📈 Get daily crypto insights that make you smarter about your money

Lamassu Bitcoin ATM Vulnerabilities Exposed: How Physical Access Could Drain Your Wallet

Cybersecurity researchers have disclosed a set of critical vulnerabilities in Lamassu Douro Bitcoin ATMs that could have allowed attackers with nothing more than customer-level physical access to take full control of the machines and drain user wallets. The disclosure, published on January 23, 2024, by IOActive, underscores a persistent blind spot in the cryptocurrency ecosystem: the security of physical infrastructure.

The Exploit Mechanics

IOActive identified three distinct vulnerabilities tracked as CVE-2024-0175, CVE-2024-0176, and CVE-2024-0177. The attack chain begins with a remarkably simple observation: during the boot sequence, the Douro ATM briefly exposes the underlying operating system’s window manager. While this interaction window lasts only several seconds, it proves sufficient for an attacker to launch a terminal or installed application.

The researchers exploited the ATM’s built-in QR code reader to bypass the need for a physical keyboard. By crafting a malicious QR code containing their payload, they demonstrated that scanning it during the boot window could lead directly to a root shell. This was made possible by a vulnerability in the ATM’s software update mechanism, which allowed an attacker to supply a malicious file and trigger legitimate code execution processes.

Perhaps most alarming was the discovery that all Lamassu Douro devices shipped with an identical, weak root password that IOActive was able to crack within one minute. With Bitcoin trading at approximately $39,845 on the day of disclosure, the potential losses from compromised ATMs could have been substantial.

Affected Systems

The vulnerabilities affect the Lamassu Douro model, one of the most widely deployed Bitcoin ATM units globally. These machines are typically installed in public-facing locations such as convenience stores, gas stations, and shopping malls, precisely the environments where physical access by malicious actors is most difficult to prevent.

IOActive CTO Gunter Ollmann explained that an attacker who gains control of a vulnerable ATM can view and manipulate all user interactions. The theft would be limited to the user’s account balance during a single session, but a more sophisticated attacker could replace the entire user experience to socially engineer victims into revealing sensitive information such as online banking credentials.

The Mitigation Strategy

Lamassu Industries was notified of all three vulnerabilities in July 2023 and deployed fixes in October 2023, months before the public disclosure. The vendor hardened permissions for the update process, implemented a stronger root account passphrase, and blocked user access to the desktop environment during OS startup.

The coordinated disclosure process worked as intended. Lamassu had already patched the vulnerabilities before IOActive went public, meaning operators who kept their firmware updated were protected. However, the incident raises questions about how many Bitcoin ATM operators regularly install security updates.

Lessons Learned

This disclosure highlights several key security principles for the cryptocurrency hardware ecosystem. First, physical access remains a potent attack vector that cannot be ignored, even for devices designed for public use. Second, default credentials shared across all deployed units represent a systemic risk that vendors must eliminate at the manufacturing stage. Third, the QR code attack vector demonstrates that even seemingly benign input mechanisms can be weaponized by skilled researchers.

For the broader crypto community, the Lamassu case serves as a reminder that security must extend beyond digital protocols and smart contracts to encompass every physical touchpoint where users interact with cryptocurrency systems.

User Action Required

Bitcoin ATM operators running Lamassu Douro units should verify that their firmware has been updated to the October 2023 security patch or later. Users who have recently transacted at a Lamassu ATM should monitor their wallet activity and consider moving funds to a new address if they suspect any irregularities. As always, hardware wallet storage remains the most secure option for significant cryptocurrency holdings, with Bitcoin currently valued near $39,845 and Ethereum at $2,240.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making security decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Lamassu Bitcoin ATM Vulnerabilities Exposed: How Physical Access Could Drain Your Wallet”

  1. the boot sequence exposing the OS window manager for a few seconds is a hardware design flaw, not a software bug. you literally cannot patch physical exposure like that without redesigning the kiosk

    1. desk_recon_ scanning a malicious QR code during those seconds to get a root shell is clever though. the QR reader is meant for payment addresses, not payload delivery. nobody at Lamassu thought about that attack surface

  2. scanning a malicious QR code during boot to get root shell is embarrassingly simple. lamassu shipped these machines without basic boot hardening

    1. atm_rekt_ the 5 second boot window being exploitable via the built in QR reader is almost comical. physical access plus zero hardening equals disaster

  3. CVE-2024-0177 is wild. a QR reader that accepts shell commands during boot. whoever designed that input validation needs to find a new career

    1. qr_inject_ right. the QR reader was basically a root terminal if you timed it right. 5 seconds of exposure is all it takes with a pre-rendered payload

  4. CVE-2024-0175 through 0177 is three separate vulns on one ATM model. IOActive found the whole security model was basically decorative

  5. atm_archaeologist_

    three CVEs on a machine that handles cash to crypto conversions and the fix was basically a firmware update. physical access will always win against kiosk security, this just proves it again

  6. everyone audits smart contracts for millions of dollars but the ATM running a 3 year old kernel gets zero attention. physical security is where crypto keeps failing

  7. CVE-2024-0177 is the one that kills me. a QR code reader that accepts arbitrary shell commands during boot. who greenlit that design decision

    1. qr_oracle_ the QR reader accepting shell commands is the kind of thing that should have been caught in code review. input sanitization on embedded devices is security 101 and Lamassu skipped it entirely

    1. atm_ghost 5 seconds is generous. a prepared attacker with the QR pre-rendered needs maybe 1.5 seconds to scan during that window

      1. boot_sequence_ 1.5 seconds if pre-rendered. but you also need to know the QR reader position and angle. in practice maybe 3-4 seconds for a cold approach. still way too short for a boot window

      2. boot_sequence_ 1.5 seconds is generous if you pre-render the QR but you still need physical access to the machine undisturbed. not exactly a remote attack

    2. kernel_panic_

      the IOActive team also found that the ATM was running an outdated Linux kernel. layered vulnerabilities like an onion

      1. kernel_panic_ swiss cheese is right. fix any one of those three and the attack fails. three layers of security all broken at once is negligence not bad luck

        1. boot_lockdown_

          kiosk_drift_ three layers failing simultaneously is not bad luck its a culture of skipping security reviews. the firmware team, the hardware team, and the QA team all missed the same obvious attack path

      2. everyone audits smart contracts to death but the ATM running an unpatched kernel gets a pass. physical security is the blind spot

      3. outdated kernel plus no boot lockdown plus exposed window manager. three independent failures all needed to be present. classic swiss cheese model

        1. Anja M. three failures and the swiss cheese still got through production. hardware security audits in crypto are basically voluntary

    3. a 5 second window is generous for a prepared attacker. you can pre-encode the QR and just scan it the moment the window opens. the real failure is no keyboard input lockdown during boot

  8. IOActive did solid work here but every ATM vendor has similar issues. Lambright and BitAccess probably have worse gaps they just havent been tested yet

    1. kiosk_pentest_

      serial_uart_ Lambright and BitAccess probably have the same boot sequence issue. nobody physical security audits crypto ATMs because the margins are too thin for compliance budgets

  9. physical access attacks on ATMs are underrated. everyone focuses on smart contract bugs while the actual machine in front of you is running an unpatched OS

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,276.00-1.4%ETH$1,876.27-2.5%SOL$75.87-1.6%BNB$600.17-1.2%XRP$1.02-2.0%ADA$0.1947-1.2%DOGE$0.0695-1.5%DOT$0.8040-0.8%AVAX$6.48-0.6%LINK$8.29-0.6%UNI$3.94-2.6%ATOM$1.40+1.1%LTC$45.15-2.7%ARB$0.0801+2.2%NEAR$1.63-0.1%FIL$0.6962-2.1%SUI$0.6883-1.6%BTC$64,276.00-1.4%ETH$1,876.27-2.5%SOL$75.87-1.6%BNB$600.17-1.2%XRP$1.02-2.0%ADA$0.1947-1.2%DOGE$0.0695-1.5%DOT$0.8040-0.8%AVAX$6.48-0.6%LINK$8.29-0.6%UNI$3.94-2.6%ATOM$1.40+1.1%LTC$45.15-2.7%ARB$0.0801+2.2%NEAR$1.63-0.1%FIL$0.6962-2.1%SUI$0.6883-1.6%
Scroll to Top