATMtwo Bitcoin ATM. “Our team found that a large number of ATMs are conf...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Kraken’s Security Labs, the cybersecurity arm of crypto exchange Kraken, has identified several vulnerabilities in the commonly used General Bytes BATMtwo Bitcoin ATM.
“Our team found that a large number of ATMs are configured with the same default admin QR code, allowing anyone with this QR code to walk up to an ATM and compromise it,” the Kraken Security Labs team wrote in a blog post disclosing the vulnerabilities.
“Our team also found a lack of secure boot mechanisms, as well as critical vulnerabilities in the ATM management system,” Kraken added.
Kraken’s discoveries have both hardware and software ramifications for the General Bytes machines.
The detailsAccording to Kraken, the General Bytes BATMtwo ATM only has one single compartment protected by a lock.
Bitcoin ATMs are a convenient way to purchase crypto - but are they safe?
Kraken Security Labs discovered flaws in one major ATM fleet. Learn more: https://t.co/sYmYY1PUMx pic.twitter.com/xwMmWcgmSY
— Kraken Exchange (@krakenfx) September 29, 2021
“Bypassing it provides direct access to the full internals of the device,” Kraken said, adding that an attacker could “compromise the cash box, embedded computer, webcam and fingerprint reader.”
When it comes to software, Kraken found that “many common security features were lacking.”
By attaching a USB keyboard to the BATMtwo, it was possible to gain full access to the user interface. This, in theory, would allow would-be-attackers to install applications, copy files, or even have the device send private keys to the attacker.
Improving securityKraken provided a series of remedies for both users and owners or operators of Bitcoin ATMs.
Should you wish to use a Bitcoin ATM, Kraken advises that you only use those which are in stores you trust, and ensure that it has “perimeter protections” like surveillance cameras.
For owners and operators of General Bytes’ Bitcoin ATMs, Kraken suggests changing the default QR admin code, placing it in a location where there are security controls, and following General Bytes’ “best practices.”
Why this matters
This bitcoin story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on DecryptRelated market context
Ethereum Founder Vitalik Buterin Says AI Won’t Doom Crypto Security
The Ethereum co-founder said AI could help developers mathematically verify entire software systems, turning the same technology p...
Wall Street gains direct oversight of Web3 security as S&P Global buys OpenZeppelin
S&P Global has agreed to acquire smart contract security company OpenZeppelin in a transaction that would put the crypto company i...
Fake AI crypto software is secretly replacing browser wallet extensions
HP Wolf Security, the company's threat-research team, said a fake AI crypto-trading assistant distributed malware that could repla...
Stani’s Aave “Uber plan” could turn everyday crypto savers into Washington’s worst political nightmare
The Senate gave DeFi a policy setback on Sept. 15. Then Aave founder Stani Kulechov used it to frame a new product challenge. Aave...
Payward files to offer single-stock perpetual futures on Kraken for US traders
The launch of single-stock perpetual futures could revolutionize US trading by offering continuous market access and new leverage...
3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt
A routine Radix code refactor created a vault flaw that enabled a roughly $1.3 million theft and later forced validators to halt t...