440 / 691GB

GENERAL BYTES

Manufacturer of Bitcoin ATMs and CAS software

GENERAL BYTES supplies BATM terminals and CAS management software. The device manufacturer is not automatically the operator of a location or the counterparty to a customer's transaction.

GENERAL BYTES manufactures cryptocurrency ATMs and their management software in the Czech Republic. Assessment must separate terminal hardware, CAS server security, operator configuration and the terms of a particular exchange.

GENERAL BYTES' own timeline places its founding in Prague in 2013 and its first public ATM installation in 2014. A counter of machines sold is not a list of currently working locations or a count of independently verified customers. [GENERAL BYTES — Company timeline]

The GENERAL BYTES FAQ explicitly distinguishes manufacturing from operation: customers should take a specific transaction problem to that ATM's operator. The brand on the cabinet alone does not determine the rate, fee, payment recipient or refund responsibility. [GENERAL BYTES — Manufacturer and operator FAQ]

The FAQ distinguishes buying cryptocurrency with cash from two-way models that also dispense cash. BATM configurations differ; a feature supported by the product family does not prove it is enabled and available at a particular location. [GENERAL BYTES — Manufacturer and operator FAQ]

Crypto Application Server (CAS) manages BATM terminals and communicates with configured exchanges and hot wallets. The manufacturer says the terminal itself does not hold cryptocurrency. This does not mean there are no keys or risks on the server and connected services. [GENERAL BYTES — CAS architecture]

The batm_public repository offers a Java API, examples and testing tools for CAS extensions. Its public availability alone does not establish publication of all source code for the complete product. A custom extension also adds responsibility for its code and compatibility. [GENERAL BYTES — Public extensions repository]

The GENERAL BYTES notice for 17–18 March 2023 describes remote application execution through a server interface and access to the database and API keys for hot wallets and exchanges. Remediation included rebuilding compromised servers and replacing credentials, not just installing an update. [GENERAL BYTES — March 2023 incident report]

The 22 July 2026 report links another CAS incident to the Hessian library and terminal fingerprint checking. The manufacturer also reports compromise of its own infrastructure. This is a separate event; the 2023 fix does not prove this later vulnerability was resolved. [GENERAL BYTES — July 2026 incident and August update]

The August update to the 2026 report describes the Sentry compromise and potential exposure of CAS server addresses and images of unrecognized QR codes. According to the manufacturer these were addresses, not private keys. Alongside identity-verification features, this shows why a cash ATM is not automatically an anonymous service. [GENERAL BYTES — July 2026 incident and August update] [GENERAL BYTES — Manufacturer and operator FAQ]

For the clearest picture, read this entry together with Bitcoin, Custodial Exchange, Self-custody.

DOC · 001GENERAL BYTES — Company timelinePrimary ↗DOC · 002GENERAL BYTES — Manufacturer and operator FAQPrimary ↗DOC · 003GENERAL BYTES — CAS architecturePrimary ↗DOC · 004GENERAL BYTES — Public extensions repositoryDocumentation ↗DOC · 005GENERAL BYTES — March 2023 incident reportPrimary ↗DOC · 006GENERAL BYTES — July 2026 incident and August updatePrimary ↗
Source-first · No investment advice