A customer personal data breach has occurred at Bits of Gold, Israel's leading regulated cryptocurrency brokerage. Founded in 2013, the company was the first Israeli cryptocurrency firm to obtain a permanent financial services provider license, and it also holds SOC 2 Type 2 certification. Some outlets estimated the potentially affected range at roughly 200,000 to as many as 250,000 people, but the actual number of customers whose information was exposed has not yet been confirmed.
Bits of Gold said on August 16 that unauthorized access had occurred in a secondary data analytics system. The information potentially exposed includes names and national identification numbers, email addresses, phone numbers, IP addresses, bank account information, and public wallet addresses. According to the company, customer funds, digital assets, private keys, passwords, card security codes (CVV), and copies of identification documents were not affected.
The company explained that the incident occurred in an environment linked to an external data analytics vendor. Some security experts have raised a possible connection to the recent Metabase breach, but the exact intrusion path and vulnerability have not been officially confirmed. The company isolated the system in question, reported the incident to the Capital Markets Authority and the National Cyber Directorate, and then launched an investigation with an outside security firm.
Following the incident, Paz, an Israeli retail and energy company, suspended the bitcoin purchase function in its convenience store app Yellow until the investigation is complete. However, it said that because the Yellow app and Bits of Gold's systems are not directly connected, Yellow users' information was not exposed, and the partnership between the two companies remains in place.
Around the same period, roughly 40,000 people's information was exposed at SafePal through its order tracking function, and at Trezor, shipping information for roughly 14,000 people was leaked through a breach at a logistics provider. All three incidents share the characteristic that they occurred not in private keys or the wallets themselves but in peripheral operational systems such as ordering, shipping, and data analytics.