Kraken Reveals Vulnerabilities in ‘Commonly Used’ Bitcoin ATMs
Kraken’s Security Labs, the cybersecurity arm of crypto exchange Kraken, has identified several vulnerabilities in the commonly used General Bytes BATMtwo Bitcoin ATM. “Our team found that a large number of ATMs are conf...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Kraken’s Security Labs, the cybersecurity arm of crypto exchange Kraken, has identified several vulnerabilities in the commonly used General Bytes BATMtwo Bitcoin ATM.
“Our team found that a large number of ATMs are configured with the same default admin QR code, allowing anyone with this QR code to walk up to an ATM and compromise it,” the Kraken Security Labs team wrote in a blog post disclosing the vulnerabilities.
“Our team also found a lack of secure boot mechanisms, as well as critical vulnerabilities in the ATM management system,” Kraken added.
Kraken’s discoveries have both hardware and software ramifications for the General Bytes machines.
The detailsAccording to Kraken, the General Bytes BATMtwo ATM only has one single compartment protected by a lock.
Bitcoin ATMs are a convenient way to purchase crypto - but are they safe?
Kraken Security Labs discovered flaws in one major ATM fleet. Learn more: https://t.co/sYmYY1PUMx pic.twitter.com/xwMmWcgmSY
— Kraken Exchange (@krakenfx) September 29, 2021
“Bypassing it provides direct access to the full internals of the device,” Kraken said, adding that an attacker could “compromise the cash box, embedded computer, webcam and fingerprint reader.”
When it comes to software, Kraken found that “many common security features were lacking.”
By attaching a USB keyboard to the BATMtwo, it was possible to gain full access to the user interface. This, in theory, would allow would-be-attackers to install applications, copy files, or even have the device send private keys to the attacker.
Improving securityKraken provided a series of remedies for both users and owners or operators of Bitcoin ATMs.
Should you wish to use a Bitcoin ATM, Kraken advises that you only use those which are in stores you trust, and ensure that it has “perimeter protections” like surveillance cameras.
For owners and operators of General Bytes’ Bitcoin ATMs, Kraken suggests changing the default QR admin code, placing it in a location where there are security controls, and following General Bytes’ “best practices.”
Why this matters
This bitcoin story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on DecryptRelated market context
Ethereum researchers are racing to close a zkEVM security gap before December
Ethereum’s better.codes contest now measures a cryptographic proof gap that researchers can attack from both sides. At 15:44:47 UT...
Rust supply chain attack exposes Solana ecosystem components to potential remote code execution
The attack highlights the critical need for enhanced security measures in blockchain ecosystems to prevent potential widespread vu...
SEC proposes a path for crypto projects to raise $75 million and later end the token’s securities contract
US regulators have already found a home for true Bitcoin perpetuals inside the CFTC’s exchange framework. The SEC is now turning t...
YZi Labs-backed BounceBit Chain shuts down after $3M exploit
The YZi-backed bitcoin restaking firm BounceBit announced today that it is shutting down its blockchain after hackers exploited an...
Uniswap Founder Warns CFTC That US Crypto Builders Are Moving Overseas
Uniswap founder Hayden Adams warned at the CFTC’s inaugural Innovation Advisory Committee meeting that regulatory uncertainty in t...
Open Source vs. Source-Available: What the Coldcard Failure Teaches About Bitcoin Software Incentives
Bitcoin Magazine Open Source vs. Source-Available: What the Coldcard Failure Teaches About Bitcoin Software Incentives Closed vers...