Normal view

There are new articles available, click to refresh the page.
Today — 23 July 2026Main stream

Ethereum price faces $2,000 test as oil surge revives rate fears

By: Rony Roy
23 July 2026 at 08:30
Ethereum price has remained trapped below $2,000 as rising oil prices, renewed interest-rate concerns and BitMEX’s planned shutdown have tempered bullish sentiment despite continued spot ETF inflows. According to data from crypto.news, Ethereum (ETH) price traded near $1,927 on July…

BlackRock, Coinbase, Strategy Among Nine Firms Launching the Bitcoin Security Consortium, Pledging $15 Million To BTC Security Development

23 July 2026 at 09:33

Bitcoin Magazine

BlackRock, Coinbase, Strategy Among Nine Firms Launching the Bitcoin Security Consortium, Pledging $15 Million To BTC Security Development

Nine of the largest names in institutional Bitcoin launched the Bitcoin Security Consortium on Thursday, a group backed by $15 million in member pledges over three years to fund work on the network’s long-term security, including preparation for a future era of quantum computing.

Founding members are Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy, and Strategy, a lineup that spans holders, custodians, exchanges, infrastructure and payments providers, and asset managers. 

The consortium’s day-to-day work falls to Mike Schmidt, executive director of the developer non-profit Brink, who serves in a volunteer role.

Schmidt tweeted about the role, saying, “I said yes because supporting Bitcoin’s developers and helping people understand their work are the two things I’ve spent my time in Bitcoin on, through Brink and Optech. This group wants to do both: fund the people already securing Bitcoin, and bring accurate information about that work to audiences it doesn’t currently reach.”

Each member directs its own funding to the developers, researchers, and organizations it chooses; the $15 million figure is an aggregate of independent pledges rather than a pooled fund. The group also plans to serve as a reference point on Bitcoin’s security for investors, the public, and the media, and to publish material it will update as the field develops.

Funding advocates

The consortium drew clear limits around its role. It says it does not develop or direct Bitcoin’s protocol, takes no position on specific protocol changes, and does not speak for Bitcoin or its developers.

It casts itself on the model of industry groups that fund the open-source software they rely on without controlling the work. 

“Bitcoin’s development is, and will remain, the work of a global, decentralized community of contributors,” the group said.

“As long-term holders, we have every incentive to see Bitcoin remain secure for generations,” said Phong Le, Chief Executive Officer of Strategy. “Funding the people who do this work, and helping inform the conversation around it, is a natural way for us to contribute.” 

Robert Mitchnick, BlackRock’s Global Head of Digital Assets, said Bitcoin Core developers “do incredibly important work,” and that the members would make “significant additional funding available to support Bitcoin’s long-term security needs.”

Brink, the non-profit coordinating the effort, has funded open-source Bitcoin work since 2020, including more than $1 million to developers in a single year and the first third-party security audit of Bitcoin Core. Schmidt co-founded the group with developer John Newbery.

Bitcoin and quantum 

Much of the consortium’s stated focus lands on the quantum question. Large-scale quantum computers able to break BTC’s cryptography do not exist today, and credible estimates place such capability years out. 

The group frames post-quantum protection as a long-term priority the technical community already works on, and positions itself as a grounded source as that work moves.

That framing matches a wider institutional turn toward the issue. Coinbase has formed a quantum computing advisory board, Galaxy launched its own quantum readiness initiative with developer grants days before, and BlackRock has listed quantum computing as a risk in its spot BTC ETF filings. 

Developers, for their part, have proposed migration plans built on schemes such as BIP-360 that would move coins to quantum-resistant addresses, and the Bitcoin Policy Institute has warned the timeline is compressing.

Views on urgency diverge, a split the consortium’s members embody. Adam Back, founder of member firm Blockstream, has called the quantum threat decades away, while other voices place a capable machine within the next several years. 

The stakes are large either way, since Coinbase research has estimated that between 20% and 50% of BTC’s supply, much of it in older wallet formats, could face exposure to a long-range quantum attack. 

The consortium sidesteps the timeline debate and stakes its role on funding and information rather than a forecast. Its own summary holds that the risk is real, yet the network is preparing.

This post BlackRock, Coinbase, Strategy Among Nine Firms Launching the Bitcoin Security Consortium, Pledging $15 Million To BTC Security Development first appeared on Bitcoin Magazine and is written by Micah Zimmerman.

Russian naval gun maker patents a wheeled artillery version

23 July 2026 at 07:23
A Russian shipyard supplier best known for arming warships just patented a way to put its naval gun on wheels, and the design tells a story about a much larger program that appears to have stalled. Saint Petersburg-based Arsenal Machine-Building Plant, the manufacturer behind Russia’s AK-100, AK-130, AK-726 and A-192M naval guns, has patented a […]

Britain isn't considering datacenters' thirst for water in its 'AI superpower' ambitions

23 July 2026 at 04:30
The UK government's blueprint for turning Britain into an AI superpower largely ignore the water datacenters need, prompting warnings that these facilities could end up competing with homes and businesses for supply. The warning comes as parts of southern, central, and eastern England move closer to drought, putting the pressure on water availability firmly on the agenda. MPs were told earlier this year that official forecasts of England's future water needs excluded datacenters, despite government efforts to encourage more of them to power AI development. In written evidence to a parliamentary committee, Water UK, the trade association for Britain's water industry, said the government's policies for delivering AI Growth Zones under the AI Opportunities Action Plan appear to assume the country will have ample supplies of H₂O. This, Water UK argues, limits the investment that water companies can plan for, including new reservoirs, leaving future supply constrained by forecasts that it says are already too low. The submission claims some housing projects are already being blocked and businesses barred from expanding because water isn't available. Water UK says supply is so constrained that the Environment Agency has effectively imposed a moratorium on business expansion in East Anglia and parts of Essex. Water UK is calling for new supply infrastructure to be fast-tracked and abstraction limits to be reviewed. It also wants operators to cover the infrastructure costs their facilities create, minimum efficiency standards for server farms, and requirements to use non-potable water wherever possible. Current economics push operators toward cooling methods that save energy rather than water. Where water is relatively cheap compared to energy, operators favour using more of it to use less power, as The Register previously detailed. UK energy prices are among the highest in the developed world. The submission says global datcenter water use is expected to more than double between 2025 and 2050, with services-based economies like the UK likely to account for a disproportionate share of that growth. T he UK datacenter pipeline is almost double that of the next-largest country in Europe, with ambitions to treble capacity by 2030. A government report [PDF] says most of the UK's current datacenter capacity is sited in and around London, with more than 1,000 MW located there. Europe's largest datacenter cluster is reportedly in Slough, Berkshire, home to as many as 35 facilities. The same report notes UK datacenter operators aren't required to report water use, so no official consumption figures exist, though the Water Research Centre estimates English facilities use almost 1.9 billion liters a year. According to PublicTechnology, the Government Digital Sustainability Alliance warned last year that AI is driving a significant, yet often underestimated, rise in water consumption, threatening water security both globally and in the UK A Water UK spokesperson told The Register: "We desperately want to supply the water that datacenters need. That's impossible because the UK government explicitly excludes them from its water planning framework for England." Water companies have been given approval to build ten reservoirs, but they will take years to complete, the spokesperson added. "We need planning hurdles cleared and water efficiency standards for datacenters introduced. Major businesses should pay for the water infrastructure they need so that the costs don't fall onto households." The Register also asked the relevant government department for comment, but had not received a response by the time of publication. ®

Industrial GPU Adapted for the Desktop

23 July 2026 at 01:00

As technologies change and adapt, we’re often left with seemingly useless junk that has nowhere to go. Certainly anyone still sitting on a pile of floppy disks feels this way sometimes, but odds are anyone who owns a mining ASIC or an NFT can attest to that as well. The trillions of dollars flowing into GPU-based data centers will likely become the next victim of this trend, so if you want to capitalize on the losses of some venture capitalist you’ll want to figure out a way to get GPUs meant for a server into your desktop doing useful work.

Of course, calling these devices GPUs is a bit of a stretch compared to the Radeon and GeForce cards many of us are used to using for gaming. These don’t even have a PCIe slot or video output, after all. But, as [Oscar] notes, the VRAM and GPU cores are very real and can still do useful work. An adapter board is able to mate a Tesla V100 SXM2 16 GB GPU to a standard PCIe slot, which solves the first problem, but the major downside from there is that the cooling fan for this unit was literally deafeningly loud. At 82 dB it was about as loud as a lawnmower, which is fine in a server rack but not great in a bedroom. [Oscar] found a way to tamp down the fan speed, making it usable in a home.

Without video output, the utility of these cards mainly comes from adding VRAM and compute for tasks that benefit from parallel computing. Using tensor splitting, [Oscar] is running a local LLM with this card alongside his RTX 4080, providing 32 GB of VRAM on his NixOS system. With his benchmarking tests, the LLM sports impressive stats for a self-hosted model, ranking somewhere around Claude Sonnet 4.6. What’s even more impressive is that this is all done for around £200, and with the rate the various LLM companies are ratcheting up pricing could pay itself back very quickly. If trading off performance for cost is acceptable, though, it’s possible to run local models on much less powerful hardware as well.

Yesterday — 22 July 2026Main stream

Uniswap Governance Proposal Would Route Optimism Fees To UNI Burns

22 July 2026 at 20:15

Uniswap governance is reviewing a proposal that would route protocol fees from selected Optimism pools toward UNI token burns, testing a more direct connection between deployment-level activity and token economics.

The proposal is specific to Optimism pools. That distinction matters because it is not a protocol-wide fee burn across all Uniswap deployments.

Still, the idea is significant.

UNI holders have long debated how Uniswap’s massive trading footprint should connect to the UNI token. A fee-routing and burn mechanism on Optimism would give governance a narrower test case rather than changing the entire protocol at once.

TL;DR

  • Uniswap governance is reviewing a proposal tied to Optimism pool fees.
  • The proposal would route selected fees toward UNI token burns.
  • The scope is Optimism-specific, not a protocol-wide Uniswap burn mechanism.

UNI Tokenomics Are Back In Focus

Uniswap is one of the most important decentralized exchanges in crypto, but its token economics have always been debated.

The protocol processes large amounts of trading volume, yet UNI does not automatically capture value from every trade in a direct, simple way. Governance controls key decisions, but tokenholders have often wanted clearer links between protocol usage and token value.

That is why fee routing matters.

If protocol fees from selected pools can be used to buy and burn UNI, the token may gain a more visible economic connection to exchange activity. Burns reduce supply, at least mechanically, and they are easy for the market to understand.

But implementation is everything.

Which pools are included? How much fee revenue is routed? How are burns executed? What are the legal and governance implications? Could the model expand beyond Optimism later?

Those are the questions governance needs to answer.

Why Optimism Is A Sensible Test

Optimism is a useful place to test the idea because it narrows the scope.

Uniswap is deployed across multiple networks. A protocol-wide change would be more complex and more controversial. Testing fee routing on a specific deployment gives governance a way to examine the mechanics without rewriting the entire system.

It also reflects how DeFi is becoming more chain-specific.

Activity on Ethereum mainnet is different from activity on Optimism, Arbitrum, Base, Polygon, or other networks. Fees, users, liquidity, incentives, and trading behavior vary by chain.

A deployment-level test may help Uniswap learn whether fee burns are practical in one environment before considering broader changes.

That does not guarantee the proposal will pass or expand.

But it gives UNI holders a concrete experiment to debate.

Burns Are Simple, But Not Magic

The market often likes token burns because they are easy to understand.

Fewer tokens can sound bullish. But burns only matter if the underlying fee stream is meaningful, recurring, and large enough to affect supply over time.

A small burn from limited pools may be symbolically important but economically modest. A larger mechanism could matter more, but it may also raise more governance, liquidity, and regulatory questions.

That is why the Optimism-specific scope is important.

The proposal can show how the process works without overpromising immediate impact. UNI holders should watch the mechanism, not just the headline.

If fees are routed transparently and burns are executed reliably, the model may gain support. If the impact is tiny or the process creates new complications, governance may be more cautious.

Uniswap Is Searching For Token Value Alignment

The broader issue is value alignment.

Uniswap has strong product-market fit. It is widely used, deeply integrated, and central to DeFi liquidity. But tokenholders still want to know how that usage translates into UNI’s long-term role.

Governance power alone may not be enough for every investor.

A fee burn proposal gives the DAO another possible answer. It connects protocol activity, chain-specific revenue, and token supply mechanics in a way that is easier to track.

That does not mean every Uniswap fee should automatically flow to tokenholders. The protocol also needs liquidity, incentives, legal resilience, and sustainable governance.

But the discussion is important.

It shows that DeFi’s largest protocols are still experimenting with how to align users, liquidity providers, developers, and tokenholders.

For Uniswap, the Optimism proposal could become a small but meaningful test of whether deployment-level fee routing can support UNI economics without disrupting the protocol’s broader market position.

This article is based on the Uniswap governance proposal for Optimism pool fee routing.

This article was written by the News Desk and edited by Samuel Rae.

This report is based on information released in disclosures at primary source documentation.

New Markdown rival: Open-source DGML format aims to turn docs into data that AI (and humans) can trust

22 July 2026 at 11:15
L-R: Mantra CEO John Patrick Mullin, Docugami CEO Jean Paoli, and Inveniam CEO Patrick O’Meara. The companies are partnering to make DGML a standard for AI, with Docugami turning documents into data, Inveniam verifying it on a blockchain, and Mantra providing the chain.

Jean Paoli has spent his career making documents readable by machines — first as a co-creator of XML, then helping build the file formats behind Microsoft Office. Now his Kirkland, Wash.-based startup, Docugami, is open-sourcing the technology at the heart of its business, betting it can become a standard way to turn documents into data that people and AI agents can trust. 

The company is releasing its technology, called DGML (short for Document Graph Markup Language), under Apache 2.0, a widely used open-source license, so other developers and companies can adopt it.

The idea is to turn it into a shared standard that no single company owns, much as XML became a common foundation across the tech industry. 

The move reflects a shift in where the value is created in AI. Docugami until now has made its money selling software that turns unstructured documents into usable data. It’s betting now that there’s more value in proving that data is trustworthy instead. 

How it works: Docugami is teaming up with Inveniam, a Detroit company whose software helps big investors keep tabs on the mountains of paperwork behind real estate and other hard-to-value assets. Inveniam will record a kind of digital fingerprint of each piece of DGML data on NVNM Chain, its blockchain built with Mantra, a crypto firm that Inveniam is acquiring.

That means, for example, that a single fact buried in a 200-page lease — such as the rental rate, a renewal option, or a default clause — can be verified on its own, without exposing the whole document. An investor, auditor, or AI agent can trace it to the page it came from. 

To work with documents, AI systems usually convert them into a simpler format first. DGML enters a growing field of contenders in that regard, competing with the popular Markdown format and DocLang, a new open standard for AI-ready documents backed by IBM, Nvidia and Red Hat.

The business model: This is a big move for a company of Docugami’s size, taking the 30-person startup in a new direction. Paoli is handing the industry the technology his team spent years building, and pinning the company’s future on a larger idea.

The plan is to make money not from the format itself but from the value of the trusted data. Once a company converts its leases or loans into DGML and anchors the key numbers on the blockchain, investors, lenders and auditors can pay to draw on that verified data.

Docugami will share in the revenue through its partnership with Inveniam. The company also stands to collect a small fee each time a piece of data is recorded on the chain. 

The company is giving away the DGML format and a working version of the software, but not everything. Paoli said the company is keeping some of its own technology private, including AI models it has fine-tuned to read documents, and could sell those or other tools to enterprises. 

“The business model of everybody is changing. And if you know any company where it’s not true, you need to tell me, because I haven’t met them yet,” Paoli said in an interview. 

Docugami has raised about $13 million to date, including a $10 million seed round in 2020 that drew the first investment in Grammarly’s history.

The partnership: Paoli met Patrick O’Meara, Inveniam’s CEO, a few months ago, through a former Microsoft colleague who had become one of O’Meara’s advisers. They quickly realized they had been working toward the same idea from different directions.

Inveniam, founded in 2017, helps big investors keep track of assets that are hard to value, like office towers, private loans and infrastructure. It monitors the documents behind those assets and flags changes as they happen, and its clients include some of the world’s largest sovereign wealth funds, according to O’Meara.

What it lacked was a consistent way to break those documents into verifiable pieces. That is what Docugami provides.

“We’re not putting the data itself on-chain, just a fingerprint of the document. Change one bit, one byte, one pixel, and the hash won’t match,” O’Meara said.

The blockchain comes from Mantra, a crypto company run by John Patrick Mullin. Inveniam invested $20 million in Mantra last year and has since agreed to acquire it outright. Mantra’s OM token collapsed in April 2025, erasing several billion dollars in value. 

Paoli said the project uses the underlying blockchain, not the token.

“Crypto as an industry has gone through a lot of changes in the last 18 to 24 months, and it’s growing up in a lot of ways. This is a real use case with fundamental value, not just pure speculation,” Mantra’s Mullin said in an interview. 

The result is a division of labor: Docugami turns documents into data, Inveniam verifies it and brings the customers, and Mantra provides the chain where the proof is recorded.

The DGML specification, sample documents and reference code are at dgml.io and on GitHub

Editor’s note: This story was updated after publication to correct the name of a competing document format, DocLang, and to note that Inveniam’s blockchain is called NVNM Chain.

Unlimited AI tokens aren't unlimited after all as US Army burns through supply

By: WIRED
22 July 2026 at 09:35

A little over a month after the Department of Defense (DOD) bragged that nearly half of its 3.5 million employees were using AI at work, members of the Army’s Combat Capabilities Development Command (DEVCOM) received an email informing them that they were burning through tokens, and needed to limit use.

“Although the Army CIO announced in May 2026 that they were offering unlimited tokens, by mid-June the Army CIO pool was exhausted of tokens and had to re-establish limits,” the email reads. The email goes on to say that although the Army has chosen to renew token usage at “its current levels,” it’s unclear “if the Army CIO pool will be renewed after 1 Oct.”

The Army uses Ask Sage, a multimodal generative AI platform where users can run different large language models (LLMs), including Alphabet’s Gemini, Meta’s Llama, and OpenAI’s ChatGPT. “Apparently the whole Army burned through the whole year of tokens for just one service,” says an Army employee who spoke to WIRED anonymously because they were not authorized to speak to the press.

Read full article

Comments

© Carmen Martínez Torrón/Getty

Pentesting: A Look at ATM Security

22 July 2026 at 09:05

Welcome back, aspiring cyberwarriors!

Part of our work involves supporting red team engagements. We review completed tests, size up the risk tied to each vulnerability and build out recommendations for shoring up the infrastructure. This time around, we wanted to pull back the curtain on something special. It’s ATM security. 

This article is written to help with security assessments on ATMs, showing possible vulnerabilities you may find. It covers many things, from running malware bought off a forum, to an insider on the bank’s payroll, to a service technician who understands the machine’s internals and has been handed broad access to the equipment. We also look at whether a hacker could get into the bank’s broader network simply because the perimeter wasn’t locked down well enough.

Nothing here is meant as a tutorial. We’re documenting weaknesses hackers could exploit so that defenders know what to fix, not handing anyone a blueprint. We take no responsibility for how this information is used.

With that out of the way, let’s start with where ATMs came from.

The History of ATMs

London got the world’s first working ATM on June 27, 1967. It was primitive by today’s standards, incapable of checking a balance, which is exactly why withdrawals topped out at 10 pounds, and it dispensed cash only against special vouchers rather than reading a card. 

first atm from barclays
Source: Barclays Bank

Nearly six decades later, ATMs look nothing like those early cash dispensers. Now they are multifunctional devices, but the hackers never stopped circling. Part of the appeal is obvious. An ATM sits on a pile of cash and offers quick access to it, and there are simply too many machines scattered across too many places to guard them all closely. A lot of them sit in isolated, low traffic spots that run unattended around the clock, think gas stations. That has shaped decades of security investment, most of it aimed at physical hardening. Today’s units can weigh over half a ton and come loaded with sensors tracking position, internal temperature, and whether a compartment has been pried open.

Here’s the catch, though. The safe holding the cash is genuinely hard to crack, but the compartment housing the control electronics is a different story, and in our assessment, it remains poorly defended. That gap opens the door to logical attacks, ones that skip the crowbar entirely and go after the software instead, and that category has been gaining ground fast.

cisco talos atm malware samples

Cisco Talos has tracked a steady climb in new ATM malware variants since 2009. The raw sample count still looks small next to other malware families, but don’t let that fool you. Europe alone saw logical attacks on ATMs jump 269% in 2020 versus the year prior, and the average payout per incident ballooned nearly a thousandfold across that same window, climbing from roughly a thousand euros to well over a million.

What changed the game was availability. ATM malware used to be a rare, closely guarded tool. Once it started circulating more freely on underground markets, prices fell and so did the skill required to use it. Cutlet Maker, which surfaced in 2017, is a good illustration. It came bundled with a Russian language manual complete with troubleshooting notes for running it against different ATM models.

atm manuals
Screenshot of the troubleshooting guide for Cutlet Maker. The author describes the ATM’s USB port location, along with advice on how to devise a stick for attaching the USB cable and accessing the internal USB port. Source: TrendMicro

Fast forward to 2024, and vendors on those same markets were offering ATM malware through subscription pricing, monthly plans included.

dark web informer

Logical attacks have always had one real weakness. They take skill and patience to pull off. That’s why cheap, well documented malware kits have had such an outsized impact on the trend. Their upside for hackers is just as real. They’re far quieter than smashing a machine open, and they often let the same person come back to a compromised ATM again and again. Manufacturers have started fighting back on the hardware side too, with tamper protected cassettes that flood the cash inside with indelible ink the moment someone tries to force them open, ruining the bills instantly.

Brief Attack Statistics

The numbers tell their own story. ATM related crime climbed 600% between 2019 and 2022, with 165% of that increase packed into 2021 and 2022 alone. Physical break ins, which have always driven the bulk of ATM crime, contributed alongside the rise in logical attacks. Germany had 496 ATM explosions recorded in 2022, a record for the country. Zoom out globally, and incidents of that kind blew past 18,000 in 2023.

Losses have kept pace. Banks worldwide absorbed $2.4 billion in direct losses from ATM fraud by the close of 2023. Europe’s share came to 173 million euros, with 67 million of that tied specifically to skimming. The United States handles just 25.29% of global transaction volume yet accounts for 42.32% of global losses. Skimming remains a big part of why, showing up in 45% of all ATM fraud cases in 2023 and costing North America over $900 million, with more than 315,000 cards compromised across at least 3,000 financial institutions.

None of this is happening in a vacuum. The market for ATM protection has grown right alongside the threat. Still, priorities inside most banks remain lopsided. Physical security tends to get the lion’s share of attention, while the operating system, drivers, and control software logic running underneath often get treated as an afterthought. That imbalance carries real consequences. A 2022 RTM Group study found that hackers could breach an ATM’s housing without setting off an alarm in one out of every two attempts, giving them free rein to tamper with the equipment inside.

How an ATM Is Built

Making sense of how these attacks work starts with understanding what happens inside the machine during an ordinary transaction. We’ll walk through that process using one representative configuration, illustrated in the diagram below.

how an atm is built

The diagram reflects one specific setup we’re using for illustration, not a universal default, since real world configurations vary by device.

1. User Layer

From where the customer stands, using an ATM is simple. They need to present a card and pick a transaction. That wasn’t always the whole story. Inserting a physical card into a reader used to be the only entry point, and that reliance on the magnetic stripe made skimming and shimming, techniques aimed at stealing card data to produce counterfeit copies, a persistent problem for years.

Contactless cards changed the entry point itself. NFC readers now sit alongside traditional card slots on most machines. 

A PIN code layers on additional protection against someone using a stolen card. Entry happens through an encrypting PIN pad, a combination of physical keypad and cryptographic module that ensures the PIN never travels or gets stored anywhere in plain text. Verification of the resulting encrypted PIN block happens back at the processing center. 

Once identity checks clear, you can withdraw cash, check your balance, transfer funds, and so forth. There’s a full computer running inside the housing, but customers never get anywhere near it directly. Every interaction they have flows through a single banking application running in kiosk mode, locked to full screen.

2. OS Layer

That computer we just mentioned lives inside what’s called the service zone, and this section covers what happens there, setting the cash handling hardware aside for the moment. Physically, the service zone is protected by a thin door and a basic lock. Machines from the same product line frequently share an identical key too, one that’s often available for purchase online with minimal effort.

Beyond the system unit itself, the service zone also houses the ATM’s networking equipment and its wired connections to the card reader, contactless reader, PIN pad, and dispenser, typically running over USB, Ethernet, PCI, or COM interfaces depending on the device.

Windows powers most of these systems, historically through Windows Embedded and increasingly through Windows IoT, a Windows 10 variant built for embedded use.

atm

The kiosk application isn’t the only thing running on that OS. Alongside it sits the ATM’s control software plus a handful of security tools. That can be antivirus protection, Windows AppLocker that keeps unauthorized programs from executing, and a VPN client that maintains a secure tunnel back to the bank’s internal network.

Control software is arguably the most important piece at this layer. Core responsibilities for the control software boil down to managing peripherals and communicating with the processing center, though specific implementations often add more on top of that. Some bundle in software for a monitoring server, letting technicians manage an entire network of self service machines remotely. Others are built in a supervisor mode meant purely for technical staff, offering quick access to diagnostic tools through a hidden menu to simplify physical maintenance visits.

3. Network Layer

Selecting a transaction sets off a verification process handled entirely by the processing center, a server living on the bank’s internal network. That server confirms the card data is legitimate, checks the PIN again before letting the transaction through, rules out any restrictions on the account, and verifies there’s enough balance to cover the request.

Everything exchanged between the ATM and the processing center travels encrypted, usually through a VPN tunnel, protecting against interception or tampering along the way. NDC and DDC are the most common messaging protocols in this exchange, functioning as something of an informal industry standard even before multi-vendor control software became widespread. ISO 8583 and its various offshoots see heavy use as well. 

The processing center isn’t the only thing an ATM talks to. Many machines also maintain a connection to a monitoring server used for remote management, health checks, and pushing updates, and unlike the processing center link, this channel frequently runs without any encryption at all.

4. Firmware Layer

Once the processing center signs off, the control software hands things over to the dispenser for a withdrawal, or the deposit module if cash is going in. These components typically sit inside the most fortified section of the ATM, the safe zone, built from tougher materials and secured with its own dedicated key separate from the service zone. 

inside the atm

The dispenser counts out the required banknotes from the ATM’s cassettes, moves them into position at the dispensing tray, then opens the shutter, the physical flap that blocks access to the cash until it’s ready. Data moving between the control software and the dispenser can be encrypted, and both sides authenticate one another before any exchange begins, a safeguard against device spoofing. All of that encryption and authentication logic lives directly in the dispenser’s own firmware. 

Deposits work differently. Incoming banknotes pass through a validator that checks their authenticity.

ATM Attacks

With the mechanics of an ATM covered, we can turn to the threats themselves. Every attack against these machines falls into one of two broad camps, physical or logical, depending on what the hacker is going after and how they approach it.

Physical attacks go straight after the machine or its components, aiming to extract cash or knock the device out of normal operation without touching a line of code. These predate targeted malware by decades and don’t require much specialized skill. Some don’t even target the machine itself, focusing instead on the people standing in front of it.

physical attacks on atms

Logical attacks operate on a different level entirely. They demand genuine technical skill and preparation, built around exploiting weaknesses in the ATM’s software and network layers. They draw less public attention than physical attacks despite posing a bigger threat to banks, largely because they’re quieter and let a hacker return to the same compromised machine to cash in more than once.

System attacks go after functionality or logic running at the ATM’s OS layer, typically aiming to extract cash or sidestep security controls outright. Black box attacks deserve special attention, where a hacker skips gaining OS access altogether and instead wires their own device directly into the dispenser to control it externally. The same technique can target other peripherals, like the banknote validator.

system attacks on atms

Network attacks aim at the ATM’s networking components instead, with hackers looking to intercept, forge, or otherwise abuse data in transit, or to seize remote control of the machine. With weak enough safeguards in place, a hacker can forge the responses coming back to the ATM and push through a cash withdrawal even after the processing center rejected it.

network attacks on atms

Not every attack in this framework ends with cash in hand. A hacker might, say, work to gain remote network access first, then pivot into an OS layer attack from there. 

We have seen cases where compromising a single ATM meant compromising the entire bank because there was no network segmentation in place. Conversely, gaining access to the bank’s internal network could provide a path to ATMs and other critical systems connected to it. Credential reuse and a lack of understanding of Active Directory security can lead to devastating consequences in environments like these.

Summary

ATMs have evolved from simple cash dispensers into complex and networked systems. Their security has evolved unevenly alongside them. Physical hardening has made the cash safe itself genuinely difficult to crack, but the service zone housing the control electronics remains comparatively exposed, and that gap has fueled a steady rise in logical attacks. These attacks demand more skill than a physical break-in, but they’re increasingly accessible because of well-documented malware kits.

Cybersecurity is a vast field, and we offer courses covering a wide range of topics, including Active Directory Hacking, Wi-Fi Hacking, Web Application Hacking, SCADA Security, and much more. Our course library is constantly growing as we continue to add new training, all of which is available through our Member Gold plan. If you want unlimited access to our entire training library, including our most advanced courses, consider upgrading to Subscriber Pro.

The post Pentesting: A Look at ATM Security first appeared on Hackers Arise.

U.S. Army bets $447 million on giant surveillance aerostats

22 July 2026 at 09:29
Persistent Surveillance System-Tethered (PSS-T) aerostatTCOM LP, based in Columbia, Maryland, was awarded a $447 million contract by U.S. Army Contracting Command at Aberdeen Proving Ground, Maryland, to handle production, fielding, sustainment and lifecycle support for the Persistent Surveillance Systems-Tethered family of systems, an aerostat-based surveillance program the Army has relied on for more than a decade. The contract itself […]
❌
❌