Part III: Slot Machine Cheating · Electronic & Digital Cheating Methods
SCAM #26: Bluetooth/Wi-Fi Slot Machine Remote Access
How it works
Some modern slot machines and gaming peripherals include wireless connectivity for maintenance monitoring, player tracking, or remote management. Attackers can exploit these wireless interfaces to: (1) connect to unsecured Bluetooth management interfaces, (2) intercept wireless communications between machines and central servers, (3) use fake cellular base stations to hijack machines with cellular modems, (4) exploit weak or default Wi-Fi passwords on gaming networks. The IOActive DeckMate 2 research demonstrated that some devices with cellular modems could potentially be attacked without physical access — by planting a fake cellular base station nearby, tricking the device into connecting, and using that access to carry out the same exploits as the USB attack. Similar vulnerabilities could exist in slot machines with wireless connectivity if the wireless interface is not properly secured.
Where it appears
Slot machines or gaming devices with Bluetooth, Wi-Fi, or cellular connectivity; server-based gaming terminals; wireless player tracking systems; mobile gaming devices
On the record
The IOActive DeckMate 2 research (Black Hat 2023) demonstrated both USB and cellular attack vectors. The researchers noted that some devices rented with cellular monitoring capabilities could be attacked via fake base stations. While the research focused on card shufflers, the principles apply to any gaming device with wireless connectivity. As casinos adopt more IoT and wireless technologies, the attack surface continues to expand.
Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.