Bits of Gold Customer Data Breach: Yellow App Suspends Bitcoin Purchases

A customer personal data breach has occurred at Bits of Gold, Israel's leading regulated cryptocurrency brokerage. Founded in 2013, the company was the first Israeli cryptocurrency firm to obtain a permanent financial services provider license, and it also holds SOC 2 Type 2 certification. Some outlets estimated the potentially affected range at roughly 200,000 to as many as 250,000 people, but the actual number of customers whose information was exposed has not yet been confirmed.

Bits of Gold said on August 16 that unauthorized access had occurred in a secondary data analytics system. The information potentially exposed includes names and national identification numbers, email addresses, phone numbers, IP addresses, bank account information, and public wallet addresses. According to the company, customer funds, digital assets, private keys, passwords, card security codes (CVV), and copies of identification documents were not affected.

The company explained that the incident occurred in an environment linked to an external data analytics vendor. Some security experts have raised a possible connection to the recent Metabase breach, but the exact intrusion path and vulnerability have not been officially confirmed. The company isolated the system in question, reported the incident to the Capital Markets Authority and the National Cyber Directorate, and then launched an investigation with an outside security firm.

Following the incident, Paz, an Israeli retail and energy company, suspended the bitcoin purchase function in its convenience store app Yellow until the investigation is complete. However, it said that because the Yellow app and Bits of Gold's systems are not directly connected, Yellow users' information was not exposed, and the partnership between the two companies remains in place.

Around the same period, roughly 40,000 people's information was exposed at SafePal through its order tracking function, and at Trezor, shipping information for roughly 14,000 people was leaked through a breach at a logistics provider. All three incidents share the characteristic that they occurred not in private keys or the wallets themselves but in peripheral operational systems such as ordering, shipping, and data analytics.

Metanomia View

Even if private keys are safe, when real names, bank accounts, and public wallet addresses are exposed together, attackers can link specific users to their on-chain transaction histories and use that for targeted phishing and impersonation. The likelihood also grows that they will screen targets based on wallet balances and transaction flows.

Recently, incidents have occurred in succession at SafePal's order tracking function, Trezor's logistics provider, and Bits of Gold's data analytics environment. The shipping addresses exposed at SafePal and Trezor connect hardware wallet purchase histories to places of residence. Such information can be abused as a target list for physical attacks, not just online fraud. Chainalysis counted 46 cases of cryptocurrency extortion involving violence through the end of June 2026, and analyzed that more than $30 million was taken in successful attacks.

Virtual asset security does not stop at wallets and private keys. The entire data supply chain, including the analytics tools that receive customer information and the logistics and partner services, must be managed as a single security perimeter.

Sources