Latest News

Israel’s Largest Regulated Crypto Broker Bits of Gold…

Israel’s largest regulated cryptocurrency broker, Bits of Gold, is investigating a cybersecurity incident that may have exposed personal and financial information belonging to a substantial portion of its customer base, with reports estimating that approximately 200,000 users could be affected. Bits of Gold notified customers on August 16 after detecting unauthorized access to a third-party software system used for customer support and data analysis.

The company said potentially accessed information includes names, Israeli identification numbers, email addresses, telephone numbers, IP addresses, bank account details and public cryptocurrency wallet addresses. Bits of Gold emphasized that customer cryptocurrency and fiat funds were not compromised. Passwords, scanned identification documents, complete credit-card numbers and CVV security codes were also unaffected, according to the company. The widely reported figure of approximately 200,000 affected customers remains preliminary. Bits of Gold has not publicly confirmed the number of records accessed, while the company says it serves more than 300,000 customers.

Third-Party Software Was Compromised

Bits of Gold said the incident originated from software supplied by an external provider rather than a direct breach of its core trading or custody infrastructure. The compromised software was reportedly involved in support and data-analysis functions and was affected as part of a broader global cyber incident involving other companies. After learning of the unauthorized access, Bits of Gold said it blocked the intrusion, disconnected the affected system from its information sources and notified the relevant authorities. The company has also engaged a specialist cyber incident-response firm to conduct a broader investigation.

Bits of Gold said it currently has no indication that the potentially exposed information has been misused. Its services remain operational, and customers have not been instructed to move assets or change account credentials as a result of the incident. The most immediate concern is instead targeted social engineering. Information combining a customer’s identity, telephone number, banking relationship and public cryptocurrency addresses could allow criminals to construct convincing phishing messages.

Breach Tests Security at a Regulated Crypto Firm

The incident is particularly notable because of Bits of Gold’s position within Israel’s regulated digital-asset market. Bits of Gold operates under financial-services licence 56716 and became the first active Israeli cryptocurrency company to receive a permanent licence from the country’s Capital Market, Insurance and Savings Authority in 2022. Its regulatory footprint expanded further this year. In April 2026, Israeli regulators approved the company’s BILS stablecoin following an approximately two-year regulatory sandbox process. BILS is designed to maintain a one-to-one peg with the Israeli shekel, with corresponding shekel reserves backing tokens in circulation.

The latest incident illustrates a different category of risk from the exchange hacks historically associated with cryptocurrency. Regulated custody can protect customer assets, and private keys can remain secure, while conventional databases containing personally identifiable information remain vulnerable through third-party software providers. Bits of Gold has specifically warned customers to be alert for phishing and impersonation attempts and said users should never provide passwords, verification codes or private keys in response to unsolicited communications. Until the investigation is completed, the scale of the incident remains uncertain. Reports of approximately 200,000 affected customers would make it a significant exposure, but that number should not be treated as confirmed. What Bits of Gold has confirmed is potentially more important for customers: sensitive identifying and financial information may have been accessed, even though the credentials required to directly take control of their crypto accounts were not.

You may also like