General Bytes Hack

Reported loss $1.5M
Ethereum
Key Leaked via Infrastructure

What happened

On March 17-18, 2023, an attacker broke into servers running General Bytes' Crypto Application Server (CAS), the back end for its Bitcoin ATMs, and emptied operators' hot wallets. The Block, citing on-chain analysis of the attacker's wallet, reported at least 56 BTC (about $1.5 million) stolen; on-chain tallies reported by Bitdefender put the haul at 56.283 BTC, 21.823 ETH and 1,219.183 LTC, worth over $1.6 million.

The attacker scanned DigitalOcean's cloud IP space for CAS instances on port 7741, including General Bytes' own cloud service and standalone operator servers, and abused a zero-day in the interface ATMs use to upload videos. General Bytes released patched CAS versions, told operators to reinstall servers, rotate every API key and password and check wallet settings, published the attacker's addresses, and shut down its cloud service, saying a system shared by many operators, some of them possibly bad actors, could not be made secure.

How it happened

  1. The attacker scanned DigitalOcean's IP address space for CAS servers exposing the master service interface on port 7741.
  2. That interface, used by ATMs to upload videos to the server, let the attacker upload a Java application remotely; it was deployed as a .war file and ran with the batm user's privileges.
  3. With code running on the server, the attacker read the database and decrypted the stored API keys for hot wallets and exchanges. They could also read usernames and password hashes, turn off 2FA, and see terminal logs, including cases where customers had scanned private keys at an ATM.
  4. Using the decrypted keys, the attacker sent funds out of operators' hot wallets, at least 56 BTC plus ETH and LTC according to on-chain analysis.

Protocol details

Classification Frontend & Infrastructure
Protocol Type Other

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.