
Bits of Gold, Israel's regulated crypto broker, probes a data breach that may expose customer identity and financial details. Phishing risk rises as attackers could use the data for impersonation.
Bits of Gold, Israel's regulated crypto broker, is investigating a cyber incident that may have exposed customer identity and financial information. The breach stemmed from unauthorized access to a third-party system used for support and data analysis.
The company notified customers on Aug. 16 and said it had blocked the access, disconnected the affected system from its information sources and informed relevant authorities, Calcalist reported. Bits of Gold said its review indicates "there may have been access to certain personal information," including names, ID numbers, emails, phone numbers, IP addresses, bank account details and public crypto wallet addresses. Digital assets, account passwords, scanned ID documents, full credit card numbers and CVV codes were not affected, the company said. So far, "there is no indication" that the potentially exposed information has been used.
The incident was part of a broader cyber event involving a software company Bits of Gold uses, along with other businesses worldwide. Calcalist reported that hundreds of companies may have been affected and that Bits of Gold was not believed to have been a direct target. The software provider has not been publicly identified.
Reports circulating Sunday put the potentially affected customer count at roughly 200,000. That figure should be treated cautiously. The customer notice reproduced by Calcalist does not state how many records were accessed. Bits of Gold's website lists more than 300,000 customers, and the company has not publicly confirmed that 200,000 people were affected.
The main immediate risk is social engineering, not theft from wallets through the reported incident itself. Names, phone numbers, emails, banking information and public wallet addresses could give attackers material for more convincing messages impersonating Bits of Gold, a bank or another financial service. Bits of Gold specifically warned customers about phishing and impersonation attempts.
The company told users not to provide passwords or verification codes, and never to share private keys. It also said not to transfer money or digital assets in response to unsolicited approaches. The warning follows a similar third-party exposure in the crypto sector: a ShipMonk breach exposed personal information belonging to 13,689 Trezor customers, crypto.news reported, prompting parallel concerns about targeted phishing.
Bits of Gold operates under financial services license 56716. The company says it was the first active Israeli crypto business to receive a permanent financial services license from the Capital Market, Insurance and Savings Authority. Its website lists more than 300,000 customers, while Calcalist described it as the first currently active company among nine businesses licensed to trade cryptocurrencies by the authority.
Its regulatory profile expanded this year with BILS, a shekel-pegged stablecoin. Bits of Gold says regulators approved BILS for issuance and distribution on April 27 after a roughly two-year sandbox. Israel approved the BILS shekel stablecoin after its regulatory pilot, and Bits of Gold says each token is backed 1:1 by shekels held in reserve.
Bits of Gold said its security team has begun a review with a specialist cyber incident response company and continues to monitor its systems. Services remain operational, and the company told customers no account action is currently required.
The next key disclosures will be the confirmed number of affected customers, the identity of the compromised software provider, the exact scope of accessed records and whether investigators find evidence that the data was misused. Until then, the widely reported 200,000-customer figure and the full scale of the incident remain unconfirmed by Bits of Gold.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.