Monday, 24 February 2025
25.5 C
Singapore
28.3 C
Thailand
19.8 C
Indonesia
25.6 C
Philippines

Hackers bypass Ticketmaster’s barcode system to enable resales on other platforms

Hackers have found a way to bypass Ticketmaster's "nontransferable" tickets, allowing resales on other platforms despite security measures.

Scalpers have discovered a way to bypass the “nontransferable” digital tickets from Ticketmaster and AXS, allowing these tickets to be resold on other platforms. This revelation came from a lawsuit filed by AXS in May against third-party brokers using this method. 404 Media first reported the news.

The beginning of the saga

In February, an anonymous security researcher, Conduition, published technical details on how Ticketmaster generates its electronic tickets. If you’re unaware, Ticketmaster and AXS restrict ticket resales within their platforms, preventing transfers to third-party services like SeatGeek and StubHub. They even stop transfers to other accounts on the same platform for high-demand events.

While the companies claim this is a security measure, they control the resale process entirely. Ticketmaster and AXS create their “nontransferable” tickets with rotating barcodes that change every few seconds, preventing screenshots or printouts from working. This technology is similar to two-factor authentication apps. The barcodes are generated shortly before the event starts, limiting the time they can be shared outside of the apps. This setup locks buyers into the platforms’ resale services, giving Ticketmaster and AXS control over ticketing.

The hackers’ workaround

Hackers have now found a way to bypass this system. Using Conduition’s published findings, they extracted the secret tokens that generate new tickets. They achieved this by using an Android phone with its Chrome browser connected to Chrome DevTools on a desktop PC. They created a parallel ticketing system with these tokens that generates genuine barcodes on other platforms. This allows them to sell working tickets on platforms not approved by Ticketmaster and AXS. Reports indicate that these parallel tickets often work at the event gates.

404 Media reports that AXS’ lawsuit accuses the defendants of selling “counterfeit” tickets, even though they usually work, to “unsuspecting customers.” The lawsuit describes the parallel tickets as being created by mimicking or copying tickets from the AXS platform.

AXS claims it doesn’t know how the hackers are managing this. The possibility of effectively jailbreaking Ticketmaster has proven so lucrative that several brokers have tried to hire Conduition to build ticket-generating systems. Some services already using the researcher’s findings include Secure. Tickets, Amosa App, Virtual Barcode Distribution, and Verified-Ticket.com.

The bigger picture

404 Media’s report provides a detailed look into the technical aspects of what Ticketmaster and AXS are doing to keep their ecosystems under control. Conduition’s findings reveal these companies’ measures to prevent ticket transfers and maintain their monopoly over the resale market.

This situation highlights the ongoing battle between consumers looking for flexibility and companies aiming to retain control over their products. As hackers continue to find ways around these restrictions, it remains to be seen how Ticketmaster and AXS will respond to protect their systems and maintain their business models.

Hot this week

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

Android Auto bug is causing wireless connectivity issues

Android Auto users face wireless connectivity issues, with phones rebooting or failing to connect after recent updates. Google is investigating.

Baidu embraces DeepSeek AI to enhance search experience

Baidu integrates DeepSeek AI into its search engine, following Tencent’s move with Weixin. China’s AI race heats up as DeepSeek gains popularity.

Nvidia introduces priority access for RTX 5080 and 5090 Founders Edition GPUs

Nvidia introduces Verified Priority Access for RTX 5090 and 5080 FE GPUs, letting gamers apply for an invite to buy one card per person.

Google expands in-car apps, turning vehicles into mobile entertainment hubs

Google is expanding its in-car apps, bringing more streaming and gaming options to vehicles with built-in Google services, starting with Volvo and Polestar.

Did xAI mislead the public about Grok 3’s benchmarks?

xAI is under scrutiny for allegedly misleading AI benchmark results, with OpenAI employees questioning its claims about Grok 3’s performance.

BT and Equinix expand partnership to enhance global interconnectivity

BT and Equinix expand their partnership to boost interconnectivity for multinational businesses, deploying BT’s Global Fabric NaaS in 40+ Equinix data centres worldwide.

LG unveils new SKS branding for luxury kitchen suite at KBIS 2025

LG rebrands Signature Kitchen Suite to SKS at KBIS 2025, introducing new luxury appliances like a free-zone induction range and an advanced island system.

LG unveils advanced laundry solutions at KBIS 2025

LG unveils its latest heat pump washer and dryer lineup at KBIS 2025, featuring AI-driven efficiency, ventless design, and smart connectivity.

Related Articles