Owning a Bitcoin ATM: Hardware & Logical Exploitation

Bitcoin Automated Teller Machines (BATMs) process millions of dollars in cryptocurrency and fiat transactions worldwide. During our research at IOActive Labs, we conducted a comprehensive physical and logical security assessment of leading Bitcoin ATM models (published in the research paper Owning a Bitcoin ATM: Hardware & Logical Exploitation).

Hardware Inspection & Debug Access

Physical access to internal cabinets revealed standard commercial motherboards connected to cash dispensers, bill acceptors, and thermal receipt printers via USB and serial buses. Crucially, the internal hardware communication buses lacked end-to-end cryptographic mutual authentication.

By attaching hardware sniffers to the internal serial lines, it was possible to eavesdrop on unencrypted peripheral commands and inject spoofed cash dispenser pulse commands.

Firmware Analysis & Privilege Escalation

Extracting the onboard storage allowed us to audit the kiosk application layer. The application executed with full administrative privileges and exposed local network interfaces vulnerable to command injection.

Original IOActive Research Publication & Advisory

Read the full research paper detailing bus tapping methodologies, physical microswitch bypasses, and root firmware exploitation on Lamassu Bitcoin ATMs (CVE-2024-0674 / CVE-2024-0675).

Read IOActive Research Paper ↗
Gabriel González García

About Gabriel González García

Hardware hacker, embedded systems security researcher, and author of Attacking & Securing U-Boot. Specializing in fault injection, bootloader exploitation, satellite terminal security, and cryptographic hardware analysis.

Connect on LinkedIn More Research