Dark Web vendors are now selling malwares specifically designed to target bitcoin ATMs, according to cybersecurity firm TrendMicro.
In the blog post, the cybersecurity firm cites an advertisement posted by an “apparently established and respected” user on a darknet forum. The malware reportedly exploits a service vulnerability of bitcoin ATMs that allows the user to receive bitcoins worth up to 6,750 in US dollars, euros, or pounds. At a cost of $25 000, the package includes, “a ready-to-use card that comes with EMV and near-field communication (NFC) capabilities.”
The seller has reportedly received over 100 online reviews both for the malware and other products. Another thread reveals that the seller is also offering regular ATM malware that has been updated for EMV standards, a global standard for credit and debit payment cards based on chip card technology. According to other comments on the thread, the malware works by exploiting a menu vulnerability to disconnect the bitcoin ATM from the network in order to disable alarms.
More https://app.algory.io/app/cryptonews/52071/bitcoin-atm-malware-found-for-sale-in
What do you think about it? Everything can be hacked? And is it only the matter of time when we see the news that XYZ hardware wallet has been hacked or sth like that?
I want to believe this should be a wake up call for entrepreneurs running bitcoin ATM services to be more updated concerning their security infrastructure as I hold the view that the compromise is from them and not bitcoin itself or else as it is expected that the ATM is connected to a storage somewhere that owns more than 6750 bitcoins for the hacker to be a beneficiary in which if not for the vulnerability in their own system, then the whole of Coinbase, Xapo or Blockchain.com that holds several amounts of bitcoin would have gone bankrupt by now.
Everyday hackers would always hack in which there is hardly anything anyone can do about it. Preaching, discouraging won't even stop it but the responsibility is service providers to ensure that their security is fool proof.