Vulnerable: Kraken reveals many US Bitcoin ATMs still use default admin QR codes

Vulnerable: Kraken reveals many US Bitcoin ATMs still use default admin QR codes

Kraken has urged BATMTwo ATM owners and operators to change the admin QR code for their ATMs to avoid potential attacks. Kraken Security Labs has said that a “large number” of Bitcoin ATMs are vulnerable to hacking as the administrators never changed the default admin QR code. In a Sept. 29 blog post, Kraken posted research from its Security Labs team which found that there are “multiple hardware and software vulnerabilities” in the General Bytes BATMTwo ATM range. “Multiple attack vectors were found through the default administrative QR code, the Android operating software, the ATM....


Related News

Kraken Unveils Security Vulnerabilities In A Large Number Of U.S. Bitcoin ATMs

Bitcoin ATMs are becoming a popular fixture in major cities around the world. With the growth of bitcoin has come to the increased installations of automated teller machines where people can purchase bitcoin on the go. There are currently at least 26,000 bitcoin ATMs installed around the world. But the vast majority of these ATMs […]

First US Bitcoin ATMs Coming to Seattle and Austin

Seattle and Austin will soon become the first US cities with bitcoin ATMs, provided everything goes according to plan. The machines are coming from ATM manufacturer Robocoin and the company claims they will be installed by the end of the month, Reuters reports. Robocoin ATMs are more elaborate than their Lamassu counterparts. They are cash-only machines and they have a few additional security features, such as biometric and optical scanners. In theory, this should allow much higher levels of security than regular ATMs. The barcode scanner can be used to scan QR codes and transfer bitcoins....

Hackers exploit zero day bug to steal from General Bytes Bitcoin ATMs

The hack meant that all crypto going into the Bitcoin ATM would instead be siphoned off by the hackers. Bitcoin ATM manufacturer General Bytes had its servers compromised via a zero-day attack on Aug. 18, which enabled the hackers to make themselves the default admins and modify settings so that all funds would be transferred to their wallet address. The amount of funds stolen and number of ATMs compromised has not been disclosed but the company has urgently advised ATM operators to update their software.The hack was confirmed by General Bytes on Aug. 18, which owns and operates 8827....

Report: GALA token exploit resulted from public leak of private key on GitHub

It appears that the leaked private key caused a change of ownership in the compromised smart contract 70 days prior. According to a new post by blockchain security firm SlowMist on Nov. 7, it appears that the last week’s token exploit affecting GameFi project Gala Games resulted from a public leak of applicable security keys on GitHub. As told by SlowMist, pNetwork, the cross-chain interoperability bridge used by Gala Games on the BNB Smart Chain, had three privileged roles in its smart contract pGALA.“The Admin role is used to manage upgrades and changes to the Admin address of the proxy....

Hash Watch: Kraken Announces BCH Fork Plans, Bitcoin ABC Reveals Two-Pronged ...

A number of third party infrastructure providers have announced contingency plans for the upcoming Bitcoin Cash upgrade on November 15, 2020. Hitbtc has revealed the exchange’s plans to halt bitcoin cash transactions on that day, and it plans to credit all users with an additional token if a blockchain split happens. Additionally, Kraken has announced plans for the fork as well with airdrop support requirements. The Bitcoin Cash (BCH) network will upgrade on November 15, 2020, and the latest feature that will be added to the network is the ASERT Difficulty Adjustment Algorithm....