Bits of Gold, Israel's largest regulated cryptocurrency broker, has reportedly suffered a significant data breach after a hacker stole personal information belonging to approximately 200,000 customers. The security incident potentially impacts the broker's entire user base, presenting a major challenge for a firm that built its industry reputation on strict regulatory compliance and robust platform security.
Nature and Scope of the Compromised Data
The cyberattack specifically focused on personal data belonging to the platform's client base. With Bits of Gold serving more than 200,000 clients in Israel, the breach stands to affect virtually every individual user registered on the exchange platform. Although the specific types of compromised personal details have not been publicly disclosed by the firm, cryptocurrency brokers are bound by know-your-customer regulations to collect extensive identification records. Under these mandatory regulatory guidelines, brokers typically gather government-issued identification cards, proof of residence, and personal financial information.
Security Features and Cold Storage Limitations
To reassure its clientele, Bits of Gold has previously emphasized security protocols including multi-factor authentication and cold storage arrangements for user funds. However, while cold storage technology safeguards cryptocurrency holdings by storing keys offline, it does not provide security for personal identity documents that reside on connected corporate servers.
Regulatory Background and Recent Developments
The incident puts notable pressure on a broker that has functioned as a central figure in Israel's crypto industry. In September 2022, Bits of Gold earned distinction as the first digital asset business in the country to obtain a virtual asset service provider license from the Capital Market Authority. The company's platform provides shekel and U.S. dollar trading pairs, over-the-counter trading services, and dedicated API solutions tailored for corporate clients.
Building on its regulatory standing, Bits of Gold obtained official authorization in April 2026 to issue BILS, a digital stablecoin collateralized one-to-one by the Israeli shekel. The stablecoin project was developed in technical collaboration with Solana and Fireblocks, with auditing services performed by accounting firm EY.
Heightened Phishing and Security Risks for Users
The exposure of sensitive customer files introduces major secondary risks for Bits of Gold's client base. Similar security breaches in the digital asset sector, such as the 2020 security incident involving hardware wallet firm Ledger—which resulted in the public exposure of client names, email contacts, and physical street addresses—subsequently triggered targeted phishing campaigns and direct threats against victims. For the 200,000 users affected by the Bits of Gold incident, exposed personal information could be exploited by malicious actors conducting SIM-swapping operations, social engineering efforts, and specialized phishing tactics designed to steal digital asset holdings.







