CONTINUE TO SITE »
or wait 15 seconds

Security

ATM security expert raises alarm on CryptoPro security flaw

Photo: Adobe Stock

August 31, 2026

Security researcher Matt Burch recently raised an alarm on nine vulnerabilities with the CryptoPro Secure Disk pre-boot authentication software. This software is used on ATMs, and thieves could have used these flaws to bypass its integrity checks and circumvent encryption, according to a report by Wired.

He stated that these nine vulnerabilities were fixed in a series of patches in 2025, but this reveals a key issue of how unaddressed vulnerabilities can cause big issues in the supply chain, especially as CryptoPro is used in a variety of industries beyond just ATMs.

"ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that," Burch said during a presentation. "From the perspective of ATMs and the financial network, there are a lot of layers, and I think as a result of that, things just get implemented a certain way and then there's limited technical insight—bugs can get overlooked or they don't get addressed."

Michael Jacobsen, spokesperson for Diebold Nixdorf, said that only two of the vulnerabilities were relevant to its Vynamic Security Hard Disk Encryption, and that these issues were fixed in December 2025.

Burch said that part of the issue is that CryptoPro and other software companies hide or conceal when they release patches or updates. This obscurity model can make it difficult for companies to identify issues, especially in the age of AI, when criminal groups don't need to fully understand the software to break into it.

Included In This Story

Diebold Nixdorf

As a global technology leader and innovative services provider, Diebold Nixdorf delivers the solutions that enable financial institutions to improve efficiencies, protect assets and better serve consumers.

Request Info
Learn More




©2026 Connect Media, All rights reserved.
b'S1-NEW'