Bitcoin Depot: Bitcoin Depot, the crypto ATM giant, hit by $3.6M theft

Bitcoin Depot: Bitcoin Depot, the crypto ATM giant, hit by $3.6M theft

Bitcoin Depot Hit by $3.6M Crypto Heist in Sophisticated Cyberattack

Bitcoin Depot, a major operator of cryptocurrency ATMs and a publicly traded company on the New York Stock Exchange, confirmed a significant cyberattack resulting in the theft of 50.9 Bitcoins valued at approximately $3.6 million. The breach targeted the company’s digital accounts rather than its physical ATMs, with attackers gaining access to master wallet keys and draining funds within minutes.

The unauthorized transfer was detected on March 23, though blockchain investigator ZachXBT suggests the theft may have occurred earlier. He identified 19 suspicious wallet addresses linked to the incident as early as March 20, raising concerns that the total loss could exceed the reported amount potentially reaching 54 Bitcoins (nearly $3.9 million). The delay in detection has drawn scrutiny, with ZachXBT noting it took Bitcoin Depot three days to realize the funds were missing.

While no group has been officially attributed to the attack, the modus operandi aligns with tactics used by North Korean APT groups, particularly Lazarus, which has a history of targeting crypto platforms to fund regime activities. The incident follows a similar high-profile heist earlier this year, where hackers stole $286 million from the cryptocurrency exchange Drift Protocol.

The investigation remains ongoing, with authorities yet to confirm the perpetrators. The breach underscores the persistent vulnerabilities in digital asset management, even among publicly traded firms.

Source: https://www.escudodigital.com/en/cybersecurity/bitcoin-depot-crypto-atm-giant-hit-36m-theft.html

Bitcoin Depot cybersecurity rating report: https://www.rankiteo.com/company/bitcoin-depot

"id": "BIT1776076773",
"linkid": "bitcoin-depot",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cryptocurrency, Financial Services',
                        'location': 'United States',
                        'name': 'Bitcoin Depot',
                        'type': 'Publicly traded company'}],
 'attack_vector': 'Unauthorized access to master wallet keys',
 'date_detected': '2024-03-23',
 'description': 'Bitcoin Depot, a major operator of cryptocurrency ATMs and a '
                'publicly traded company on the New York Stock Exchange, '
                'confirmed a significant cyberattack resulting in the theft of '
                '50.9 Bitcoins valued at approximately $3.6 million. The '
                'breach targeted the company’s digital accounts rather than '
                'its physical ATMs, with attackers gaining access to master '
                'wallet keys and draining funds within minutes.',
 'impact': {'financial_loss': '$3.6 million (50.9 BTC)',
            'operational_impact': 'Funds drained within minutes',
            'systems_affected': 'Digital accounts, master wallet keys'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain (potentially to fund regime activities)',
 'post_incident_analysis': {'root_causes': 'Delay in detection (3 days), '
                                           'potential earlier breach (March '
                                           '20)'},
 'references': [{'source': 'ZachXBT (blockchain investigator)'}],
 'threat_actor': 'Lazarus (suspected)',
 'title': 'Bitcoin Depot Hit by $3.6M Crypto Heist in Sophisticated '
          'Cyberattack',
 'type': 'Cryptocurrency Theft'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.