$3.6 Million Stolen in Bitcoin Depot Hack

2026-04-09T07:24:10Zc9adbb0d58e919c31dee1a5835181bd778d6a7d2507f617369b025a13154eb66
APT28Apache-ActiveMQDDoSDNS-hijackingFBI-cybercrime-statsIoTIran-linkedJolokiaMasjesuNinja-FormsOTOpenSSLPLCRCESCADAWordPressbitcoinbotnetcredential-theftcritical-infrastructurecryptocurrency-thefthealthcare-disruptionpatchrouter-compromisevulnerabilities

What happened

SecurityWeek roundup: attackers stole roughly $3.6M (50+ BTC) from Bitcoin Depot after stealing credentials. Multiple high-impact vulnerabilities and fixes were reported: OpenSSL received patches for seven flaws (including data-leak and DoS issues); an RCE in Apache ActiveMQ Classic persisted for 13 years (exploitation requires auth, but Jolokia API can be exposed without authentication); and a critical Ninja Forms WordPress bug allowing arbitrary file upload and RCE is being actively exploited. Nation‑state and infrastructure threats include APT28 using compromised TP-Link/MikroTik routers to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
c9adbb0d58e919c31dee1a5835181bd778d6a7d2507f617369b025a13154eb66
Enrichment time
2026-04-09T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.