Hackers use Ticketmaster's barcode technology to reverse engineer it in order to enable resale on other websites.
Using the discoveries of a security researcher, scalpers have discovered a method to get around the “nontransferable” digital tickets from Ticketmaster and AXS. According to 404 Media, AXS sued third-party brokers that used this technique in May, highlighting this development.
The story began in February when an anonymous security researcher, using the pseudonym Conduition, published technical details about Ticketmaster’s electronic ticket generation process. Modern e-ticketing systems by Ticketmaster and AXS lock ticket resales within their platforms, preventing transfers to third-party services like SeatGeek and StubHub. For high-demand events, these companies sometimes prohibit transfers even within their own platform accounts.

While Ticketmaster and AXS claim that these measures are for security, they also allow the companies to control the ticket resale market. The tickets are designed to be “nontransferable” using rotating barcodes that change every few seconds, similar to the technology used in two-factor authentication apps. These barcodes are only generated shortly before an event, limiting the window for sharing them outside the official apps. This setup locks buyers into the platforms’ own resale services, maintaining their control over the entire ecosystem.

Enter the hackers. Utilizing Conduition’s published findings, they extracted the platforms’ secret tokens needed to generate new tickets. This was done by using an Android phone with its Chrome browser connected to Chrome DevTools on a desktop PC. With these tokens, they created a parallel ticketing infrastructure capable of regenerating genuine barcodes on unauthorized platforms, enabling the sale of working tickets on platforms that Ticketmaster and AXS do not permit. Reports indicate that these parallel tickets often successfully work at event gates.
AXS’ lawsuit against the defendants accuses them of selling “counterfeit” tickets, even though these tickets usually work. The court documents describe these tickets as being “created, in whole or in part, by one or more of the Defendants illicitly accessing and then mimicking, emulating, or copying tickets from the AXS Platform.” Interestingly, AXS claims it doesn’t fully understand how the hackers are achieving this.
The opportunity to essentially jailbreak Ticketmaster’s system is so enticing that several brokers have reportedly tried to hire Conduition to develop their own parallel ticket-generating platforms. Existing services operating on the researcher’s findings include names like Secure.Tickets, Amosa App, Virtual Barcode Distribution, and Verified-Ticket.com.

The story detailed by 404 Media is a revealing look at the underlying technologies used by major ticketing platforms to maintain their control. It also highlights the ongoing battle between these companies and those who seek to circumvent their restrictions.
The researcher’s findings demonstrated how Ticketmaster generates its electronic tickets, focusing on the use of rotating barcodes. These barcodes change every few seconds, preventing static screenshots or printouts from being used. The codes are also generated just before an event begins, further limiting the ability to share tickets outside the apps. This technology effectively locks users into the platforms’ ecosystems, controlling how and when tickets are resold.
The lawsuit filed by AXS against the third-party brokers underscores the seriousness of the issue. The company claims that the defendants are selling counterfeit tickets, which, despite being unauthorized, often work at events. This has created a significant challenge for AXS, which maintains that it does not fully understand the methods used by the hackers.
The ability to bypass Ticketmaster and AXS’s security measures represents a lucrative opportunity for scalpers. As a result, several brokers have sought to hire Conduition to develop similar parallel ticket-generating platforms. The services operating on these findings have gained attention for their ability to produce working tickets that circumvent the official platforms’ restrictions.
A thorough examination of the legal and technological facets of this ongoing tale is given in the report by 404 Media. Technical information lovers should refer to Conduition’s previous research, which provides insights into the strategies AXS and Ticketmaster employ to keep control of their ticketing ecosystems.

Digital tickets systems are vulnerable, as evidenced by the discovery of this security issue and the subsequent acts of scalpers. AXS and Ticketmaster’s legal retaliation will probably continue to fuel the ongoing struggle for dominance in the ticket resale market, posing significant concerns over accessibility, security, and justice in the digital era.

If you like the article please follow on THE UBJ.