Bits of Gold disclosed Sunday that hackers stole personal data for roughly 200,000 customers through a breach at a third-party data analytics provider the broker relied on. The exposed information includes names, Israeli national ID numbers, emails, phone numbers, IP addresses, bank account details and public wallet addresses. Funds, private keys, passwords and CVV codes were not touched, and the company said the unauthorised access has since been cut off.
Why it matters
The Tel Aviv-based broker is Israel's largest crypto on-ramp and the first in the country to hold a permanent Financial Services Provider licence, serving more than 250,000 customers. Leaking national IDs and bank account details is a categorically worse outcome than a typical email leak because it gives attackers the inputs for identity fraud, account takeover attempts and convincing phishing that survives customer scepticism. CEO Youval Rouach stressed that funds and private keys remained safe, but the incident is the third crypto-vendor breach in roughly a week, after SafePal lost data on nearly 40,000 users and Trezor saw 14,000 customers exposed via fulfillment partner ShipMonk on August 13.
Market impact
The pattern is what worries the sector: in all three cases the entry point was a third-party vendor rather than the crypto company itself, and Bits of Gold's SOC 2 Type 2 certification did not cover the analytics network that was compromised. Investors should expect heightened regulatory scrutiny of vendor-risk frameworks across licensed crypto venues and renewed pressure on exchanges and brokers to map every external data flow. Spot BTC and ETH showed little reaction because no funds were lost, but the customer-facing trust costs tend to be slow-burn, and Bits of Gold now faces the same playbook SafePal and Trezor have to run: notify users, monitor for fraudulent account openings, and rebuild the third-party perimeter.
Frequently asked questions
-
How did the Bits of Gold data breach happen?
Bits of Gold said a hacker gained unauthorised access to a third-party data analytics provider the broker relied on, then disconnected the system from its information sources once the incident was detected.
-
What personal data was exposed in the Bits of Gold breach?
Names, Israeli national ID numbers, emails, phone numbers, IP addresses, bank account details and public wallet addresses were exposed. Funds, private keys, passwords and CVV codes were not touched.
-
How many Bits of Gold customers were affected?
Roughly 200,000 customers were affected, out of more than 250,000 total customers the Tel Aviv-based broker serves.
-
Were customer funds at risk in the Bits of Gold breach?
No. Bits of Gold stated that funds, digital assets, private keys, passwords, CVV codes and scanned ID documents were not involved in the incident.
-
Is the Bits of Gold breach linked to other recent crypto attacks?
It is the third crypto-vendor breach in about a week, following SafePal losing data on nearly 40,000 users and Trezor exposing data on 14,000 customers via fulfillment partner ShipMonk on August 13.
CoinDesk