Cybercrime

$3.6 Million Stolen in Bitcoin Depot Hack

A hacker transferred more than 50 bitcoin from the Bitcoin ATM operator’s wallets after stealing credentials. 

Cryptocurrency heist

Bitcoin Depot (NASDAQ: BTM), the largest Bitcoin ATM operator in the United States, reported on Wednesday that millions of dollars worth of bitcoin were stolen by hackers from its wallets.

The company disclosed in an SEC filing that it detected an intrusion into its IT systems on March 23. 

The attacker obtained credentials for digital asset settlement accounts, enabling them to steal roughly 50.903 bitcoin (worth approximately $3.6 million) from Bitcoin Depot wallets.

“The Company further believes that the incident was contained to the Company’s corporate environment and did not affect the Company’s customer platforms, divisions, systems, data or environments,” Bitcoin Depot stated.

The company’s investigation into the full extent of the incident is ongoing. It says the attack has not had a material impact on operations, but it may incur reputational, legal, incident response, and regulatory costs. 

“The Company has recorded a preliminary estimate of loss of approximately $3.665 million, representing the fair value of the Bitcoin transferred without authorization as of the date of the incident. The ultimate impact may differ from this estimate as the investigation continues,” Bitcoin Depot said in the SEC filing

Advertisement. Scroll to continue reading.

“The Company maintains insurance coverage that may cover certain losses associated with cybersecurity incidents, but there can be no assurance that such coverage will be sufficient to recover any or all losses incurred as a result of this incident,” it added.

In July 2025, Bitcoin Depot notified more than 26,000 individuals of a data breach that had occurred a year earlier. Hackers who gained access to the company’s systems obtained files that stored personal information, including names, phone numbers, email addresses, dates of birth, physical addresses, and driver’s license numbers.

Bitcoin Depot said at the time that its disclosure was delayed by a year due to a law enforcement investigation.  

News of the latest Bitcoin Depot hack comes just days after threat actors believed to be operating out of North Korea stole $285 million from the DeFi platform Drift in a carefully planned attack.

Related: Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption

Related: US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator

Related: $29 Million Worth of Bitcoin Seized in Cryptomixer Takedown

Related Content

Malware & Threats

Masquerading as popular cryptocurrency wallets, the apps can hijack recovery phrases and private keys.

Cybercrime

The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.  

Cybercrime

Law enforcement in the US, UK and Canada identified more than $45 million in cryptocurrency and froze $12 million.

Mobile & Wireless

The security hole affected an EngageLab SDK and it was reported by Microsoft to the vendor one year ago.

Cybercrime

The attackers prepared infrastructure and multiple nonce-based transactions, took over an admin key, and drained five vaults.

Data Protection

Google researchers have shown that breaking the encryption of Bitcoin and Ethereum requires 20x fewer qubits. 

Application Security

The worm exposed Trust Wallet’s Developer GitHub secrets, allowing attackers to publish a backdoor extension and steal funds from 2,520 wallets.

Cybercrime

The exchange has been allegedly involved in laundering money for ransomware groups and other transnational cybercriminal organizations.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version