Israel's largest regulated crypto broker Bits of Gold is investigating a data breach that may have exposed personal and financial information of up to 250,000 customers, the third major crypto-sector leak in a week.
Israel's largest regulated crypto broker Bits of Gold is investigating a data breach that may have exposed personal and financial information of up to 250,000 customers, the third major crypto-sector leak in a week.

Israel's largest regulated crypto broker Bits of Gold is investigating a data breach that may have exposed personal and financial information of up to 250,000 customers, the third major crypto-sector leak in a week.
Bits of Gold said a data breach may have exposed up to 250,000 customers' personal data, prompting Israeli retailer Paz to halt Bitcoin purchases on its Yellow app.
"Upon detection of the incident, we blocked access and disconnected the system from the information sources, so this access ended," Bits of Gold said in an Aug. 16 notice, adding that customer funds and digital assets were not involved.
The exposed data includes names, national identity numbers, phone numbers, email and IP addresses, bank-account details and public crypto wallet addresses. Account passwords, identification-document images, private keys, full card details and CVV codes were not exposed. CTech attributed the breach to CVE-2026-72898, an active exploit affecting self-hosted releases of Metabase, an analytics software provider.
The incident marks the third major crypto-sector data breach in a week, following SafePal's exposure of 39,798 customers and Trezor's ShipMonk-linked leak of roughly 13,700 users. With Chainalysis documenting 46 violent incidents and more than $30 million stolen in the first half of 2026, the combination of home addresses and proof of crypto ownership raises physical-safety concerns for affected users.
Bits of Gold, founded in 2013, was the first crypto company in Israel to receive a permanent Financial Services Provider license. The firm holds SOC 2 Type 2 certification and serves more than 250,000 customers, according to its website.
Paz, the Israeli retail and energy conglomerate, suspended the Bits of Gold integration on its Yellow convenience store app following the disclosure, according to a CTech report. Paz said it was not concerned that Yellow customer information had leaked because the two applications lack a direct interface. The broader commercial agreement between the firms remains in effect.
Bits of Gold said it has notified the Capital Market Authority and the National Cyber Directorate, and has retained a cybersecurity incident-response firm. The company advised customers that no technical action, such as moving funds or crypto assets, was required, but urged them to remain alert for phishing attempts and to never share verification codes, one-time passwords or private keys.
The breach adds to a growing pattern of crypto-sector incidents in which attackers gain access to customer information without directly compromising digital assets. SafePal disclosed Sunday that a flaw in an order-tracking plug-in exposed names, email addresses, shipping addresses, phone numbers and purchase details of 39,798 customers who ordered between March 2, 2025, and April 11, 2026. Trezor disclosed days earlier that a breach at shipping partner ShipMonk compromised data on roughly 13,700 customers.
The clearest cautionary tale remains Ledger, whose 2020 leak of some 272,000 customers' details led to a wave of phishing and, for some, ransom threats invoking violence. The timing adds to a jittery stretch for self-custody users still shaken by the Coldcard exploit, which drained long-dormant Bitcoin through a firmware entropy flaw and pushed industry-wide losses toward $130 million.
This article is for informational purposes only and does not constitute investment advice.