Bits of Gold, Israel's largest regulated cryptocurrency broker, notified customers on August 16, 2026 that a cyber incident several days earlier may have exposed personal and financial identity data. The company attributes the breach to unauthorized access to a third-party software system it uses for customer support and data analysis, and says the compromise is part of a wider global event affecting hundreds of companies. Affected-customer estimates differ across coverage: CoinDesk, FinanceFeeds and Value The Markets all report approximately 200,000 customers, while Calcalist's CTech headlines the figure as "up to 250,000." Bits of Gold itself is reported to serve more than 300,000 customers, meaning the exposure covers a majority but not the entirety of its base. One caveat on sourcing: the reporting reviewed here is all secondary. No regulator filing, national CERT advisory or vendor statement was available at publication, and the company's own notification is known only through quotation in press coverage.
What Happened
According to the company's customer notification as quoted by Calcalist and reproduced across crypto trade press, Bits of Gold identified unauthorized access to a third-party system connected to its environment. The system was used for customer support and data analysis functions rather than for custody or trading. On detection, the company says it blocked the access, disconnected the affected system from its information sources, and informed the relevant authorities. Customers were notified on August 16.
Bits of Gold has framed the incident as collateral damage rather than a targeted attack. The company describes the event as part of a broader global cyber incident in which a software provider it uses was breached. Calcalist reports that hundreds of companies worldwide may have been affected and that Bits of Gold is not believed to have been directly targeted; the same reporting notes that at this stage no other Israeli company is publicly known to have been hit. The software provider has not been named in any of the disclosures reviewed.
Accounts of certainty differ. Most coverage repeats the company's account of the intrusion path. CoinLineup, by contrast, characterises the situation as an active investigation in which the precise scope, timing and record count are not established, and cautions against treating the vendor link as settled fact. That is a fair read: the timeline of the intrusion, the dwell time before detection, and whether data was exfiltrated or merely accessible have not been publicly established.
What Was Taken
The company's stated review indicates "there may have been access to certain personal information." The categories consistently reported across sources are:
- Full names
- Israeli national identification numbers
- Email addresses
- Telephone numbers
- IP addresses
- Bank account details
- Public cryptocurrency wallet addresses
Bits of Gold states that the following were not affected: customer funds and digital assets, account passwords, scanned identity documents, full credit card numbers and CVV codes. The company also says there is no indication so far that the potentially exposed information has been used.
That last claim deserves the usual scepticism. "No indication of misuse" this early in an investigation is a statement about visibility, not about attacker behaviour, and it is worth noting that Value The Markets asserts the breach threatens stored identity documents, a claim that directly contradicts the company's own position and is not corroborated by any other source in this set.
The combination that was exposed is the operationally dangerous part. A national ID number plus a verified phone number, email, bank account and a public wallet address is a complete targeting package. It links a real identity to on-chain holdings that anyone can then inspect on a block explorer, which effectively converts a data breach into a shopping list for social engineering, SIM swap attempts and, at the severe end, physical coercion against high-balance holders. Calcalist's framing is blunt on this point: what was stolen is precisely what is needed for phishing-style fraud, and the company has told customers to be vigilant about approaches from third parties, including impersonation of official entities.
Why It Matters
Bits of Gold is not a marginal player. It received Israel's first virtual asset service provider licence from the Capital Market Authority in September 2022 and operates under Israeli financial regulation with licence number 56716. It offers shekel and dollar trading, OTC execution and business API services, and it issued BILS, a shekel-backed stablecoin that received approval in April 2026 after a two-year regulatory sandbox and is reported to remain backed one to one by shekels.
That regulatory pedigree is the point. This was the compliance benchmark for Israeli digital assets, an institution whose entire market position rested on doing KYC properly, and it is exactly that KYC data store that is now in question. The uncomfortable lesson for regulated finance is that mandatory identity collection creates a mandatory identity liability. The stricter the AML regime, the richer the dataset a broker is obliged to hold, and the more valuable it becomes to an attacker who never has to touch the custody stack.
The second-order significance is the supply chain. If the company's account holds, the attacker did not need to defeat a regulated broker's controls at all. They compromised one software vendor and reached hundreds of downstream customers, of which a licensed Israeli crypto broker was simply one entry on the list. The victim's own security posture, two-factor authentication and cold storage included, was never the deciding variable. Until the vendor is publicly identified, every organisation using support and analytics tooling in the same category is operating without the ability to check whether it is also on that list.
The Attack Technique
Concrete technical detail is thin, and no source in this set provides indicators of compromise, malware names, threat actor attribution or a CVE.
What is stated by the company: unauthorized access to a third-party software system used for customer support and data analysis, obtained via a compromise at the software provider itself rather than at Bits of Gold. The affected system had live access to Bits of Gold's information sources, which is why disconnecting it was part of the response.
This is a familiar shape. Support desk, CRM and business intelligence platforms are typically granted broad read access to customer records because that is their function, they are frequently integrated via long-lived API tokens or OAuth grants rather than interactive sessions, and their activity rarely receives the same monitoring scrutiny as core banking or custody infrastructure. A single compromised provider with tenanted access across hundreds of customer organisations produces exactly the fan-out pattern described here, with no lateral movement required inside any individual victim.
Two things remain unestablished. First, whether "access" means confirmed exfiltration or only demonstrated reachability; the company's language leaves that open. Second, the intrusion window. The incident is described as having occurred "several days" before the August 16 notification, but the compromise at the provider may predate that considerably.
What Organizations Should Do
- Inventory every third-party system holding customer PII and audit its access scope. Support desks, analytics platforms and BI tools routinely hold the same identity data as your system of record, with a fraction of the monitoring. Enumerate what each integration can read, not what it is supposed to read.
- Rotate and time-bound integration credentials. Long-lived API tokens and standing OAuth grants to SaaS vendors are the mechanism by which a vendor breach becomes your breach. Enforce short expiry, scope tokens to the minimum data set, and ensure you can revoke a single vendor's access in minutes rather than hours.
- Log and alert on vendor-side data access volume. Detection here depends on noticing anomalous bulk reads through a legitimate integration. Baseline normal query volume per integration and alert on deviation, since the credential itself will look valid throughout.
- Prepare for identity-led fraud, not account takeover. Where names, national ID numbers, phone numbers and wallet addresses are exposed together, the follow-on activity is targeted phishing, official-entity impersonation, SIM swap and account recovery abuse. Harden recovery flows, require out-of-band verification for withdrawal address changes, and warn customers that legitimate staff will never initiate contact requesting credentials or transfers.
- Treat exposed wallet addresses as a physical risk signal for high-value customers. Deanonymised addresses with visible balances have historically preceded coercion attempts against holders. Where account sizes justify it, notify affected customers directly and advise moving funds to fresh addresses.
- Push vendors for named disclosure and demand contractual notification timelines. The unnamed provider in this incident means downstream organisations cannot self-assess exposure. Require breach notification windows and vendor identification rights in contracts now, before you are the one waiting on someone else's disclosure.
Sources: Israel’s largest crypto broker Bits of Gold hit by data breach affe... | Bits of Gold data breach exposes personal details of up to 250,000... | Israel's Regulated Crypto Broker Bits of Gold Probes Customer Data... | https://financefeeds.com/israels-largest-regulated-crypto-broker-bi... | Israel Crypto Broker Bits of Gold Probes Third-Party Customer Data... | Understanding the Data Breach at Bits of Gold and Its Implications... | https://bitcoinethereumnews.com/crypto/israel-crypto-broker-bits-of... | Cyber incident at crypto company Bits of Gold: customers' personal...