Bitcoin Depot disclosed that attackers breached parts of its corporate IT environment and stole 50.903 BTC—worth about $3.665 million—from company-controlled wallets after obtaining credentials tied to digital asset settlement accounts. The company said it detected suspicious activity on March 23, activated incident response procedures, brought in external cybersecurity experts, and notified law enforcement after the unauthorized transfers had already occurred.
The company reported that the intrusion was contained to its corporate systems and did not affect customer platforms, customer data, or other environments. Bitcoin Depot later determined the incident was material because of potential reputational, legal, regulatory, and response-related impacts, adding to broader scrutiny of security in the crypto ATM sector following earlier breaches involving Bitcoin Depot and rival operator Byte Federal.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Bitcoin Depot determined that the incident was material because of potential reputational, legal, regulatory, and response-related consequences. This assessment was disclosed in the company's SEC filing.
After identifying the incident, Bitcoin Depot activated its incident response procedures, brought in external cybersecurity experts, and notified law enforcement. The company also blocked the attackers' access after the credential compromise was identified.
On detecting suspicious activity, Bitcoin Depot discovered attackers had breached certain corporate IT systems, obtained credentials for digital asset settlement accounts, and transferred about 50.903 BTC worth roughly $3.665 million from company-controlled wallets. The company said the incident was limited to its corporate environment and did not affect customer platforms, systems, or data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.