{"id":69806,"date":"2024-01-25T07:54:57","date_gmt":"2024-01-25T11:54:57","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=69806"},"modified":"2024-01-25T07:55:01","modified_gmt":"2024-01-25T11:55:01","slug":"bitcoin-atm-vulnerability-could-give-hackers-total-control-ioactive-cto","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/bitcoin-atm-vulnerability-could-give-hackers-total-control-ioactive-cto\/","title":{"rendered":"Bitcoin ATM Vulnerability Could Give Hackers Total Control &#8211; IOActive CTO"},"content":{"rendered":"\n<p>According to IOActive chief technology officer (CTO) Gunter Ollman,  through the vulnerabilities of <a href=\"https:\/\/coinscreed.com\/staging\/bitcoin-atms-installation-decrease-by-11-in-last-1-year.html\" target=\"_blank\" rel=\"noreferrer noopener\">Bitcoin ATMs<\/a>, attackers could gain unrestricted access to steal users\u2019 Bitcoin through the ATM. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"959\" height=\"548\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126.png\" alt=\"Bitcoin ATM Vulnerability Could Give Hackers Total Control - IOActive CTO\" class=\"wp-image-38046\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126.png 959w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126-300x171.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126-768x439.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126-150x86.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126-750x429.png 750w\" sizes=\"(max-width: 959px) 100vw, 959px\" \/><figcaption class=\"wp-element-caption\">Bitcoin ATM Vulnerability Could Give Hackers Total Control &#8211; IOActive CTO<\/figcaption><\/figure>\n\n\n\n<p>In 2023, security researchers from IOActive attempted to seize control of several ATMs issued by Lamassu. While trying to penetrate the ATMs, the research team identified several vulnerabilities they effectively exploited.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"366\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-117-750x366.png\" alt=\"\" class=\"wp-image-69816\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-117-750x366.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-117-300x147.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-117-768x375.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-117.png 944w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Security researchers demonstrating access to the camera and the ATM\u2019s system. Source: IOActive<\/figcaption><\/figure>\n\n\n\n<p>According to<a href=\"https:\/\/ioactive.com\/article\/ioactive-names-gunter-ollmann-as-chief-technology-officer\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> IOActive's chief technology officer, Gunter Ollman<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, the exploit, told Cointelegraph, enabled attackers to &#8220;view and manipulate interactions with the hijacked ATM.&#8221; The security expert explained that hackers could steal Bitcoin from the user's wallet by exploiting the ATM's vulnerabilities. Ollman elaborated:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cA sophisticated attacker, with sufficient preparation, could modify or replace the entire user experience of the ATM and socially engineer the user into performing additional actions.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Additionally, the executive asserted that the assailant might be able to deceive the user by requesting their bank account information in return for complimentary or discounted Bitcoin. In addition, Ollman reassured the community that the effect on an individual's account balance would be minimal.<\/p>\n\n\n\n<p>&#8220;In the end, when an operating system compromise of a device restricts the attack surface to the user's level of trust in the device or its manufacturer,&#8221; he explained further.<\/p>\n\n\n\n<p>Additionally, the director of<a href=\"https:\/\/coinscreed.com\/staging\/the-relationship-between-crypto-security-and-regulation.html\" target=\"_blank\" rel=\"noreferrer noopener\"> hardware security<\/a> at IOActive, Gabriel Gonzalez, stated that an assailant with physical access to the ATM could gain &#8220;complete control&#8221; over the vulnerability. <\/p>\n\n\n\n<p>Gonzalez further expounded that the vulnerability not only might enable the pilferage of Bitcoin but also potentially deplete the entire fund balance in the ATM. Moreover, it can mislead the note reader by exhibiting an imprecise depiction of the deposited funds, thereby inflating the quantity.<\/p>\n\n\n\n<p>The executive further stated that the ATMs, mainly when left unattended in their designated locations, could have been subject to various forms of exploitation.<\/p>\n\n\n\n<p>Despite the potentially lethal consequences that the ATM's defect could have imposed on its users, the ATM provider had already executed a security upgrade before the public disclosure of the vulnerability in 2024. The organization formally notified Bitcoin ATM proprietors, advising them to update their machines immediately.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to IOActive chief technology officer (CTO) Gunter Ollman, through the vulnerabilities of Bitcoin ATMs, attackers could gain unrestricted access to steal users\u2019 Bitcoin through the ATM. In 2023, security researchers from IOActive attempted to seize control of several ATMs issued by Lamassu. While trying to penetrate the ATMs, the research team identified several vulnerabilities [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":38046,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[1717,2118,18045],"class_list":["post-69806","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-bitcoin-atms","tag-hacker","tag-ioactive"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-126.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/69806","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=69806"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/69806\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/38046"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=69806"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=69806"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=69806"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}