Bitcoin Automated Teller Machines (BATMs) process millions of dollars in cryptocurrency and fiat transactions worldwide. During our research at IOActive Labs, we conducted a comprehensive physical and logical security assessment of leading Bitcoin ATM models (published in the research paper Owning a Bitcoin ATM: Hardware & Logical Exploitation).
Hardware Inspection & Debug Access
Physical access to internal cabinets revealed standard commercial motherboards connected to cash dispensers, bill acceptors, and thermal receipt printers via USB and serial buses. Crucially, the internal hardware communication buses lacked end-to-end cryptographic mutual authentication.
By attaching hardware sniffers to the internal serial lines, it was possible to eavesdrop on unencrypted peripheral commands and inject spoofed cash dispenser pulse commands.
Firmware Analysis & Privilege Escalation
Extracting the onboard storage allowed us to audit the kiosk application layer. The application executed with full administrative privileges and exposed local network interfaces vulnerable to command injection.
- Unauthenticated Peripherals: Dispenser controller responded directly to raw binary packets without challenge-response tokens.
- Root File System Encryption Missing: Boot partitions were stored in plaintext on standard eMMC flash chips.
- Kiosk Breakout: Standard USB keyboard injection enabled rapid shell access in under 30 seconds.
Original IOActive Research Publication & Advisory
Read the full research paper detailing bus tapping methodologies, physical microswitch bypasses, and root firmware exploitation on Lamassu Bitcoin ATMs (CVE-2024-0674 / CVE-2024-0675).
Read IOActive Research Paper ↗