{"id":18897,"date":"2023-03-19T05:46:31","date_gmt":"2023-03-19T05:46:31","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/major-cryptocurrency-atm-manufacturer-general-bytes-hacked-over-1-5m-in-bitcoin-stolen-bitcoin-news\/"},"modified":"2023-03-19T05:46:31","modified_gmt":"2023-03-19T05:46:31","slug":"major-cryptocurrency-atm-manufacturer-general-bytes-hacked-over-1-5m-in-bitcoin-stolen-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/major-cryptocurrency-atm-manufacturer-general-bytes-hacked-over-1-5m-in-bitcoin-stolen-bitcoin-news\/","title":{"rendered":"Major Cryptocurrency ATM Manufacturer General Bytes Hacked, Over $1.5M in Bitcoin Stolen \u2013 Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div id=\"\">\n<header class=\"article__header\">\n<\/header>\n<div class=\"featured_image_container\">\n\n<\/div>\n<p><strong>General Bytes experienced a security incident on March 17 and 18 that enabled a hacker to remotely access the master service interface and send funds from hot wallets, according to the company and sources. The breach forced a majority of U.S.-based crypto automated teller machine (ATM) operators to temporarily shut down. The hacker was able to liquidate 56.28 bitcoins, worth approximately $1.5 million, from about 15 to 20 crypto ATM operators nationwide.<\/strong><\/p>\n<h2>Crypto ATM Operators Temporarily Shut Down After General Bytes Security Breach Enables Hacker to Liquidate $1.5M in Bitcoin and Other Cryptocurrencies<\/h2>\n<p>The largest cryptocurrency automated teller machine (ATM) manufacturer, <a href=\"https:\/\/www.generalbytes.com\/en\/\">General Bytes<\/a>, has produced <a href=\"https:\/\/coinatmradar.com\/manufacturer\/5\/general-bytes-bitcoin-atm-producer\/\">9,505<\/a> such machines globally, with thousands located in the United States. On Saturday, March 18, the company <a href=\"https:\/\/twitter.com\/generalbytes\/status\/1637192687160897537?s=20\">informed the public<\/a> of a serious security incident that occurred on March 17 as well.<\/p>\n<p>\u201cWe released a statement urging customers to take immediate action to protect their personal information,\u201d the company explained at 4:42 p.m. (ET) on Saturday. \u201cWe urge all our customers to take immediate action to protect their funds and personal information and carefully read the security bulletin,\u201d the firm added.<\/p>\n<figure id=\"attachment_578986\" aria-describedby=\"caption-attachment-578986\" style=\"width: 1280px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-578986 size-full\" src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss.jpg\" alt=\"\" width=\"1280\" height=\"720\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss-300x169.jpg 300w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss-1024x576.jpg 1024w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss-768x432.jpg 768w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss-190x107.jpg 190w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss-380x214.jpg 380w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss-760x428.jpg 760w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2023\/03\/ctmradarss.jpg 1280w\" sizes=\"(max-width: 1280px) 100vw, 1280px\"\/><figcaption id=\"caption-attachment-578986\" class=\"wp-caption-text\">The number of General Bytes ATMs located around the world according to Coin ATM Radar statistics.<\/figcaption><\/figure>\n<p>General Bytes\u2019 <a href=\"https:\/\/generalbytes.atlassian.net\/wiki\/spaces\/ESD\/pages\/2885222430\/Security+Incident+March+17-18th+2023\">security bulletin<\/a> said the attacker was able to remotely upload their own Java application using the master service interface, which is typically used by terminals to upload videos. The attacker had access to BATM user privileges and was also able to access the database, read and decrypt API keys used to access funds in hot wallets and exchanges. In addition, the hacker could download usernames, access their password hashes, turn off 2FA, and send funds from hot wallets.<\/p>\n<p>Bitcoin.com News spoke with a U.S.-based cryptocurrency automated teller machine (ATM) operator who confirmed that all U.S. operators using General Bytes machines were shut down nationwide for the evening. The operator also mentioned that servers would have to be rebuilt from the ground up, which can be a lengthy process.<\/p>\n<p>Reportedly, General Bytes is transitioning crypto ATM operators to self-hosted servers. In the security bulletin, General Bytes stated that the company is discontinuing its cloud service. Furthermore, the firm explained that it had conducted multiple security audits since 2021, and none of them had identified this vulnerability.<\/p>\n<p>According to onchain statistics, the hacker siphoned 56.28 bitcoins worth approximately $1.5 million and also liquidated dozens of other cryptocurrencies such as <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ETH\" target=\"_blank\" rel=\"noopener\">ETH<\/a>, <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/USDT\" target=\"_blank\" rel=\"noopener\">USDT<\/a>, BUSD, <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ADA\" target=\"_blank\" rel=\"noopener\">ADA<\/a>, DAI, DOGE, SHIB, and <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/TRX\" target=\"_blank\" rel=\"noopener\">TRX<\/a>. The <a href=\"https:\/\/blockchair.com\/bitcoin\/address\/bc1qfa8pryacrjuzp9287zc2ufz5n0hdthff0av440\">bitcoin (BTC) address<\/a> holding the 56.28 <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/BTC\" target=\"_blank\" rel=\"noopener\">BTC<\/a> has not moved the funds since its last transaction at 3:20 a.m. on March 18. Some digital currencies were transferred to different locations, and a fraction was <a href=\"https:\/\/etherscan.io\/tx\/0x35bae2ead0c03fc22ae5658a7994ca66e0113d6fee1fe375a638695ac2ea30b8\">sent<\/a> to the decentralized exchange (DEX) platform Uniswap.<\/p>\n<p>General Bytes has experienced issues before, <a href=\"https:\/\/generalbytes.atlassian.net\/wiki\/spaces\/ESD\/pages\/2785509377\/Security+Incident+August+18th+2022\">recording<\/a> a security flaw on August 18, 2022. The attacker at the time leveraged a zero-day attack to \u201ccreate an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user.\u201d<\/p>\n<p>As for the March 17 and 18, 2023 hack, General Bytes not only disclosed the addresses used in the attack but also three IP addresses used by the attacker. The source who spoke with Bitcoin.com News on Saturday evening further noted that while their firm\u2019s system was hacked, the company runs a full node that\u2019s \u201clocked down enough\u201d to prevent the attacker from accessing funds.<\/p>\n<div class=\"article__body__tags-related__tags\">\n<h6 class=\"article__body__tags-related__title\">\nTags in this story<br \/>\n<\/h6>\n<div class=\"article__body__tags\"><a href=\"https:\/\/news.bitcoin.com\/tag\/2fa\/\">2FA<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/ada\/\">ada<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/api-keys\/\">API keys<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/atm\/\">ATM<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/atm-attack\/\">ATM attack<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/atms-down\/\">ATMs down<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/automated-teller-machine\/\">Automated Teller Machine<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/bitcoin\/\">Bitcoin<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/breach\/\">Breach<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/busd\/\">BUSD<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/cloud-service\/\">Cloud Service<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/crypto\/\">Crypto<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/crypto-atm-attack\/\">Crypto ATM attack<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/cryptocurrency\/\">Cryptocurrency<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/dai\/\">DAI<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/doge\/\">Doge<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/eth\/\">ETH<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/exchanges\/\">Exchanges<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/funds\/\">Funds<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/general-bytes\/\">General Bytes<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/general-bytes-atms\/\">General Bytes ATMs<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/general-bytes-crypto-atms\/\">General Bytes Crypto ATMs<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/hack\/\">Hack<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/hot-wallets\/\">hot wallets<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/ip-addresses\/\">IP addresses<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/java\/\">java<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/liquidation\/\">Liquidation<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/nationwide\/\">nationwide<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/onchain-statistics\/\">onchain statistics<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/operators\/\">operators<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/security\/\">Security<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/self-hosted-servers\/\">self-hosted servers<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/shib\/\">shib<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/trx\/\">trx<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/uniswap\/\">uniswap<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/us-atm-operators\/\">US ATM Operators<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/usdt\/\">USDT<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/vulnerability\/\">Vulnerability<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/zero-day-attack\/\">zero-day attack<\/a><\/div>\n<\/div>\n<p><em><strong>What do you think about the breach that affected General Bytes? Share your thoughts about this subject in the comments section below.<\/strong><\/em><\/p>\n<div class=\"article__body__author\">\n<div class=\"article__body__author__avatar\">\n<img src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg 1x, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-300x300.jpg 2x\" class=\"avatar avatar-150 photo\"\/>\n<\/div>\n<div class=\"article__body__author__info\">\n<h6 class=\"article__body__author__info__name\">\nJamie Redman <\/h6>\n<p class=\"article__body__author__info__about\">\nJamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 6,000 articles for Bitcoin.com News about the disruptive protocols emerging today.<br \/><span class=\"td-social-icon-wrap\"><br \/>\n<a target=\"_blank\" href=\"https:\/\/twitter.com\/jamieCrypto\" title=\"Twitter\" rel=\"noopener\"><br \/>\n<i class=\"td-icon-font td-icon-twitter\"\/><br \/>\n<\/a><br \/>\n<\/span>\n<\/p>\n<\/div>\n<\/div>\n<p class=\"images_credits\"><em><b>Image Credits<\/b>: Shutterstock, Pixabay, Wiki Commons<\/em><\/p>\n<div class=\"disclaimer\">\n<p><strong>Disclaimer<\/strong>: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. <a href=\"https:\/\/bitcoin.com\">Bitcoin.com<\/a> does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.<\/p>\n<\/div>\n<div class=\"bottom_article_widgets\">\n<aside id=\"bn_widget_spacing-18\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-21\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>More Popular News<\/span><\/h4>\n<\/aside>\n<aside id=\"bn_widget_spacing-19\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-46\" class=\"widget_text td_block_template_1 widget widget_custom_html\"\/>\n<aside id=\"bn_widget_spacing-20\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-30\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>In Case You Missed It<\/span><\/h4>\n<\/aside>\n<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script>(function(d, s, id) {\n        var js, fjs = d.getElementsByTagName(s)[0];\n        if (d.getElementById(id)) return;\n        js = d.createElement(s); js.id = id;\n        js.src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&version=v3.2\";\n        fjs.parentNode.insertBefore(js, fjs);\n    }(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/major-cryptocurrency-atm-manufacturer-general-bytes-hacked-over-1-5m-in-bitcoin-stolen\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) General Bytes experienced a security incident on March 17 and 18 that enabled a hacker to remotely access the master service interface and send funds from hot wallets, according to the company and sources. The breach forced a majority of U.S.-based crypto automated teller machine (ATM) operators to [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":18898,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/18897"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=18897"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/18897\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/18898"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=18897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=18897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=18897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}