Skip to content
Bits of Gold Investigates Cyber Incident; Customer Data Possibly Exposed

Bits of Gold Investigates Cyber Incident; Customer Data Possibly Exposed

Kucoin • August 16, 2026

Bits of Gold, one of Israel’s largest regulated crypto brokers, is investigating a cyber incident that may have exposed customer identity and financial information after unauthorized access to a third‑party system the firm uses for support and data analysis. What happened - The company told customers on Aug. 16 that it had blocked the intrusion, disconnected the affected system from its information sources and notified the relevant authorities, according to Calcalist. - Bits of Gold said its review so far suggests “there may have been access to certain personal information,” including names, ID numbers, email addresses, phone numbers, IP addresses, bank account details and public crypto wallet addresses. - The firm said sensitive items such as customers’ digital assets, account passwords, scanned ID documents, full credit card numbers and CVV codes appear to be unaffected. There is, at present, “no indication” that the potentially exposed data has been misused. Third‑party vector, wider event - Bits of Gold says the breach was part of a broader cyber event that involved a software company it and other firms worldwide rely on; the software provider has not been publicly identified. Calcalist reported that hundreds of businesses may have been impacted and that Bits of Gold was not believed to have been directly targeted. - Media reports circulating on Sunday put the potentially affected customer count at roughly 200,000. That number should be treated cautiously: the customer notice reproduced by Calcalist does not specify how many records were accessed, and Bits of Gold—whose website lists more than 300,000 customers—has not confirmed the 200,000 figure. Primary risk and guidance - The immediate threat from this incident is social engineering. Names, phone numbers, emails, bank details and public wallet addresses can make phishing and impersonation attempts far more convincing. Bits of Gold specifically warned users not to respond to unsolicited requests for passwords, verification codes or private keys, and not to transfer money or crypto following an unsolicited approach. - The company has emphasized that customers should be wary of phishing attempts masquerading as communications from Bits of Gold, banks or other financial services. Context in the sector - The alert follows another third‑party exposure in the crypto industry: a ShipMonk breach that exposed personal data of 13,689 Trezor customers, highlighting how supplier compromises can cascade across crypto ecosystems. Bits of Gold’s profile and response - Bits of Gold operates under financial services license 56716 and was the first active Israeli crypto company to receive a permanent license from the Capital Market, Insurance and Savings Authority. Its site lists more than 300,000 customers. - Earlier this year the company expanded its regulatory footprint by rolling out BILS, a shekel‑pegged stablecoin it says is backed 1:1 by shekel reserves and was approved for issuance and distribution after a roughly two‑year regulatory sandbox. - The firm says its security team has launched a full review with a specialist cyber incident response company, is monitoring systems closely and has notified regulators. Services remain operational and no immediate account action is required from customers. What to watch - Key forthcoming disclosures will include a confirmed count of affected customers, the identity of the compromised software provider, the precise scope of accessed records and whether investigators uncover evidence of data misuse. Until Bits of Gold provides those details, the exact scale of the incident remains unverified.

Extracted Entities

Attack Types (2)

Countries (1)

Industries (1)

MITRE ATT&CK (1)