The cyberattack on Bitcoin Depot, which took place last month, resulted in the theft of approximately 50,903 Bitcoin, worth $3.6 million.

The incident, disclosed in a filing with the U.S. Securities and Exchange Commission (SEC), occurred on March 23, 2026, and involved compromised credentials associated with the company's digital asset settlement accounts.
Bitcoin Depot Inc. confirmed that attackers managed to gain access to certain parts of IT environment and execute unauthorized transfers from crypto wallets controlled by the company.
See also: Signature Healthcare: Cyberattack paralyzes hospital services
How the Cyberattack on Bitcoin Depot Evolved
According to the company’s Form 8-K, the cyberattack began when an unauthorized actor infiltrated its IT systems and gained control of credentials associated with digital asset settlement accounts. These credentials were used to transfer Bitcoin without authorization.
After detecting the breach, the company said it immediately activated incident response protocols. External cybersecurity experts were called in to investigate the intrusion, and law enforcement was notified.
The company noted that, based on the investigation so far, the incident appears to be limited to its corporate systems and did not affect customer-facing platforms or services.

Economic Impact
The unauthorized transfer involved 50,903 Bitcoins, which Bitcoin Depot valued at approximately $3.6 million at the time of the incident. This amount has been recorded as a preliminary estimate of the loss in the company’s depository.
See also: Uffizi Galleries: Cyberattack should worry every museum in Europe
Although the cyberattack on Bitcoin Depot has been classified as a significant incident due to potential reputational and legal and regulatory compliance, the company said it does not expect the breach to have a material impact on its overall financial condition or operating performance.
However, the ultimate financial impact may change as the investigation progresses. The company also said it maintains cybersecurity insurance, which may cover some of the losses, although there is no guarantee of full recovery.
No Indication of Customer Data Exposure
Bitcoin Depot stressed that there is currently no indication that customer data was compromised. The company said its platforms, systems, and customer environments remain unaffected.
This clarification is important, as the breach appears to have been limited to internal systems and not the broader infrastructure that handles customer transactions or personal data.

However, the company acknowledged that the investigation is ongoing and that the conclusions may change as more information becomes available.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: APT28 targets Ukraine with PRISMEX malware
As part of its response, Bitcoin Depot is working to strengthen its IT systems and implement additional security measures aimed at preventing similar incidents in the future. These efforts include reviewing access controls and strengthening security around credential management.
The company also said it would amend its SEC filing if details were required that were not fully available at the time of the original report.
Source: thecyberexpress.com
