Skip to content

Bitcoin Depot Hack: ATM Operator Took 3 Days to Detect $3.6 Million Theft

Hacker running with Bitcoin ATM. Bitcoin Depot Hack: ATM Operator Took 3 Days to Detect $3.6 Million Theft

The Bitcoin Depot hack was quietly disclosed in a Securities and Exchange Commission (SEC) Form 8-K filing on April 6, 2026, revealing that the largest U.S. Bitcoin ATM operator suffered a cybersecurity breach on March 23. As a result, a hacker was able to obtain the necessary credentials and access the firm’s digital asset settlement accounts in order to transfer approximately 50.903 BTC from company wallets. 

Bitcoin Depot Hack: ATM Operator Took 3 Days to Detect $3.6 Million Theft: The largest U.S. crypto ATM operator disclosed a March 23 breach after attackers stole 50.9 BTC using compromised credentials.
Bitcoin Depot Hack: Form 8-K filing. (Source: SEC)

How the Hack Unfolded

ZachXBT, the very well-known investigator focusing on blockchain transactions, traced the Bitcoin Depot hack to March 20, 2026, three days before the incident was first reported. There are 19 theft addresses known to ZachXBT with a high level of confidence. The total amount of Bitcoin stolen was 54.45 BTC, worth approximately USD 3.7 million, which exceeds the amount reported early on (50.903 BTC), by approximately USD 3.55 million in total, indicating that employees may have lost personal funds due to this hack as well; and all of the stolen assets were moved to KuCoin, which ZachXBT has identified as an increasingly popular destination for criminals. 

Bitcoin Depot Hack: ATM Operator Took 3 Days to Detect $3.6 Million Theft: The largest U.S. crypto ATM operator disclosed a March 23 breach after attackers stole 50.9 BTC using compromised credentials.
Bitcoin Depot Hack: Wallets involved (Source: ZachXBT’s X)

Bitcoin Depot stated that no customer platforms, systems, or data were affected as a result of the intrusion. The company identified its preliminary loss estimate as approximately USD 3.665 million, with the ultimate loss to be determined as the investigation develops. The company does maintain insurance; however, there is no assurance that any or all of the losses will be covered.

Bitcoin Depot Hack: ATM Operator Took 3 Days to Detect $3.6 Million Theft: The largest U.S. crypto ATM operator disclosed a March 23 breach after attackers stole 50.9 BTC using compromised credentials.
Bitcoin Depot Hack Traced Transactions. (Source: ZachXBT – TRM)

Significance of the Incident

The Bitcoin Depot hack shows, once more, that many crypto ATM operators, including Bitcoin Depot, have significant weaknesses in protecting their internal credentials and monitoring wallet usage. The fact that it took three days for the firm to detect the hack raises serious questions regarding its internal security controls. 

This incident follows another instance, a data breach in July 2025, where 26,000 individual records were compromised. Bitcoin Depot did not disclose this hack for a year because of an ongoing law enforcement investigation. These hacks are particularly sensitive given that Bitcoin Depot has instituted a new compliance policy that requires verification of customer identity for every transaction made at its kiosks; however, these new compliance requirements did not prevent the internal breach from occurring. 

To add a bit more drama to the cybersecurity controls, this hack came to light in tandem with another major incident last week, where the Drift Protocol (Solana’s decentralized perpetual trading exchange) was exploited, draining around USD 285 million, after administrative keys were compromised. It was a sophisticated, well-prepared, and timely executed exploit. 

What Happens Next 

Potential repercussions for Bitcoin Depot include regulatory oversight, legal costs, and damaged reputation. The ongoing investigation will likely reveal additional financial consequences than what was initially reported to be USD 3.6 million stolen. Furthermore, KuCoin exchange may be asked to freeze the stolen funds, but ZachXBT noted that these wallet addresses had not been registered through compliance tools before the time of disclosures. 

Final Take

The Bitcoin Depot hack shows a raw reality: even large public companies in the crypto ATM business are at risk from a credential based inference point of view. Finding out about the teh hack three days after it occurred indicates that there are not just failures in security, but there is a systemic problem. As crypto ATMs are becoming such an important way for millions of people to access crypto, operators need to have the same level of sophistication in the tech they use to serve customers as they do in the internal security controls. Otherwise, the next breach could be far worse.

Disclaimer: All content provided on Times Crypto is for informational purposes only and does not constitute financial or trading advice. Trading and investing involve risk and may result in financial loss. We strongly recommend consulting a licensed financial advisor before making any investment decisions.

A Web3 Journalist at TimesCrypto with a knack for turning complex ideas into engaging stories. With a solid Tech background, Alan has led teams to create and refine impactful projects across industries, working in firms such as IBM, Cisco Systems, and Telecom. He’s passionate about Blockchain, Finance, Science, bringing a unique blend of technical expertise and creative flair to every piece he writes. When he’s not crafting content, you’ll find him diving deep into research or just having some fun!

Zoomable Image