A new report from a security researcher has revealed nine vulnerabilities in an enterprise security program, but its potential impact on physical ATM cash security is stirring debate. While the bugs themselves are undisputed, their significance — particularly for major ATM manufacturer Diebold Nixdorf — is contentious.
What Happened
Matt Burch, a principal security researcher for Atredis Partners, is set to present his findings at Black Hat USA 2026. He uncovered nine new vulnerabilities in CryptWare CryptoPro Secure Disk, a solution commonly referred to as CryptoPro. This software offers full-disk encryption (FDE) and pre-boot authentication for Windows systems, surprisingly marketed to both general corporations and specifically to ATM manufacturers.
While the existence of the vulnerabilities is not in question, their practical implications are. Burch asserts that CryptoPro is a "foundational" component of a security suite utilized by Diebold, suggesting a direct path for attackers to potentially steal cash from ATMs. Diebold Nixdorf, however, counters this claim, stating that CryptoPro is not foundational to their ATM security. This disagreement means Burch's discovery is either a critical flaw with the potential for widespread ATM jackpotting, or it represents significant issues in a widely used enterprise security tool with less direct ATM cash theft implications.
To understand the context, ATMs have historically presented a unique security challenge. The bottom portion, where cash is stored, is heavily reinforced. However, the top portion, housing the PC components and critical software, is often constructed with lighter-grade steel or even plastic. Burch highlights that manufacturers don't always consider this "head unit" a significant security risk. Physical access to internal cables can bypass some locking mechanisms, making it possible to access the computer components.
Internally, ATMs run a stack of software on Windows, including banking configurations that enable fund dispensation. A key component is the eXtensions for Financial Services (XFS) dynamic link library (DLL), which facilitates communication between the ATM and banks, and controls cash dispensing. Attackers have exploited this by physically gaining access to the ATM's top unit, wiring in malware, and targeting XFS. The most infamous example is the Ploutus malware, which facilitates "jackpotting" attacks – forcing ATMs to dispense all their cash. Such attacks have been on the rise, with over 700 reported to the FBI in 2025 alone, resulting in more than $20 million in stolen funds.
All ATM manufacturer
Why It Matters
For developers, IT security professionals, and enterprises, these findings are significant on several fronts. First, regardless of the direct ATM cash theft debate, nine vulnerabilities in a full-disk encryption and pre-boot authentication solution are inherently serious. FDE and pre-boot authentication are critical layers for securing endpoints, especially in environments where physical access to devices might be possible. Flaws here could allow attackers to bypass crucial controls, potentially gaining access to sensitive data or altering system behavior before the operating system even loads.
If Matt Burch's assessment is accurate, and CryptoPro is indeed foundational to Diebold Nixdorf's ATM security, then these vulnerabilities represent a substantial supply chain risk. Enterprises rely on third-party software components, and a critical flaw in one could compromise the entire system, even if direct integration isn't immediately obvious. This situation highlights the need for rigorous vetting of all components in a security stack, particularly those handling encryption and authentication.
The broader context of ATM jackpotting further amplifies the concern. With over $20 million stolen in 2025 from such attacks, any potential new vector is a major red flag for financial institutions and their security teams. Even if the vulnerabilities don't directly lead to jackpotting, they could be part of a larger chain of exploits that facilitate it.
What To Watch
The immediate focus will be on Matt Burch's presentation at Black Hat USA 2026, where he is expected to detail the nine vulnerabilities. His presentation will likely provide more technical specifics on the flaws and how they could potentially be exploited. Following this, watch for responses or official statements from CryptWare, the developer of CryptoPro Secure Disk, and Diebold Nixdorf. We will need to see if patches are issued, or if Diebold provides further clarification on CryptoPro's role within their ATM security architecture.
This incident also serves as a reminder for all organizations about the importance of supply chain security and the often-overlooked physical security of computing components, even in seemingly hardened systems like ATMs. The ongoing discussion will undoubtedly influence how manufacturers design and secure future generations of self-service terminals.