Israel's largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
Bits of Gold reported on August 17 that a hacker compromised a third-party data analytics provider connected to the platform, exposing personal and banking data for approximately 200,000 customers. Digital assets and funds remained untouched. The breach is one of three major crypto-sector data compromises disclosed within a week.
Bits of Gold, Israel's largest crypto broker, reported on August 17 that a hacker gained unauthorized access to a third-party data analytics network connected to its platform, exposing personal and financial data for approximately 200,000 customers. According to CoinDesk's reporting, the breach is the third major crypto-sector data compromise disclosed within a week, following similar third-party vendor incidents at SafePal and Trezor.
The exposed data includes names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses. Bits of Gold confirmed that no funds, private keys, passwords, CVV codes, or scanned ID documents were compromised. Upon detecting the breach, the company blocked access to the analytics system and disconnected it from information sources, ending the hacker's access.
Bits of Gold's initial findings indicate the attack was part of a broader global incident that targeted other companies simultaneously, according to CoinDesk. The company's security team has launched a comprehensive investigation with assistance from a specialized cyber incident response firm.
The platform, founded in 2013, was the first crypto company in Israel to receive a permanent Financial Services Provider license. Under CEO Youval Rouach, it serves more than 250,000 customers and holds SOC 2 Type 2 certification. Despite these compliance credentials, the vendor compromise exposed the firm to a class of attack that circumvents direct platform security.
The three concurrent breaches within one week, per CoinDesk, underscore a pattern of adversaries targeting crypto industry supply chains rather than attacking platforms directly. SafePal disclosed on August 17 that nearly 40,000 users' data was stolen after a third-party vendor suffered compromise. Trezor announced on August 13 that personal data from almost 14,000 wallet customers was exposed after its fulfillment partner, ShipMonk, was compromised.
Bits of Gold advised customers to remain vigilant against phishing and social engineering, noting that the company would never request passwords, verification codes, private keys, or fund transfers. The firm's rapid response, disconnecting the compromised system immediately upon detection, limited the exposure window, though the full extent and duration of the hacker's access remain unclear from available reporting.
The breach raises questions about the adequacy of vendor risk management frameworks across platforms that hold formal compliance certifications. Bank account details and national ID numbers, though not immediately actionable without additional authentication, create significant identity theft and fraud risk for the 200,000 affected customers.
Approximately 200,000 customers' names, national ID numbers, bank account details, emails, phone numbers, and IP addresses were exposed through a compromised third-party vendor, but no funds, passwords, or private keys were taken.
Watch for Bits of Gold's comprehensive investigation findings and any evidence of coordinated targeting across the three concurrent breaches. The incident invalidates the premise that SOC 2 Type 2 certification alone prevents large-scale data compromise, and signals a structural gap in crypto platform security posture: third-party vendor access is now a primary attack vector.
And that's the way it is.
Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.
