[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgXDT1e0_UJOty2IwUmQxMFwjNh-b3jAEm7i3VC6KeUE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"7cf0e8f4-f149-4acc-8122-a2f43592eb4a","credential-compromise-leads-to-36m-bitcoin-theft-at-major-atm-operator","ed508805-6d12-4fd4-8918-a20b8a38a0a2","Credential Compromise Leads to $3.6M Bitcoin Theft at Major ATM Operator","Bitcoin Depot suffered a significant financial loss when attackers successfully compromised credentials for their digital asset settlement accounts, enabling the theft of over 50 bitcoin worth $3.6 million. The breach demonstrates how inadequate access controls for high-value financial accounts can lead to immediate and substantial monetary losses. This incident is particularly concerning as it represents the company's second major security breach within a year, suggesting systemic security weaknesses that weren't adequately addressed after the first incident.","**Immediate actions:**\n- Implement multi-factor authentication (MFA) for all accounts with access to digital asset wallets\n- Enable real-time monitoring and alerts for all cryptocurrency transactions above defined thresholds\n- Rotate all credentials and API keys with access to financial systems\n\n**Long-term improvements:**\n- Deploy privileged access management (PAM) solutions to control and monitor high-value account access\n- Establish multi-signature wallet requirements for large cryptocurrency transfers\n- Implement network segmentation to isolate financial systems from corporate networks\n\n**Detection measures:**\n- Configure automated alerts for unusual login patterns or geographic anomalies on financial accounts\n- Deploy behavioral analytics to detect abnormal access patterns to cryptocurrency wallets\n- Establish 24\u002F7 security operations center monitoring for all digital asset transactions",[12,13,14,15,16,17],"CIS Control 6 - Access Control Management","CIS Control 5 - Account Management","NIST AC-2 - Account Management","NIST AC-6 - Least Privilege","NIST SI-4 - Information System Monitoring","PCI DSS 8.2 - Multi-Factor Authentication","published","2026-04-09T08:08:40.549745+00:00","2026-04-09T08:08:40.409+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002F3-6-million-stolen-in-bitcoin-depot-hack\u002F","3-6-million-stolen-in-bitcoin-depot-hack-24066e","$3.6 Million Stolen in Bitcoin Depot Hack",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]