FEDERALItem 1.05 · mandatoryHackingFinancial ServicesTechnologyFinanceDepository CreditStolen CredentialsHighActive
Bitcoin Depot Inc.
bd_e7d2c7760ef16931 · schema v1 · pii pii-v1
Full breach record for Bitcoin Depot Inc. →On March 23, 2026, Bitcoin Depot Inc. discovered unauthorized access to certain IT systems in which an actor obtained control of credentials associated with the Company's digital asset settlement accounts and transferred approximately 50.903 Bitcoin (~$3.665 million) from Company-controlled wallets. The Company believes the incident was contained to its corporate environment and did not affect customer platforms; no evidence of customer PII access identified. Materiality determined April 6, 2026.
SEC clockMateriality determined Apr 6, 2026 → Filed Apr 8, 20262d ✓ SEC 4-day OK16 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1901799/000119312526147772/btm-20260406.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 8, 2026
- Raw hash
- 06066be123b551b74dc6d17ef3d377f6426526746c570b2045a0bdd891ca55cd
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Bitcoin Depot Inc.norm: bitcoin depot
- SEC CIK
- 0001901799
- Domain
- bitcoindepot.com
Victim entity
- Name
- Bitcoin Depot Inc.norm: bitcoin depot
- SEC CIK
- 0001901799
- Domain
- bitcoindepot.com
- Industry
- Financial ServicesllmTechnologyllmNAICS 522180 · Savings Institutions and Other Depository Credit Intermediation
Incident
- Discovered
- Mar 23, 2026
- Materiality determined
- Apr 6, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1657 Financial Theft
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed Form 8-K Item 1.05 with the SEC
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Apr 6, 2026→ Filed: Apr 8, 20262d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.