General Bytes, a bitcoin automated teller machine (ATM) manufacturer, has lost over $1.5m of bitcoin (BTC) following an exploit on Mar. 17 and 18.
General Bytes hacked
In a security update on Mar. 18, General Bytes said the hacker, or a group of hackers, found an exploit on their master service interface before using it to send funds to their hot wallets. Following this hack, General Bytes was temporarily forced to shut down as it assessed the damage caused.
General Bytes admit that hackers could access their database through the master service interface. Subsequently, the attackers could download usernames, password hashes, and, critically, turn off user two-factor authentication (2FA). They could also decrypt API keys to send funds to hot wallets and exchanges. Because of this leeway, the hacker could automatically send funds from hot wallets.
Hackers eventually stole 56.28 BTC from about 15 to 20 ATM operators through this flaw. When writing on Mar. 19, the address still held 56.28 BTC; no funds had been transferred.
Go to Source to See Full Article
Author: Dalmas Ngetich