Kraken Reveals Vulnerabilities in ‘Commonly Used’ Bitcoin ATMs
Kraken’s Security Labs, the cybersecurity arm of crypto exchange Kraken, has identified several vulnerabilities in the commonly used General Bytes BATMtwo Bitcoin ATM. “Our team found that a large number of ATMs are conf...
Kraken’s Security Labs, the cybersecurity arm of crypto exchange Kraken, has identified several vulnerabilities in the commonly used General Bytes BATMtwo Bitcoin ATM.
“Our team found that a large number of ATMs are configured with the same default admin QR code, allowing anyone with this QR code to walk up to an ATM and compromise it,” the Kraken Security Labs team wrote in a blog post disclosing the vulnerabilities.
“Our team also found a lack of secure boot mechanisms, as well as critical vulnerabilities in the ATM management system,” Kraken added.
Kraken’s discoveries have both hardware and software ramifications for the General Bytes machines.
The detailsAccording to Kraken, the General Bytes BATMtwo ATM only has one single compartment protected by a lock.
Bitcoin ATMs are a convenient way to purchase crypto - but are they safe?
Kraken Security Labs discovered flaws in one major ATM fleet. Learn more: https://t.co/sYmYY1PUMx pic.twitter.com/xwMmWcgmSY
— Kraken Exchange (@krakenfx) September 29, 2021
“Bypassing it provides direct access to the full internals of the device,” Kraken said, adding that an attacker could “compromise the cash box, embedded computer, webcam and fingerprint reader.”
When it comes to software, Kraken found that “many common security features were lacking.”
By attaching a USB keyboard to the BATMtwo, it was possible to gain full access to the user interface. This, in theory, would allow would-be-attackers to install applications, copy files, or even have the device send private keys to the attacker.
Improving securityKraken provided a series of remedies for both users and owners or operators of Bitcoin ATMs.
Should you wish to use a Bitcoin ATM, Kraken advises that you only use those which are in stores you trust, and ensure that it has “perimeter protections” like surveillance cameras.
For owners and operators of General Bytes’ Bitcoin ATMs, Kraken suggests changing the default QR admin code, placing it in a location where there are security controls, and following General Bytes’ “best practices.”
Original source
Read on DecryptRelated market context
Kraken named to FXC Intelligence’s 2026 Cross-Border Payments 100
TL;DR Payward and Kraken have been named to FXC Intelligence’s 2026 Cross-Border Payments 100, the eighth annual market list of th...
Kraken Becomes Official Crypto Exchange Supporter Of FIFA World Cup 2026
TL;DR Kraken says it has become the Official Crypto Exchange Supporter of the FIFA World Cup 2026. The tournament expands to 48 te...
Haiti fans organize communal watch parties for first World Cup in 52 years as Kraken backs tournament
Haiti's World Cup return fosters unity and cultural pride among its diaspora, highlighting the power of sports to bridge communiti...
Kraken’s FIFA World Cup deal puts crypto front and center as tournament kicks off
The Kraken-FIFA partnership could significantly boost crypto adoption and scrutiny, influencing regulatory landscapes and fan enga...
FIFA World Cup 2026 kicks off with crypto partnerships from Kraken, Chainlink, and Chiliz
The 2026 FIFA World Cup's crypto partnerships could significantly boost blockchain adoption and reshape fan engagement in sports....
Carlo Ancelotti confident Brazil can compete with any team as crypto fan tokens heat up ahead of World Cup opener
Ancelotti's leadership and Brazil's strong squad could boost fan token interest, impacting crypto markets and enhancing digital fa...