What to Know

  • Bits of Gold said personal data belonging to roughly 200,000 customers was stolen after hackers accessed a third party data analytics network.
  • The exposed information includes names, national ID numbers, emails, phone numbers, IP addresses, bank account details and public wallet addresses.
  • The company said funds, digital assets, private keys, passwords, CVV codes and scanned ID documents were not exposed.
  • Bits of Gold said it blocked access and disconnected the system from information sources after detecting the incident.
  • The broker said initial findings indicate the attack was part of a broader global incident that affected other companies at the same time.
  • The incident follows separate recent data exposures affecting nearly 40,000 SafePal users and almost 14,000 Trezor wallet customers.
  • Bits of Gold said its security team has started a comprehensive investigation with help from a company specializing in cyber incident investigation and response.
  • The company told customers it would never ask for passwords, verification codes, private keys or fund transfers.

Customer Data Exposed Through Outside Analytics Provider

Bits of Gold, one of Israel’s most established cryptocurrency brokers, said hackers gained access to personal information tied to about 200,000 customers after breaching a third party data analytics provider. The Tel Aviv based company disclosed the incident on Sunday and said the unauthorized access involved an external network rather than its core custody or trading infrastructure.

The exposed data includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details and public wallet addresses. That mix of information is significant because it can be used by criminals to build convincing phishing messages, impersonation attempts or account targeting campaigns, even when no crypto assets are directly stolen. Public wallet addresses do not provide access to funds, but they may allow attackers to connect blockchain activity with real world identities if combined with other personal details.

Bits of Gold said the most sensitive asset control materials were not involved. The company stated that no funds, digital assets, private keys, passwords, CVV codes or scanned identity documents were exposed. That distinction matters in crypto markets because possession of private keys can allow direct control over digital assets, while exposed personal information more commonly raises risks around fraud, social engineering and identity abuse.

Company Says Access Was Blocked After Detection

Bits of Gold said that after the incident was detected, it blocked access and disconnected the system from the information sources, ending the unauthorized access. The company said its security team has begun a comprehensive investigation with assistance from a firm specializing in cyber incident investigation and response.

The broker also told customers that their digital assets and funds are safe and were not involved in the incident. For customers, that message is intended to separate the data exposure from a direct wallet compromise. Even so, crypto users often face heightened risk after personal data incidents because attackers may attempt to exploit fear and urgency through fake support messages, fraudulent recovery notices or requests to move funds.

Bits of Gold also warned customers that it would never ask for passwords, verification codes, private keys or fund transfers. That guidance is central to post breach risk management in the crypto sector. Once personal contact details are exposed, attackers may try to pose as a company representative and ask users to provide authentication codes, install software or transfer assets to a so called safe wallet. Legitimate crypto companies generally do not need a user’s private key, and any request for one should be treated as a red flag.

The incident adds to a broader wave of crypto industry data breaches reported within the last week. Across three firms, the breaches affected more than 230,000 users. Bits of Gold said its initial findings indicate the attack was part of a broader global incident that hit other companies simultaneously.

SafePal recently reported that data from nearly 40,000 users was stolen after a third party vendor suffered a security breach. Trezor wallet customers were also affected in a similar incident, with personal data from almost 14,000 customers exposed on August 13 after its fulfillment partner ShipMonk was compromised. These cases point to a recurring issue across digital asset infrastructure: companies may secure their own platforms while remaining exposed to weaknesses at external service providers.

Vendor risk has become a critical operational concern for crypto firms, particularly because the industry relies on a web of analytics platforms, fulfillment partners, customer support systems, compliance services and cloud based tools. Each connection can create a data pathway. If a vendor stores or processes customer information, a breach at that vendor can still become a customer security event for the crypto company that supplied the data.

Why Personal Data Matters Even When Funds Are Safe

The absence of stolen funds is an important reassurance, but it does not eliminate the seriousness of the incident. Names, national ID numbers, emails, phone numbers, IP addresses, bank account details and public wallet addresses can be combined to make scams more persuasive. A fraudster who knows a customer uses a specific crypto broker and can reference partial account or wallet information may be more likely to gain trust during a phishing attempt.

Bank account details create another layer of concern. Such information does not necessarily allow a criminal to drain an account by itself, but it can support identity based fraud attempts or make scam communications look more credible. National ID numbers are also sensitive because they may be used in attempts to impersonate individuals or pass through weak identity verification steps elsewhere.

Public wallet addresses create unique issues for crypto customers. A public address is not a password, and it cannot be used to move assets without private keys. However, blockchain transactions are often visible, meaning attackers may try to connect on chain activity to named individuals. This can increase risks of targeted scams, extortion attempts or unwanted profiling, particularly for users with visible wallet balances or repeated transaction patterns.

Bits of Gold’s Position in Israel’s Crypto Market

Bits of Gold was founded in 2013 and became the first crypto company in Israel to receive a permanent Financial Services Provider license. The company has more than 250,000 customers and holds SOC 2 Type 2 certification. It is led by CEO Youval Rouach and has long been viewed as a major player in Israel’s regulated digital asset market.

The scale of the customer base means that any exposure affecting roughly 200,000 customers is a major security event for the local crypto ecosystem. While the company said funds and digital assets were not touched, the incident may intensify scrutiny of how licensed crypto businesses manage outside technology providers and limit the amount of customer information shared across external systems.

Regulated crypto firms often collect more identifying information than decentralized platforms because they must comply with customer verification, banking and financial services rules. That requirement can make them attractive targets for criminals seeking high quality identity data. As a result, data governance and vendor oversight have become as important to crypto security as wallet management and transaction monitoring.

Customer Precautions After the Breach

Customers affected by this type of incident should be especially cautious with emails, phone calls and text messages that appear to come from a crypto broker, wallet provider, bank or compliance team. Attackers frequently use stolen personal details to create messages that appear official. The goal is often to capture a verification code, reset a password, install malicious software or persuade a user to transfer assets.

Users should treat any request for private keys, seed phrases, passwords, one time verification codes or fund transfers as suspicious. A public wallet address can be shared without giving control of funds, but a private key or recovery phrase controls access to assets. Anyone who receives a message urging immediate action should independently verify the communication through official customer service channels rather than replying directly to the message.

It is also prudent for users to review account activity, strengthen passwords and enable additional authentication where available. While Bits of Gold said passwords were not exposed, password reuse across different services can still create risk if attackers attempt credential stuffing using information obtained elsewhere. Customers should also monitor bank communications closely because bank account details were among the exposed data categories identified by the company.

Vendor Security Moves to the Forefront

The latest incidents across Bits of Gold, SafePal and Trezor underscore a growing challenge for the crypto industry: the attack surface extends beyond exchanges, brokers and wallet makers themselves. External vendors can hold sensitive customer data, process operational information or support key parts of the customer experience. When those vendors are compromised, the reputational and customer protection burden still falls heavily on the crypto brand.

For the broader digital asset industry, this wave of breaches may drive renewed focus on data minimization, vendor audits, access controls and segmentation between customer databases and outside systems. Firms may also face pressure to clarify how long customer information is retained, which vendors can access it and how quickly affected users are notified after an incident is detected.

Market participants are likely to view the Bits of Gold breach as another reminder that crypto security is not limited to blockchain protocols or custody architecture. In many cases, the weakest point is conventional data handling. Names, emails, phone numbers and identity details remain valuable targets, and attackers can turn that information into follow on campaigns long after the initial breach has been contained.

Frequently Asked Questions (FAQs)

What happened at Bits of Gold?

Bits of Gold said hackers accessed personal data for about 200,000 customers through a breach at a third party data analytics provider. The company said it blocked access and disconnected the affected system from information sources after detecting the incident.

What customer information was exposed?

The exposed information includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details and public wallet addresses. The company said scanned identity documents were not exposed.

Were customer funds or crypto assets stolen?

Bits of Gold said funds and digital assets were not involved in the incident. The company also said private keys, passwords and CVV codes were not exposed.

Did hackers get access to private keys?

Bits of Gold said private keys were not exposed. That is important because private keys can allow control over crypto assets, while public wallet addresses do not provide the ability to move funds.

Why is the breach still serious if funds were not touched?

Personal details can be used for phishing, impersonation and identity related fraud. Attackers may use names, contact information, bank details or wallet addresses to make scam messages appear more credible.

Was this breach connected to other crypto incidents?

Bits of Gold said initial findings indicate the attack was part of a broader global incident that affected other companies at the same time. Separate recent breaches also affected nearly 40,000 SafePal users and almost 14,000 Trezor wallet customers.

What should Bits of Gold customers watch for?

Customers should be alert for emails, calls or messages asking for passwords, verification codes, private keys or fund transfers. Bits of Gold said it would never ask customers for those items.

Who is Bits of Gold?

Bits of Gold is a Tel Aviv based cryptocurrency broker founded in 2013. It was the first crypto company in Israel to receive a permanent Financial Services Provider license and has more than 250,000 customers.

What is the broader lesson for crypto users?

Crypto users should protect both wallet credentials and personal data. Even when digital assets remain safe, exposed identity information can increase the risk of targeted scams and follow on fraud attempts.

Photo by Alesia Kozik on Pexels