Vulnerable: Kraken reveals many US Bitcoin ATMs still use default admin QR codes

Vulnerable: Kraken reveals many US Bitcoin ATMs still use default admin QR codes

Kraken Security Labs has said that a “large number” of Bitcoin ATMs are vulnerable to hacking as the administrators never changed the default admin QR code.

In a Sept. 29 blog post, Kraken posted research from its Security Labs team which found that there are “multiple hardware and software vulnerabilities” in the General Bytes BATMTwo ATM range.

Our top trading bots

“Multiple attack vectors were found through the default administrative QR code, the Android operating software, the ATM management system and even the hardware case of the machine,” the post read.

Kraken’s security team stated that if a hacker gets their hands on the administrative code, they can essentially “walk up to an ATM and compromise it,” while also highlighting issues with the BATMtwo’s lack of secure boot mechanisms, as well as “critical vulnerabilities” in the ATM’s management system. However, General Bytes has reportedly already alerted ATM owners to the vulnerabilities:

“Kraken Security Labs reported the vulnerabilities to General Bytes on April 20, 2021, they released patches to their backend system (CAS) and alerted their customers, but full fixes for some of the issues may still require hardware revisions.”

The team also found that it was able to gain full access to the Android operating system behind the BATMTwo ATM by simply attaching a USB keyboard to the machine, and warned that “anyone” could “install applications, copy files or conduct other malicious activities.”

General Bytes is headquartered in the Czech Republic and, according to Coin ATM Radar, there are currently 6391 General Bytes ATMs installed worldwide, which represents 22.7% of the global market. However, those figures also account for BATMThree machines which weren’t reported on by Kraken.

The majority of the BATM ATMs are located in the U.S. and Canada, with a combined figure tallying in at around 5300, while Europe has around 824 ATMs installed.

Kraken is calling on BATMTwo owners and operators to change the default QR admin code, update the CAS server and place the ATMs in visible locations for security cameras.

Related: El Salvador ranks third in global Bitcoin ATM installations, data finds

Bitcoin ATM scams

While reports of hacked Bitcoin ATMs appear to be minimal, there is a history of crafty individuals building scams around crypto ATMs.

In March of 2019, the Toronto Police issued a public statement calling on the community to locate four men suspected of carrying out a series of “double-spending” transactions that fetched $150,000 worth of funds over a 10-day window. Double spending consists of canceling transactions before the ATM has had a chance to confirm but keeping the dispensed cash.

The Oakland Press reported on June. 22 of this year that two women from Berkley were scammed out of a combined $15,000 after fraudsters posed as public safety officers and federal employees. The scammers reportedly told the victims that they had outstanding warrants and tax violations, and ordered them to pay fines via local Bitcoin ATMs in the area.

And Malwarebytes posted research in August which uncovered a trend of gas station Bitcoin ATM scams in which threat actors would post fake jobs listings to dupe applicants into money laundering.

Read on relating to Cointelegraph
Institutional crypto funds see largest capital inflows for 3 months
CoinShares data revealed on Tuesday that institutional investments into cryptocurrencies are at the highest levels in three months, a sharp rise from the...
Interchain Accounts is the biggest upgrade to Cosmos since Stargate
On Thursday, the Interchain Foundation, a nonprofit steward of the Cosmos ecosystem, announced the release of Interchain Accounts.The Inter-Blockchain Communications...
Nifty News: Land grab in the Shiberse, floor prices fall, NFT house sale and more…
The team behind one of the top memecoin projects Shiba Inu (SHIB) is rolling out tokenized real estate dubbed “Shiba Lands” as part of its upcoming metaverse...
Ava Labs and EV maker Togg to build smart contract-based mobility services
Turkey’s electronic vehicle (EV) manufacturer Togg has announced a strategic partnership with Ava Labs to design and build smart contract-based services...
BadgerDAO reportedly suffers security breach and loses $10M
The BadgerDAO decentralized finance protocol appears to have suffered from a cyber attack leading to the loss of a reported $10 million at the time of writing. The...
American Airlines partners with decentralized travel market Winding Tree
Ethereum-based decentralized travel marketplace Winding Tree has announced a new collaboration with American Airlines that will allow select travelers to...
Ethereum supply flips briefly into deflation as gas fees spike
The theoretical deflationary properties of Ethereum’s London upgrade last week have already been seen in action on the blockchain, with almost 800 “deflationary...
Crypto joins stocks in ‘extreme fear’ after Bitcoin loses $30K support
Bitcoin (BTC) failed to regain $30,000 after losing support on Tuesday as Fear & Greed indexes raced each other to the bottom. BTC/USD 1-hour candle chart...
Chinese banks tell staff to recruit up to 300 new digital yuan users each
Chinese banks have begun a hard sell of digital yuan wallets, asking staff to recruit hundreds of new users each year. According to a translation of a June...
Gelato Network launches ‘G-UNI’ Uniswap v3 management token
While Uniswap’s highly-touted v3 has been racing to the top of TVL charts as of late, the need for active management has kept some retail participants out...
3 convincing signs the Bitcoin bears have stopped selling
The price of Bitcoin surged higher on May 26, breaching the $40,000 level for the first time in five days as traders brushed aside concerns about China's...
Is DeFi yield appetite rising again? Enso raises $5M as YFI hits new highs
The appetite for DeFi is rising again as blue chips are rallying and yield-earning strategy-sharing platforms, like Enso, are on the rise.Enso, a platform...
European Investment Bank reportedly to issue bonds with blockchain tech
The European Investment Bank, an international financial institution owned by European Union member states, is reportedly exploring blockchain technology...
Buffett, Munger, Gates: What The Investment Guru Have To Say About BTC
This week CNBC brought together three whales of the financial world – Bill Gates, Warren Buffett, and Charlie Munger. Among other things, all of them...
Miner WannaMine To Replace The Virus WannaCry
The EternalBlue exploit, once stolen from the US National Security Agency, continues to be used by attackers as a component of the malicious software....