πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
News

Bits of Gold Breach Exposes Data of Up to 250,000 Customers

16 Aug 2026by CryptoJazz Admin1 min read3 views
Bits of Gold Breach Exposes Data of Up to 250,000 Customers

Bits of Gold, Israel's largest regulated cryptocurrency broker, told customers on Sunday that their personal data had been exposed. CryptoSlate, reporting the disclosure, put the count at up to 250,000 people. The intrusion happened several days earlier, through unauthorized access to a supporting data-analysis system, and the exposed fields are the uncomfortable kind: names, national ID numbers, phone numbers, email and IP addresses, bank-account details and public wallet addresses. Passwords, ID-document images, private keys and full card data were not taken. An earlier digest of the incident put the figure at approximately 200,000; the two counts do not reconcile, and we could not establish which supersedes which.

An analytics tool, not the exchange

The suspected way in was not the brokerage platform itself. According to the disclosure, attackers reached a data-analysis system running beside it, and the working theory points at CVE-2026-72898, a vulnerability in self-hosted Metabase, an open-source dashboard product that companies connect to their own databases. Analytics tools hold copies of customer records by design. That is what makes them useful to staff and to intruders alike. Bits of Gold said it disconnected the affected infrastructure, retained an incident-response firm and notified Israel's Capital Market Authority and National Cyber Directorate.

One consumer effect was immediate. CryptoSlate reported that bitcoin purchases through Yellow, the convenience-store app operated by Paz that sold the asset through Bits of Gold, were halted after the breach. For the broker's retail funnel, that is the visible cost. The quieter one is a quarter-million sets of bank and identity details exposed to whoever was inside the system.

Third notice in four days

The disclosure did not arrive alone. On 13 August, hardware-wallet maker Trezor said a breach at ShipMonk, a fulfillment partner, had exposed data on 13,689 of its customers. Wallet maker SafePal, meanwhile, disclosed that order records for 39,798 customers leaked through an authorization flaw in an order-tracking plug-in; the digest carrying that notice logged it Sunday. SafePal said it patched the flaw, hired an independent auditor, took down more than 30 phishing sites and imposed a 90-day retention limit on the data involved.

Proportion matters here. The three incidents involve three companies, three separate systems and, as far as anything published says, no common attacker. Trezor's count is a fraction of Bits of Gold's. In none of the three did funds, seed phrases or private keys move. What links them is the target class: customer records sitting in the systems around crypto firms, shipping, order tracking and analytics, while the vaults themselves held. The week's other security story ran on different rails entirely, with an actively exploited macOS flaw used to plant Monero miners on internet-exposed machines.

What the data is worth now

A bank-account number next to a national ID number is a working kit for impersonation and targeted phishing, and that risk outlives the incident response. SafePal's customers had been reporting phishing attempts since July, before any notice went out. That is the standard afterlife of leaked contact data. How long this class of information should sit on vendor systems at all is already a live argument in the industry; Coinkite suspended a policy that deleted customer data after 120 days earlier this month, pulling in the opposite direction from SafePal's new 90-day limit.

For Bits of Gold, the open item is the count itself. Exposure figures in this industry tend to climb after the first notice, and the spread between the digest's 200,000 and CryptoSlate's 250,000 is already 50,000 people wide on day one. The regulators now hold the notifications. The customers hold the risk.

Read also: Singapore's Triple-A Has Its Hot Wallets Drained

← All news