Bitcoin Depot, one of the largest Bitcoin ATM, has confirmed a serious data breach, which resulted in the disclosure of sensitive personal information nearly 27,000 customers.

The company, which operates more than 8,800 Bitcoin ATMs in the US, Canada and Australia, sent an official notification to affected individuals, revealing that the incident took place on June 23, 2023, but the public notification was delayed for a full year at the request of federal law enforcement authorities.
“Unfortunately, we were unable to notify you earlier due to the ongoing investigation. Federal law enforcement authorities have asked Bitcoin Depot to wait to notify you until they have completed their investigation,” the company said, noting that the disclosure had to be postponed until the criminal investigation was completed in July 2024.
See also: Charges against two men for the “OmegaPro” crypto scam
Bitcoin Depot data breach: What kind of data was exposed
The breach resulted in the interception of a combination of personally identifiable information (PII), including:
- Full name
- Phone number
- Driving license number
- Residential address
- Date of birth
This data is similar to that typically collected during Know-Your-Customer verification procedures . Crypto services in the US are required to comply with these verification procedures, according to current FinCEN regulations.
The collection of such data is necessary to identify users and prevent criminal activities, such as money laundering or terrorist financing.
See also: Exposed JDWP interfaces lead to crypto mining and DDoS
Where are customers – and what should they do?
Bitcoin Depot, unlike other companies that offer free identity monitoring after similar incidents, did not provide such services (because the incident involved a crypto service). Instead, it advised customers to:
- To closely monitor their banking transactions
- Consider freezing their credit report (credit freeze)
- Be on high alert for possible fraud attempts
Industry under pressure – it's not the first incident
The Bitcoin Depot data breach is not an isolated incident. In December 2024, Byte Federal, another Bitcoin ATM provider in the US, revealed that 58,000 customer data was exposed. In that case, the breach was caused by hackers exploiting a vulnerability GitLab to gain access to a server that hosted sensitive customer information.

The recurring nature of such incidents demonstrates structural weaknesses in the crypto ATM industry, where rapid expansion and decentralized operation often precede cybersecurity.
See also: Malicious extensions in the Firefox store steal crypto
What does this mean for the future of crypto ATMs?
The cryptocurrency ATM market has seen explosive growth in recent years, but breaches like the Bitcoin Depot one raise critical questions:
- How adequate is the security in systems that handle personal and financial data?
- Is there a need for stricter oversight from regulators like FinCEN?
- Will users continue to trust such platforms?
The need for transparent breach management policies, timely notification of victims , and mandatory identity protection now seems more urgent than ever.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
