Back Finance.Biggo Israeli Crypto Broker Bits of Gold Probes Data Breach Tied to Third
Bits of Gold, Israel's largest regulated cryptocurrency broker, is investigating a cyber incident that may have exposed personal information belonging to a substantial portion of its customer base after unauthorized access to a third-party system used for support and data analysis.
The Tel Aviv-based company notified customers on Aug. 16 that it had detected the breach several days earlier and immediately blocked the access point, disconnected the affected system from its information sources, and alerted relevant authorities. The incident was part of a broader global cyberattack targeting a software provider used by Bits of Gold and potentially hundreds of other businesses worldwide, according to a report by Calcalist.
The company said its preliminary review indicates "there may have been access to certain personal information," including names, identification numbers, email addresses, phone numbers, IP addresses, bank account details, and public crypto wallet addresses. Digital assets, account passwords, scanned ID documents, full credit card details, and CVV codes were not compromised, the company said.
Bits of Gold emphasized that it does not hold customers' private keys, full credit card details, or CVV codes, which limited the scope of the breach. The company also said "there is no indication" so far that the potentially exposed information has been used.
The scale of the breach remains unclear. Reports circulating on social media and in crypto-focused outlets put the potentially affected customer count at roughly 200,000, but that figure has not been confirmed by the company. The customer notice reproduced by Calcalist does not state how many records were accessed, while Bits of Gold's website says it has more than 300,000 registered customers. The company has not publicly confirmed that 200,000 people were affected.
The breach originated from a software company that Bits of Gold uses, rather than a direct attack on the crypto broker's own infrastructure. Calcalist reported that hundreds of companies worldwide may have been affected and that Bits of Gold was not believed to have been directly targeted. The software provider has not been publicly identified in the disclosures reviewed.
At this stage, no additional Israeli company is known to have been affected, according to the Calcalist report.
The incident follows another third-party exposure in the crypto sector. A ShipMonk breach previously exposed personal information belonging to 13,689 Trezor customers, prompting similar concerns targeted phishing attacks.
The primary immediate risk is social engineering rather than theft from customer wallets through the reported incident itself. Names, phone numbers, emails, banking information, and public wallet addresses could give attackers data for more convincing messages impersonating Bits of Gold, a bank, or another financial service.
Bits of Gold specifically warned customers phishing and impersonation attempts. The company told users not to provide passwords, verification codes, or private keys, and not to transfer money or digital assets in response to unsolicited approaches.
"Similar to other financial entities, the company will never ask you to provide a password, verification code, or private key, and will not ask you to transfer money or digital assets to another wallet," the company said in its customer notice.
The company said no account action is currently required and that its services continue to operate normally.
Bits of Gold operates under financial services license 56716 from Israel's Capital Market, Insurance and Savings Authority. The company says it was the first active Israeli crypto business to receive a permanent financial services license from the regulator, and Calcalist described it as the first currently active company among nine businesses licensed to trade cryptocurrencies by the authority.
Its regulatory profile expanded this year with BILS, a shekel-pegged stablecoin. Bits of Gold says regulators approved BILS for issuance and distribution on April 27 after a roughly two-year sandbox period. Each token is backed one-to-one by shekels held in reserve.
The company, which employs 55 people, recently signed a cooperation agreement with the Paz Group, under which customers will be able to purchase cryptocurrencies through the Yellow wallet.
Note: The 200,000-affected-customers figure is based on unconfirmed reports and should be treated with caution until Bits of Gold issues an official statement.
Bits of Gold said its security team has begun a comprehensive review with a specialist cyber incident response company and continues to monitor its systems. Relevant authorities have been notified.
The key disclosures will be the confirmed number of affected customers, the identity of the compromised software provider, the exact scope of accessed records, and whether investigators find evidence that the data was misused. Until then, the widely reported 200,000-customer figure and the full scale of the incident remain unconfirmed by Bits of Gold.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
