$3.6 Million Stolen in Bitcoin Depot Hack
2026-04-09T07:24:10Z•c9adbb0d58e919c31dee1a5835181bd778d6a7d2507f617369b025a13154eb66
APT28Apache-ActiveMQDDoSDNS-hijackingFBI-cybercrime-statsIoTIran-linkedJolokiaMasjesuNinja-FormsOTOpenSSLPLCRCESCADAWordPressbitcoinbotnetcredential-theftcritical-infrastructurecryptocurrency-thefthealthcare-disruptionpatchrouter-compromisevulnerabilities
What happened
SecurityWeek roundup: attackers stole roughly $3.6M (50+ BTC) from Bitcoin Depot after stealing credentials. Multiple high-impact vulnerabilities and fixes were reported: OpenSSL received patches for seven flaws (including data-leak and DoS issues); an RCE in Apache ActiveMQ Classic persisted for 13 years (exploitation requires auth, but Jolokia API can be exposed without authentication); and a critical Ninja Forms WordPress bug allowing arbitrary file upload and RCE is being actively exploited. Nation‑state and infrastructure threats include APT28 using compromised TP-Link/MikroTik routers to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- c9adbb0d58e919c31dee1a5835181bd778d6a7d2507f617369b025a13154eb66
- Enrichment time
- 2026-04-09T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.