WeAreDevelopers LIVE • Apr 27, 2023

Reverse Vending Machine (RVM) Security: Real World Exploits / Vulnerabilities

Jovan Zivanovic

Cryptographic failures in reverse vending machines allow attackers to forge receipts and print endless store credit. Discover the structural flaws leaving automated retail infrastructure exposed to massive financial manipulation.

Pause
Mute Enter Fullscreen
#1 about 3 min

Motivation for exploring reverse vending machine vulnerabilities

Exploiting financial incentives in expanding recycling infrastructure exposes critical flaws in public-facing automated store systems.

#2 about 2 min

Standard processes formatting automated reverse vending machine operations

Automating the bottle deposit cycle relies heavily on printed paper receipts that translate physical inputs into unverified monetary checkout value.

#3 about 4 min

Sensor technologies guiding exact bottle acceptance and classification

Accurately distinguishing valid containers from fraudulent items requires multi-layered hardware configurations including infrared spectroscopy and strict weight calibration.

#4 about 4 min

Common attack vectors compromising digital recycling hardware infrastructure

Malicious actors bypass hardware logic via targeted insider circumvention and fake barcode placement to trick classification endpoints for unauthorized payouts.

#5 about 8 min

Identifying critical unencrypted structural weaknesses in printed receipts

Systematically analyzing standard ean-13 barcodes on printed vouchers exposes predictable static strings mapping directly to specific monetary refund totals.

#6 about 2 min

Exploiting static voucher barcodes for unlimited refund duplication

Synthesizing unauthorized barcode printouts with simple thermal hardware successfully circumvents unpatched point-of-sale checkout restrictions to clone cash balances.

#7 about 3 min

Addressing manufacturer responses and friction with secure deployments

Despite clear physical vulnerability evidence, dominant retail chains frequently reject vendor-provided secure system upgrades in order to minimize operational deployment costs.

#8 about 3 min

Replicating manipulative barcode exploits across international recycling markets

Overwriting identical bottle silhouettes with specialized high-value import barcode stickers reliably deceives optical scanners into registering fraudulently doubled financial returns.

#9 about 3 min

Integrating cloud databases for dynamic receipt validation workflows

Preventing cloned barcode transactions fully requires isolated backend ledgers that continuously sync, validate, and permanently expire unique receipt identifiers upon usage.

#10 about 10 min

Community questions spanning system security and structural evolutions

Addressing pervasive public hardware threats ultimately necessitates transitioning entirely away from printable legacy validation tokens toward comprehensive backend security methodologies.

Matching moments

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

2:55 min

Identifying common and emerging application injection attack vectors

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:48 min

Practical limitations of theoretical double spend validation attacks

Jad Wahab · LIVE

5:19 min

Navigating practical security trade-offs for merchant transactions

Jad Wahab · LIVE

2:41 min

Setting the stage for software security demos

Vandana Verma Sehgal · LIVE

4:30 min

Introduction and the receipt extraction problem

Nazeer Saeed Nazeer Saeed · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois