Broker Investigates Possible Data Exposure
Bits of Gold, a regulated crypto broker in Israel, said it is investigating a cyber incident that may have exposed some customer identity and financial information. The company said the incident involved unauthorized access to a third-party system used for support and data analysis. Its review indicates there may have been access to certain personal information, including names, identification numbers, emails, phone numbers, IP addresses, bank account details and public crypto wallet addresses. Bits of Gold said digital assets, account passwords, scanned ID documents, full credit card details and CVV codes were not affected, and that there is so far no indication the potentially exposed information has been used.
The company linked the incident to third-party software compromised during a wider global breach. Calcalist reported that hundreds of companies may have been affected and that Bits of Gold was not believed to have been directly targeted. The software provider has not been publicly identified in the disclosures reviewed. Bits of Gold notified customers on Aug. 16, and said it had blocked the access, disconnected the affected system from its information sources and informed relevant authorities.
Customer Impact Figure Unconfirmed
Reports circulating Sunday put the potentially affected customer count at roughly 200,000, but that figure should be treated cautiously. The customer notice reproduced by Calcalist does not state how many records were accessed. Bits of Gold has not publicly confirmed that 200,000 people were affected. The company’s website lists more than 300,000 customers.
Phishing and Impersonation Risk
The main immediate risk appears to be social engineering rather than theft from customer wallets through the reported incident itself. Names, phone numbers, emails, banking information and public wallet addresses could help attackers craft more convincing messages impersonating Bits of Gold, a bank or another financial service. Bits of Gold warned customers about phishing and impersonation attempts, telling them not to provide passwords, verification codes or private keys and not to transfer money or digital assets in response to unsolicited approaches.
Regulatory Context
Bits of Gold operates under financial services license 56716 from the Capital Market, Insurance and Savings Authority and says it was the first active Israeli crypto business to receive a permanent license from the authority. Its regulatory profile expanded this year with BILS, a shekel-pegged stablecoin. According to Bits of Gold, regulators approved BILS for issuance and distribution on April 27 after a roughly two-year sandbox, with each token backed 1:1 by shekels held in reserve.
What Happens Next
Bits of Gold said its security team has begun a comprehensive review with a specialist cyber incident response company and continues to monitor its systems. Relevant authorities have been notified, services remain operational, and no account action is currently required. Key disclosures still to come include the confirmed number of affected customers, the identity of the compromised software provider, the exact scope of accessed records and whether investigators find evidence the data was misused.







