Bits of Gold data breach exposes customer personal and financial information.

Bits of Gold customers face data exposure after breach

Bits of Gold, one of Israel’s largest regulated cryptocurrency brokers, is investigating a data breach that may have exposed sensitive information belonging to a large number of its customers.

The company disclosed the incident on August 16 after detecting unauthorised access to a supporting system used for customer support and data analysis. The compromised system belonged to a third-party software provider rather than Bits of Gold’s main trading platform.

The information that may have been accessed includes customers’ names, national identification numbers, email addresses, phone numbers, IP addresses, bank account details and public cryptocurrency wallet addresses.

However, Bits of Gold said customers’ cryptocurrency and fiat funds were not affected. Account passwords, scanned identification documents, full payment card details and CVV codes were also not exposed, according to the company. Bits of Gold does not hold customers’ private keys.

The exact number of affected customers has not been confirmed by Bits of Gold. Some reports have put the figure at about 200,000, while CTech reported that the potential exposure could involve information belonging to as many as 250,000 customers. The company itself has not confirmed either figure.

How the data was exposed

Bits of Gold said the unauthorised access involved a supporting system connected to its data-analysis operations.

The company disconnected the affected system from its information sources after discovering the incident and blocked the unauthorised access. It has also hired a specialist cybersecurity incident-response firm to investigate what happened and notified the relevant authorities.

The incident appears to be connected to a wider attack involving third-party software used by multiple organisations.

CTech reported that the affected system was linked to Metabase, an analytics platform, and that the incident involved a vulnerability identified as CVE-2026-72898. Bits of Gold has not publicly identified the software provider in its own customer notice, so the exact attack path remains under investigation.

This distinction matters because the incident was not a direct compromise of Bits of Gold’s cryptocurrency wallets or trading infrastructure.

The biggest immediate risk is not the direct theft of cryptocurrency from Bits of Gold accounts.

Instead, the exposed information could give criminals enough personal details to create convincing phishing and impersonation attempts.

For example, someone with access to a customer’s name, phone number, email address and knowledge that the person uses Bits of Gold could pretend to be an employee of the company. They could then attempt to obtain a password, verification code or private key.

The presence of bank account information and public wallet addresses could make such attempts more convincing.

Bits of Gold has warned customers not to provide passwords, verification codes or private keys to anyone claiming to represent the company. It also said customers should not transfer money or digital assets to another wallet because of an unsolicited request.

The company said there is currently no indication that the potentially exposed information has been used for fraud.

Bitcoin purchases paused on Yellow

The breach has also affected one of Bits of Gold’s business partnerships.

Paz, an Israeli energy and retail company, temporarily suspended Bitcoin purchases through its Yellow app after the incident became public.

Yellow uses Bits of Gold for its Bitcoin service. Paz said the suspension was a precaution while the investigation continues and that there was no indication that Yellow users’ information had been exposed because the two systems do not have a direct interface.

Paz said its wider commercial relationship with Bits of Gold remains in place, while Bits of Gold’s main services continue to operate.

The security problem for crypto companies

The incident highlights a security risk that extends beyond cryptocurrency wallets and private keys.

Crypto companies rely on third-party providers for services such as analytics, customer support, shipping, payments and other business functions. A vulnerability in one of these systems can expose customer information even when the company’s core infrastructure and digital assets remain secure.

Bits of Gold is not the only crypto company to face this type of problem recently.

Trezor recently disclosed a breach involving one of its shipping providers that exposed personal information belonging to thousands of customers. SafePal also reported a separate incident involving its order-tracking system. In both cases, the concern centred on customer information rather than the direct theft of users’ crypto assets.

For Bits of Gold customers, the company says there is currently no need to move funds or take other account action because of the breach.The immediate concern is protecting personal information that may have been exposed and remaining alert to suspicious messages, calls or emails.

As the investigation continues, Bits of Gold still needs to establish exactly what information was accessed, how many customers were affected and whether any of the exposed data has been misused

Read also: SafePal data breach leaks 40,000 customers

Leave a Reply