BPOI Banner
Decrypt logo Decrypt logo

How a Bitcoin ATM Operator Thinks Hackers Accessed Personal Data for 58,000 Users

Major United States-based Bitcoin automated teller machine (BTM) company Byte Federal has suffered a major data breach.

A Thursday filing with Maine’s attorney general shows that Byte Federal’s breach allowed the attacker to access the personal data of 58,000 customers, including 111 Maine residents. The company noticed the attack on Nov. 18, more than a month after it occurred on Sept. 30.

Venket Naga, co-founder and CEO of security-focused data storage service Serenity, told Decrypt that the incident shows the dynamic nature of constantly expanding cybersecurity threats. According to him, crypto industry firms “must adopt adaptive frameworks that evolve with emerging risks, posing risks to both the physical and underlying infrastructure involved with blockchain.”

CoinATMRadar data shows that Byte Federal operates 1,356 Bitcom ATMs in the United States. This is equivalent to about 4.3% of all crypto ATMs in the country.

The attack was reportedly a consequence of a third-party service being exploited. After detecting the incident a month later, Byte Federal decided to shut down its platform and reassured users that no funds were lost.

A joint statement from smart contract auditors at crypto cybersecurity firm Hacken Ataberk Yavuzer and Olesia Bilenka explains that the “incident occurred due to an unpatched or outdated GitLab system.” It goes on to add that “inadequate server segmentation” could be what allowed attackers to access sensitive customer data.

“It is very likely that the GitLab repositories contained sensitive credentials to access Byte Federal’s databases, which include name, birthdate, address, phone number, email address, government-issued ID, social security number, transaction activity, and user photograph information,” the auditors highlighted.

Despite the breach, the company noted that it found no evidence that customer data was actually misused or accessed. “Nonetheless, we are taking precautionary measures to ensure the security of your data and to help alleviate any concerns you may have.” the letter to customers read.

Byte Federal also noted it’s working with an independent cybersecurity team on a forensic investigation of the incident and might pursue legal action.

Byte Federal said it applied a hard reset to all customer accounts and sent a notice concerning the incident. The company also changed internal passwords, the password management system, tokens and keys to prevent further breaches.

The company urged customers to reset their login credentials. It warned that users may be asked to verify their personal information—providing more confidential data to a firm that just experienced a potential data leak.

“The Byte Federal incident is yet another example of how forcing commercial activities to retain their customers’ data is the worst practice concerning their privacy,” an anonymous former Bitcoin ATM operator told Decrypt. They wanted to withhold their identity because they chose to shut down their service rather than comply with know-your-customer rules.

“In the case of cryptocurrencies, these data breaches are even more dangerous for users because they associate their personal information with a specific type of financial activity, making them easy targets for theft and fraud,” the former Bitcoin ATM operator added.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

Adrian Zmudzinski

https://decrypt.co/296415/bitcoin-atm-hacker-personal-data

2024-12-13 13:06:23

bitcoin
Bitcoin (BTC) $ 82,055.99 1.23%
ethereum
Ethereum (ETH) $ 1,805.11 1.51%
tether
Tether (USDT) $ 1.00 0.02%
xrp
XRP (XRP) $ 2.06 4.54%
bnb
BNB (BNB) $ 593.96 1.83%
solana
Solana (SOL) $ 123.78 0.99%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.162961 3.85%
cardano
Cardano (ADA) $ 0.639527 5.47%
tron
TRON (TRX) $ 0.233081 1.11%
staked-ether
Lido Staked Ether (STETH) $ 1,804.24 1.54%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 82,045.98 1.00%
the-open-network
Toncoin (TON) $ 3.90 2.37%
chainlink
Chainlink (LINK) $ 13.16 3.85%
leo-token
LEO Token (LEO) $ 9.09 5.89%
stellar
Stellar (XLM) $ 0.263123 2.22%
usds
USDS (USDS) $ 1.00 0.03%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,163.14 1.43%
avalanche-2
Avalanche (AVAX) $ 18.56 3.71%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 3.95%
sui
Sui (SUI) $ 2.21 6.78%
hedera-hashgraph
Hedera (HBAR) $ 0.158305 7.68%
litecoin
Litecoin (LTC) $ 81.91 4.74%
mantra-dao
MANTRA (OM) $ 6.22 2.52%
polkadot
Polkadot (DOT) $ 4.01 2.29%
bitcoin-cash
Bitcoin Cash (BCH) $ 297.27 3.02%
bitget-token
Bitget Token (BGB) $ 4.43 4.82%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.01%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999475 0.11%
weth
WETH (WETH) $ 1,805.81 1.41%
pi-network
Pi Network (PI) $ 0.697308 9.26%
hyperliquid
Hyperliquid (HYPE) $ 12.73 1.29%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,919.85 1.43%
whitebit
WhiteBIT Coin (WBT) $ 28.17 0.43%
monero
Monero (XMR) $ 215.14 0.47%
uniswap
Uniswap (UNI) $ 5.84 2.16%
dai
Dai (DAI) $ 0.999774 0.01%
aptos
Aptos (APT) $ 5.18 2.47%
near
NEAR Protocol (NEAR) $ 2.52 6.80%
susds
sUSDS (SUSDS) $ 1.05 0.03%
pepe
Pepe (PEPE) $ 0.000007 1.49%
okb
OKB (OKB) $ 47.69 2.12%
gatechain-token
Gate (GT) $ 22.04 1.63%
crypto-com-chain
Cronos (CRO) $ 0.098776 6.95%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 82,122.00 1.01%
tokenize-xchange
Tokenize Xchange (TKX) $ 33.23 4.83%
mantle
Mantle (MNT) $ 0.779466 3.68%
first-digital-usd
First Digital USD (FDUSD) $ 0.998443 0.03%
ethereum-classic
Ethereum Classic (ETC) $ 16.63 0.32%
internet-computer
Internet Computer (ICP) $ 5.16 4.46%
bitcoin
Bitcoin (BTC) $ 82,055.99 1.23%
ethereum
Ethereum (ETH) $ 1,805.11 1.51%
tether
Tether (USDT) $ 1.00 0.02%
xrp
XRP (XRP) $ 2.06 4.54%
bnb
BNB (BNB) $ 593.96 1.83%
solana
Solana (SOL) $ 123.78 0.99%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.162961 3.85%
cardano
Cardano (ADA) $ 0.639527 5.47%
tron
TRON (TRX) $ 0.233081 1.11%
staked-ether
Lido Staked Ether (STETH) $ 1,804.24 1.54%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 82,045.98 1.00%
the-open-network
Toncoin (TON) $ 3.90 2.37%
chainlink
Chainlink (LINK) $ 13.16 3.85%
leo-token
LEO Token (LEO) $ 9.09 5.89%
stellar
Stellar (XLM) $ 0.263123 2.22%
usds
USDS (USDS) $ 1.00 0.03%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,163.14 1.43%
avalanche-2
Avalanche (AVAX) $ 18.56 3.71%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 3.95%
sui
Sui (SUI) $ 2.21 6.78%
hedera-hashgraph
Hedera (HBAR) $ 0.158305 7.68%
litecoin
Litecoin (LTC) $ 81.91 4.74%
mantra-dao
MANTRA (OM) $ 6.22 2.52%
polkadot
Polkadot (DOT) $ 4.01 2.29%
bitcoin-cash
Bitcoin Cash (BCH) $ 297.27 3.02%
bitget-token
Bitget Token (BGB) $ 4.43 4.82%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.01%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999475 0.11%
weth
WETH (WETH) $ 1,805.81 1.41%
pi-network
Pi Network (PI) $ 0.697308 9.26%
hyperliquid
Hyperliquid (HYPE) $ 12.73 1.29%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,919.85 1.43%
whitebit
WhiteBIT Coin (WBT) $ 28.17 0.43%
monero
Monero (XMR) $ 215.14 0.47%
uniswap
Uniswap (UNI) $ 5.84 2.16%
dai
Dai (DAI) $ 0.999774 0.01%
aptos
Aptos (APT) $ 5.18 2.47%
near
NEAR Protocol (NEAR) $ 2.52 6.80%
susds
sUSDS (SUSDS) $ 1.05 0.03%
pepe
Pepe (PEPE) $ 0.000007 1.49%
okb
OKB (OKB) $ 47.69 2.12%
gatechain-token
Gate (GT) $ 22.04 1.63%
crypto-com-chain
Cronos (CRO) $ 0.098776 6.95%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 82,122.00 1.01%
tokenize-xchange
Tokenize Xchange (TKX) $ 33.23 4.83%
mantle
Mantle (MNT) $ 0.779466 3.68%
first-digital-usd
First Digital USD (FDUSD) $ 0.998443 0.03%
ethereum-classic
Ethereum Classic (ETC) $ 16.63 0.32%
internet-computer
Internet Computer (ICP) $ 5.16 4.46%