CSIDB logo
Incident

General Bytes

Incident posture

Attack window
Aug 2022
Location
Czechia
Status
Historical
CIA posture
Available to members
Updated
2026-07-15 02:03

Linked entities

Victim
General Bytes
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Aug 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers exploited a zero-day vulnerability in a Bitcoin ATM manufacturer's server software, enabling remote creation of administrative accounts to hijack cryptocurrency transactions. The attackers scanned cloud hosting IPs to identify vulnerable servers, then altered ATM configurations to divert customer funds to their own wallets. The company addressed the flaw through server patches and reported the incident to law enforcement, noting financial losses totaling $16,000 for affected operators despite previous security audits.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In August 2022, Bitcoin ATM manufacturer General Bytes disclosed a cyberattack exploiting a zero-day vulnerability in its Crypto Application Server (CAS) software, which facilitated the theft of cryptocurrency from its users. The flaw, present in CAS versions released since December 8, 2020, allowed attackers to remotely create an administrative user via the CAS administrative interface by exploiting a URL call intended for initial server setup. Threat actors identified vulnerable CAS instances by scanning DigitalOcean cloud IP addresses for services running on ports 7777 or 443. Upon successful exploitation, they added a default admin user named "gb" to compromised systems. This unauthorized access enabled the modification of cryptocurrency settings on two-way ATMs, redirecting customer transactions to attacker-controlled wallets. The incident occurred three days after General Bytes publicly announced a "Help Ukraine" feature on its ATMs, though no direct link between the two events was confirmed.

General Bytes responded by releasing two server patches to mitigate the vulnerability and reported the incident to Czech law enforcement. The attackers specifically altered ATM configurations to intercept funds when customers attempted to send coins to the machines, exploiting the "invalid payment address" setting. While the initial disclosure did not specify the total impact, a subsequent advisory cited operator-reported losses of $16,000. The company noted that multiple security audits conducted since 2020 had failed to identify the vulnerability prior to exploitation. No details regarding the number of breached servers or broader cryptocurrency losses beyond the confirmed $16,000 were provided in the available information.

Sources

Sources available to members: 3 sources.

CSIDB