Bitcoin ATM Maker Fixes Vulnerability Allowing Hackers Full Control
Lamassu Industries, a Bitcoin ATM maker, has successfully addressed a vulnerability that could have given hackers complete control over its Bitcoin ATM machines. The flaw was discovered by ethical hackers from security firm IOActive while attempting to compromise Lamassu’s Bitcoin ATMs in 2023. The researchers identified and exploited several vulnerabilities that allowed them to gain full control over the ATMs. Through the exploit, attackers could view and manipulate interactions with the hijacked ATMs, potentially stealing Bitcoin from users’ wallets and tricking them into entering sensitive information.
Bitcoin ATM Vulnerability Gave Hackers ‘Full Control’
Gabriel Gonzalez, Director of Hardware Security at IOActive, commented on the severity of the vulnerability, stating that it could grant an attacker full control over a physical ATM machine. This includes draining all the money in the ATM and manipulating deposit amounts displayed on the note reader. The researchers emphasized the significance of these vulnerabilities if the ATMs were left unattended in various locations. Lamassu Industries promptly deployed a security patch to fix the vulnerabilities before they were publicly disclosed in 2024.
Number of Bitcoin ATMs in Decline
The number of installed Bitcoin ATMs worldwide fell in 2023 after rising every year for over a decade. This decline was mainly due to a decrease in machines in the US from 2022 to 2023, while other regions saw an increase. Coin ATM Radar data shows that the US accounts for 82% of all installed Bitcoin ATMs globally, with 27,621 machines as of last year.
Hot Take: Bitcoin ATM Vulnerability Fixed
Lamassu Industries has successfully patched a vulnerability that could have allowed hackers to gain full control over its Bitcoin ATMs. This fix comes after security firm IOActive’s ethical hackers identified and exploited the vulnerabilities, demonstrating the potential for attackers to steal Bitcoin and manipulate user interactions. The severity of the vulnerability could have allowed hackers to drain ATMs and display false deposit amounts. It is reassuring that Lamassu Industries promptly addressed the issue, deploying a security patch to protect users’ funds and urging ATM owners to update their software. This incident highlights the importance of regular security audits and updates in the cryptocurrency industry.