Corporate Wallet Breach Drains $3.6M from Bitcoin Depot
Bitcoin Depot's March 23 breach exposed settlement-account credentials, allowing attackers to steal over 50 Bitcoin directly from company-controlled wallets. This attack bypassed customer platforms and data, focusing instead on immediate monetary theft through internal corporate access. Standard breach responses that prioritize customer data loss miss this direct financial impact from compromised corporate secrets.
The company confirmed the intrusion affected only its IT environment and did not impact customer systems or data. The stolen Bitcoin, valued at approximately $3.665 million, was transferred before the breach was contained. Bitcoin Depot engaged cybersecurity experts and law enforcement, and the investigation is ongoing. The incident highlights the risk to firms managing digital assets through corporate settlement accounts rather than customer-facing vulnerabilities.
This breach underscores that attackers targeting crypto firms are increasingly focusing on internal settlement credentials to directly siphon funds. The damage is already done, so the primary concern is understanding the blast radius of such intrusions for firms holding digital assets. This pattern signals a shift in attacker focus from data exfiltration to immediate financial theft via corporate wallet compromise.