Bits of Gold Probes Customer Data Breach Tied to Third-Party Software

1 hour ago 3 sources negative

Key takeaways:

  • Centralized exchanges' regulatory compliance does not shield customer data from third-party breaches, undermining trust.
  • Exposed Israeli banking details and wallet addresses create targeted phishing threats for local crypto users.
  • Bits of Gold's BILS stablecoin could face short-term reputational risk despite unaffected reserves.

Bits of Gold, Israel’s largest regulated cryptocurrency broker, said it is investigating a cybersecurity incident that may have exposed personal and financial information belonging to a substantial portion of its more than 300,000 customers. The company notified users on Aug. 16 after detecting unauthorized access to a third-party software system used for customer support and data analysis.

The firm said potentially accessed information includes names, Israeli identification numbers, email addresses, phone numbers, IP addresses, bank account details and public cryptocurrency wallet addresses. It emphasized that customer cryptocurrency and fiat funds were not compromised and that account passwords, scanned ID documents, complete credit-card numbers and CVV codes were unaffected.

Bits of Gold linked the incident to a wider global breach involving a software provider used by multiple businesses. Israeli outlet Calcalist reported that hundreds of companies may have been affected and that Bits of Gold was not believed to have been directly targeted. The company said it blocked the access, disconnected the affected system from its information sources and notified authorities, while also engaging a specialist cyber incident-response firm.

Reports cited by local media put the potentially affected customer count at roughly 200,000, but Bits of Gold has not publicly confirmed that figure. The firm said its review indicates “there may have been access to certain personal information,” while adding that there is so far no indication the exposed data has been misused.

The main immediate risk is social engineering. With names, phone numbers, emails, banking details and public wallet addresses exposed, attackers could craft more convincing phishing messages impersonating Bits of Gold, banks or other financial services. The company warned customers not to provide passwords, verification codes or private keys and not to transfer funds in response to unsolicited requests. The warning follows another third-party exposure in the crypto sector, when a ShipMonk breach exposed personal information belonging to 13,689 Trezor customers.

Bits of Gold operates under financial services licence 56716 and was the first active Israeli crypto business to receive a permanent licence from the Capital Market, Insurance and Savings Authority. In April 2026, Israeli regulators approved its BILS stablecoin after a two-year sandbox process; BILS is backed one-to-one by shekels.

The incident underscores a different risk from exchange hacks: regulated custody can protect customer assets and private keys, but conventional databases holding personally identifiable information remain vulnerable through third-party providers.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.