• Latest
  • Trending
  • All
  • News
  • Lifestyle
Kraken Security Labs Identifies Vulnerabilities In Commonly Used Bitcoin ATM thumbnail

Kraken Security Labs Identifies Vulnerabilities In Commonly Used Bitcoin ATM

September 30, 2021
MassDOT Sets Timeline for Cape Cod's $2.1B Sagamore Bridge Replacement thumbnail

MassDOT Sets Timeline for Cape Cod’s $2.1B Sagamore Bridge Replacement

March 14, 2026
Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why. thumbnail

Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why.

March 10, 2026
Five Republicans Vote To Force Bondi To Answer For Epstein Files Debacle thumbnail

Five Republicans Vote To Force Bondi To Answer For Epstein Files Debacle

March 6, 2026
Patriots to cut Stefon Diggs despite productive 1,000-yard season and Super Bowl run thumbnail

Patriots to cut Stefon Diggs despite productive 1,000-yard season and Super Bowl run

March 5, 2026
Serious investigation or ‘clown show’? Clintons’ closed testimonies on Epstein leave room for disagreement thumbnail

Serious investigation or ‘clown show’? Clintons’ closed testimonies on Epstein leave room for disagreement

March 1, 2026
Perioperative enfortumab vedotin + pembrolizumab tied to improved outcomes with bladder cancer thumbnail

Perioperative enfortumab vedotin + pembrolizumab tied to improved outcomes with bladder cancer

February 28, 2026
It’s a Buyer’s Market: America Has 44% More Home Sellers Than Buyers—a Near-Record Gap thumbnail

It’s a Buyer’s Market: America Has 44% More Home Sellers Than Buyers—a Near-Record Gap

February 25, 2026
New Democrats' Bill seeks to refund Trump's illegal IEEPA-based tariffs, plus interest thumbnail

New Democrats’ Bill seeks to refund Trump’s illegal IEEPA-based tariffs, plus interest

February 25, 2026
Pregnant woman hospitalized after ICE detention in Burlington thumbnail

Pregnant woman hospitalized after ICE detention in Burlington

February 25, 2026
Blizzards blast Northeast with snow, hurricane force winds thumbnail

Blizzards blast Northeast with snow, hurricane force winds

February 24, 2026
Maps show snow totals, blizzard warnings for major winter storm thumbnail

Maps show snow totals, blizzard warnings for major winter storm

February 23, 2026
6 Patriots trade targets who would take Drake Maye to the next level thumbnail

6 Patriots trade targets who would take Drake Maye to the next level

February 22, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact
  • Donate
Sunday, March 15, 2026
66 °f
Wellfleet
58 ° Tue
63 ° Wed
68 ° Thu
61 ° Fri
  • Login
  • Register
FREE Cape Cod News
DONATE
  • FREE Cape Cod News
  • Cape Cod News
  • News
    • News
    • Massachusetts
    • Breaking News
    • Cape Cod Weather
    • Storm Watch
    • Environment
  • Politics
    • democrats
    • republicans
  • Business
    • business
    • cryptocurrency
    • economy
    • money
    • Real Estate
    • Tech
  • World
  • Entertainment
  • Lifestyle
  • Photos
    • Orleans
    • Eastham
    • Wellfleet
    • Truro
    • Provincetown
    • Brewster
    • Chatham
  • Videos
No Result
View All Result
Free Cape Cod News
No Result
View All Result
  • FREE Cape Cod News
  • Cape Cod News
  • News
  • Politics
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Photos
  • Videos
Home Business Cryptocurrency News

Kraken Security Labs Identifies Vulnerabilities In Commonly Used Bitcoin ATM

FREE Cape Cod News by FREE Cape Cod News
September 30, 2021
in Cryptocurrency News
Reading Time: 6 mins read
Donate
0
Kraken Security Labs Identifies Vulnerabilities In Commonly Used Bitcoin ATM thumbnail
635
SHARES
1.4k
VIEWS
Share on TwitterShare on Facebook

Bitcoin ATMs offer a convenient and friendly way for consumers to purchase cryptocurrencies. That ease of use can sometimes come at the expense of security.

Kraken Security Labs has uncovered multiple hardware and software vulnerabilities in a commonly used cryptocurrency ATM: The General Bytes BATMtwo (GBBATM2). Multiple attack vectors were found through the default administrative QR code, the Android operating software, the ATM management system and even the hardware case of the machine.

Our team found that a large number of ATMs are configured with the same default admin QR code, allowing anyone with this QR code to walk up to an ATM and compromise it. Our team also found a lack of secure boot mechanisms, as well as critical vulnerabilities in the ATM management system.

Kraken Security Labs has two goals when we uncover crypto hardware vulnerabilities: to create awareness for users around potential security flaws and alert the product manufacturers so they can remedy the issue. Kraken Security Labs reported the vulnerabilities to General Bytes on April 20, 2021, they released patches to their backend system (CAS) and alerted their customers, but full fixes for some of the issues may still require hardware revisions.

In the below video, we briefly demonstrate how malicious attackers can exploit vulnerabilities in the General Bytes BATMtwo cryptocurrency ATM.

By reading on, Kraken Security Labs outlines the exact nature of these security risks to help you better understand why you should exercise caution before using these machines.

Before you use a cryptocurrency ATM

  1. Only use cryptocurrency ATMs in locations and stores you trust.
  2. Make sure the ATM has perimeter protections, such as surveillance cameras, and that undetected access to the ATM is unlikely.

If you own or operate BATMs

  1. Change the default QR admin code if you didn’t do so during the initial setup.
  2. Update your CAS server and follow General Bytes’ best practices.
  3. Place ATMs in locations with security controls, like surveillance cameras.

One QR Code to Rule Them All

Scanning a QR code is all it takes to take over a lot of BATMs.

When an owner receives the GBBATM2, they are instructed to set up the ATM with an “Administration Key” QR-code that must be scanned on the ATM. The QR code containing a password must be set separately for each ATM in the backend system:

However, when reviewing the code behind the admin interface, we found that it contains a hash of a default factory setting administration key. We purchased multiple used ATMs from different sources and our investigation revealed that each had the same default key configuration.

This implies that a significant number of GBBATM2 owners were not changing the default admin QR code. At the time of our testing, there was no fleet management for the administration key, meaning each QR code must be changed manually.

Therefore, anyone could take over the ATM through the administration interface by simply changing the ATMs management server address.

The Hardware

No Compartmentalization and Tamper Detection

The GBBATM2 only has a single compartment that is protected by a single tubular lock. Bypassing it provides direct access to the full internals of the device. This also places significant additional trust in the person that replaces the cashbox, as it’s easy for them to backdoor the device.

The device contains no local or server-side alarm to alert others that the internal components are exposed. At this point, a would-be attacker could compromise the cash box, embedded computer, webcam and fingerprint reader.

Inside a crypto ATM: Off-the-shelf components such as a Microsoft webcam, the bill acceptor, and the custom carrier board.

The Software

Insufficient Lockdown of Android OS

The Android operating system of the BATMtwo lacks many common security features as well. We found that by attaching a USB keyboard to the BATM, gaining direct access to the full Android UI is possible – allowing anyone to install applications, copy files or conduct other malicious activities (such as sending private keys to the attacker). Android supports a “Kiosk Mode” that would lock the UI into a single application — which could prevent a person from accessing other areas of the software, however this was not enabled on the ATM.

A keyboard and USB drive are all that is needed to gain root access to the ATM once it’s opened.

No Firmware/Software Verification

The embedded computer in the BATMtwo: A Variscite i.MX6 SoM with a custom carrier board.

The BATMtwo contains an NXP i.MX6-based embedded computer. Our team found that the BATMtwo does not make use of the secure-boot functionality of the processor, and that it can be reprogrammed simply by plugging a USB cable into a port on the carrier board and turning the computer on while holding down a button.

In addition, we found that the bootloader of the device is unlocked: Simply connecting a serial adapter to the UART port on the device is enough to gain privileged access to the bootloader.

It should be noted that the secure-boot process of a lot of i.MX6 processors is vulnerable to an attack, however newer processors with the vulnerability patched are on the market (though they might be lacking availability given the global chip-shortage).

No Cross-Site Request Forgery Protections in the ATM Backend

BATM ATMs are managed using a “Crypto Application Server” – a management software that can be hosted by the operator, or licensed as SaaS.

Our team found the CAS does not implement any Cross-Site Request Forgery protections, making it possible for an attacker to generate authenticated requests to the CAS. While most endpoints are somewhat protected by very difficult to guess IDs, we were able to identify multiple CSRF vectors that can successfully compromise the CAS.

Use Caution and Explore Alternatives

The BATM cryptocurrency ATMs prove to be an easy alternative for people to purchase digital assets. However, the security of these machines remains in question due to known exploits in both their hardware and software.

Kraken Security Labs recommends that you only use a BATMtwo at a location you trust.

Check out our online security guide to learn more about how to protect yourself when making crypto transactions.

Read More

Tags: bitcoincryptocurrencykraken

FREE Digital Newspaper Subscription!
Sign up for your free digital subscription. The FREE Cape Cod News

Unsubscribe
FREE Cape Cod News

FREE Cape Cod News

Free Cape Cod News is what's happening in the Cape Cod, U.S and World & what people are talking about right now. Local newspaper. Stay in the know. Subscribe to get notified about our latest news.

Related Posts

Coinbase says recent data breach impacts 69,461 customers thumbnail
Cryptocurrency News

Coinbase says recent data breach impacts 69,461 customers

by FREE Cape Cod News
May 22, 2025
Trump's family could make hundreds of millions from an Abu Dhabi crypto investment thumbnail
Cryptocurrency News

Trump’s family could make hundreds of millions from an Abu Dhabi crypto investment

by FREE Cape Cod News
May 4, 2025
Crypto security will always be a game of ‘cat and mouse’  — Wallet exec thumbnail
Cryptocurrency News

Crypto security will always be a game of ‘cat and mouse’ — Wallet exec

by FREE Cape Cod News
March 24, 2025
KuCoin Pleads Guilty to Federal Charges And Enters $300 Million Settlement thumbnail
Cryptocurrency News

KuCoin Pleads Guilty to Federal Charges And Enters $300 Million Settlement

by FREE Cape Cod News
January 29, 2025
Load More
Please login to join discussion

Follow Us on Twitter

FREE Cape Cod News - Your source for local Cape Cod news, latest breaking U.S. and World news. Every day, all day. Subscribe for your favorite categories.

  • Trending
  • Comments
  • Latest
MassDOT Sets Timeline for Cape Cod's $2.1B Sagamore Bridge Replacement thumbnail

MassDOT Sets Timeline for Cape Cod’s $2.1B Sagamore Bridge Replacement

March 14, 2026
Serious investigation or ‘clown show’? Clintons’ closed testimonies on Epstein leave room for disagreement thumbnail

Serious investigation or ‘clown show’? Clintons’ closed testimonies on Epstein leave room for disagreement

March 1, 2026
Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why. thumbnail

Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why.

March 10, 2026
MassDOT Sets Timeline for Cape Cod's $2.1B Sagamore Bridge Replacement thumbnail

MassDOT Sets Timeline for Cape Cod’s $2.1B Sagamore Bridge Replacement

0
Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why. thumbnail

Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why.

0
Patriots to cut Stefon Diggs despite productive 1,000-yard season and Super Bowl run thumbnail

Patriots to cut Stefon Diggs despite productive 1,000-yard season and Super Bowl run

0
MassDOT Sets Timeline for Cape Cod's $2.1B Sagamore Bridge Replacement thumbnail

MassDOT Sets Timeline for Cape Cod’s $2.1B Sagamore Bridge Replacement

March 14, 2026
Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why. thumbnail

Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why.

March 10, 2026
Five Republicans Vote To Force Bondi To Answer For Epstein Files Debacle thumbnail

Five Republicans Vote To Force Bondi To Answer For Epstein Files Debacle

March 6, 2026

FREE Cape Cod News On Twitter

Today’s News

  • MassDOT Sets Timeline for Cape Cod’s $2.1B Sagamore Bridge Replacement March 14, 2026
  • Small-Business Owners Are Getting Less Optimistic About Sales. The Latest Numbers Show Why. March 10, 2026
  • Five Republicans Vote To Force Bondi To Answer For Epstein Files Debacle March 6, 2026
  • Patriots to cut Stefon Diggs despite productive 1,000-yard season and Super Bowl run March 5, 2026
  • Serious investigation or ‘clown show’? Clintons’ closed testimonies on Epstein leave room for disagreement March 1, 2026
FREE Cape Cod News

Copyright © 2024 Free Cape Cod News

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact
  • Donate

Follow Us

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • FREE Cape Cod News
  • Cape Cod News
  • News
    • News
    • Massachusetts
    • Breaking News
    • Cape Cod Weather
    • Storm Watch
    • Environment
  • Politics
    • democrats
    • republicans
  • Business
    • business
    • cryptocurrency
    • economy
    • money
    • Real Estate
    • Tech
  • World
  • Entertainment
  • Lifestyle
  • Photos
    • Orleans
    • Eastham
    • Wellfleet
    • Truro
    • Provincetown
    • Brewster
    • Chatham
  • Videos
  • Login
  • Sign Up

Copyright © 2024 Free Cape Cod News