Bits of Gold, a licensed crypto broker in Israel, is investigating a cybersecurity incident that might have put customer identities and financial information at risk following unauthorized access to a third-party system utilized for customer support and data analysis.
Summary
- Bits of Gold has confirmed that funds, cryptocurrencies, passwords, ID scans, and complete card details were not impacted.
- The potentially exposed data may include names, identification numbers, emails, phone numbers, IP addresses, and bank account details.
- The company has linked the breach to a compromised third-party software amid a larger global cyber attack.
- Bits of Gold serves more than 300,000 customers and operates under Israeli financial regulations with the license number 56716.
- BILS received regulatory approval in April following a two-year sandbox period and is fully secured with shekels on a one-to-one basis.
The company notified customers on August 16, explaining that access had been restricted, the affected system was disconnected from its information sources, and relevant authorities were informed, as reported by Calcalist.
In its review, Bits of Gold acknowledged that “certain personal information may have been accessed,” which includes names, ID numbers, emails, phone numbers, IP addresses, bank account details, and public crypto wallet addresses. The company stressed that digital assets, account passwords, scanned ID documents, complete credit card details, and CVV codes were not compromised, asserting that “there is no indication” at this point that the exposed data has been misused.
Bits of Gold connects breach to a larger third-party incident
Bits of Gold indicated that this incident is part of a broader cyber event affecting its software provider and several other companies worldwide. Reports from Calcalist suggest that hundreds of companies could be impacted, and it appears that Bits of Gold was not a specific target. The identity of the compromised software provider remains undisclosed.
Recent reports imply that approximately 200,000 customers may be affected. However, this figure should be approached with caution; the customer notice shared by Calcalist did not specify how many records were compromised, while Bits of Gold asserts it has over 300,000 customers. The company has yet to confirm that 200,000 individuals were affected.
Exposed information may heighten phishing threats
The key immediate concern relates to social engineering rather than direct theft from customer wallets due to this incident. The leakage of names, phone numbers, emails, banking details, and public wallet addresses could enable attackers to create more convincing fraudulent communications masquerading as messages from Bits of Gold, banks, or other financial services. Bits of Gold has issued specific warnings to customers regarding potential phishing and impersonation attempts.
The company urged users not to share passwords, verification codes, or private keys and advised against transferring funds or digital assets in response to unsolicited requests. This caution follows another security breach in the crypto space: as reported by crypto.news, a breach at ShipMonk compromised personal data of 13,689 Trezor customers, raising similar concerns regarding targeted phishing.
Bits of Gold is regulated under Israeli financial law
Bits of Gold operates with the financial services license number 56716. The firm asserts it is the first active Israeli crypto business to obtain a permanent financial services license from the Capital Market, Insurance and Savings Authority. Its website claims over 300,000 customers, while Calcalist describes it as the first actively trading entity among nine licensed to trade cryptocurrencies by the authority.
This year, its regulatory framework broadened with the launch of BILS, a stablecoin pegged to the shekel. Bits of Gold announced that regulators authorized the issuance and distribution of BILS on April 27 after a two-year sandbox evaluation. As highlighted by crypto.news, Israel approved the BILS shekel stablecoin following its regulatory pilot, with Bits of Gold confirming that each token is backed 1:1 by shekels held in reserve.
Next Steps
Bits of Gold has stated that its security team has begun a comprehensive review in collaboration with a specialized cyber incident response company and continues to monitor its systems. Relevant authorities have been notified. Services remain operational, and the company has assured customers that no immediate actions are necessary regarding their accounts.
Future updates are anticipated to include the confirmed number of affected customers, the identity of the compromised software provider, the scope of accessed records, and whether any misuse of the data is uncovered. Until then, the widely reported figure of 200,000 affected customers and the overall extent of the incident remain unverified by Bits of Gold.





