Bits of Gold Leaks 200,000 Customer Records via Third-Party Vendor — And We're Not Even Surprised Anymore
2026-08-17Israel's largest regulated crypto broker, Bits of Gold, got breached in August. Not directly — their own infrastructure stayed clean — but through a third-party vendor supplying support and data-analysis software. Roughly 200,000 customer records went walking.
The compromised vendor was hit as part of a wider global cyber incident affecting multiple companies. Attackers made off with names, national ID numbers, bank account details, emails, IP addresses, and phone numbers. The good news, if you can call it that: customer funds, coins, passwords, ID documents, and credit card data stayed locked away. Bits of Gold blocked the intrusion, disconnected the affected system, and brought in specialist incident-response firms.
This matters because Bits of Gold isn't some scrappy startup. It holds license 56716 under Israel's financial-services regime and was the first active Israeli crypto company to grab a permanent licence from the Capital Market, Insurance and Savings Authority back in 2022. Earlier this year, in April 2026, Israeli regulators approved its BILS stablecoin — a shekel-pegged token that completed roughly two years in regulatory sandbox.
But here's the pattern that's started to feel inevitable: crypto firms aren't getting taken down through their shiny custody infrastructure. They're bleeding through the everyday web junk that keeps the lights on. Shipping vendors. Order-tracking plug-ins. Support software. The boring stuff nobody thinks will sink you.
Same week this landed, Trezor — you know, the hardware wallet people — disclosed a breach at ShipMonk, their shipping partner. About 13,700 customer orders exposed. SafePal took a hit through its order-tracking plug-in, compromising data on roughly 40,000 customers. Supply-chain attacks on crypto firms are becoming the industry's favourite vector.
Why does this matter beyond the headline numbers? Stolen personal data from a crypto broker isn't just an identity-theft risk. Attackers can weaponise it. Phishing campaigns become more convincing when someone knows your real name, your phone number, your bank details. SIM-swap schemes get sharper. Social engineering works better when the criminal can impersonate Bits of Gold or your actual bank with credible-sounding information. A wallet address helps too — attackers can craft messages that feel tailored to you specifically.
Bits of Gold says there's no indication the exposed information has been misused yet. Services remain operational. They're not asking customers to move assets or reset credentials. Which is reasonable — if the data gets actively weaponised, they'll move faster.
The real takeaway here isn't about one broker's security posture. It's that the crypto industry's attack surface keeps expanding, and most of it lives outside the fortress. You can lock down your core trading and custody infrastructure tight as you like. But if your shipping partner, your software vendor, or your support platform gets compromised, it doesn't matter much.
Source & further reading:
- Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers — CoinDesk
- Bitcoin options remain expensive despite summer calm. Here's why it matters — CoinDesk
- Bitcoin's biggest holders, Strategy and Metaplanet, are betting on math, not price — CoinDesk
- Bitpanda fined 70,000 euros in Austria’s first published MiCA enforcement case — CoinDesk
- Bitcoin tracks equity bounce, but $390 million ETF outflow week keeps bulls on back foot — CoinDesk
- Bits of Gold reported to have suffered data breach affecting 200,000 customers — Crypto Briefing
- Hackers hit a Bits of Gold vendor and swept up 200,000 Israeli crypto customers — Startup Fortune
- Israel's Largest Regulated Crypto Broker Bits of Gold Probes Data Leak Potentially Affecting 200,000 Customers — Finance Feeds
- Cyber incident at crypto company Bits of Gold: customers' personal details may have leaked — CTech
- Trezor discloses data breach affecting nearly 14,000 customers — Bleeping Computer
- SafePal says plug-in flaw exposed data of nearly 40,000 customers — Crypto Briefing
- Wallet provider SafePal says data breach exposed personal info of nearly 40,000 customers — The Block
Sources
- Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
- Bitcoin options remain expensive despite summer calm. Here's why it matters
- Bitcoin's biggest holders, Strategy and Metaplanet, are betting on math, not price
- Bitpanda fined 70,000 euros in Austria’s first published MiCA enforcement case
- Bitcoin tracks equity bounce, but $390 million ETF outflow week keeps bulls on back foot
- Bits of Gold reported to have suffered data breach affecting 200,000 customers
- Hackers hit a Bits of Gold vendor and swept up 200,000 Israeli crypto customers
- Israel's Largest Regulated Crypto Broker Bits of Gold Probes Data Leak Potentially Affecting 200,000 Customers
- Cyber incident at crypto company Bits of Gold: customers' personal details may have leaked
- Trezor discloses data breach affecting nearly 14,000 customers
- SafePal says plug-in flaw exposed data of nearly 40,000 customers
- Wallet provider SafePal says data breach exposed personal info of nearly 40,000 customers