The sender requests a specific amount of money through the SmartCash web wallet, generates a QR code if the account is well funded, the sender sends the QR code to the payer, and the payer scans the QR code at a compatible ATM to withdraw the corresponding amount in EUROS (Portugal) or Swiss franc (Switzerland)

We know that regular ATMs are a popular target for cybercriminals. But so far, there has been much less discussion about Bitcoin ATM malware, probably because there are relatively few machines available worldwide. With the growing popularity of cryptocurrencies and the fact that cybercriminals will always try to take advantage of them to make money, mining malware has been common over the past year. So it's not surprising that we're thinking that bitcoin ATM malware is going to appear in the underground market. Unlike regular ATMs, Bitcoin ATMs do not have uniform verification or security standards. For example, Bitcoin ATMs do not need to use ATMs, credit or debit cards for transactions, but instead use mobile numbers and ID cards for user authentication. The user must then enter the wallet address or scan their QR code. Wallets used to store digital currency are not standardized and can be downloaded from the app store, so cybercriminals are sure to have an advantage. While searching through underground forums, we found a user offering Bitcoin ATM malware for sale.

Electrum is a popular software wallet that works by connecting to a dedicated server. These servers receive a hash of the Bitcoin address in the wallet and reply with transaction information. Electrum wallets are fast and have few resources, but by default, it connects to these servers and can easily monitor users. In addition to Electrum, some other software uses public Electrum servers. By 2019, it is a faster and better alternative to BIP37.

According to Reddit user u/normal_rc, electrum's wallet was hacked and nearly 250 bitcoins (243.6 BTCs, nearly $1 million) were maliciously stolen, according to coinelegraph. Electrum then confirmed that the attack included creating a fake version of the wallet to trick users into providing password information. Electrum responded on Twitter that "this is a persistent phishing attack on Electrum users" and warned users not to download Electrum from any source other than the official website.

In a forum post on Bitcointalk, website administrator Theymos explained: "If at any time in the past you've logged in to Electrum without a wallet password and opened a web page, your wallet might have been stolen." Particularly paranoid people may want to send all bitcoins (BTCs) from their old Electrum wallets to the newly generated Electrum wallet. "