Israel’s leading regulated crypto broker, Bits of Gold, is grappling with the fallout from a cyber incident tied to a third‑party software provider, after discovering that extensive customer data may have been exposed. While the company insists that user funds and account access remain secure, the scope of potentially compromised personal information raises serious concerns about phishing and targeted social engineering.
Third‑party system at the center of the breach
According to the company, the incident stems from unauthorized access to an external system used for customer support and data analysis, rather than Bits of Gold’s core trading infrastructure. Once suspicious activity was identified, the broker says it cut off the affected system from its data sources, blocked further access, and alerted the relevant regulatory and cybersecurity authorities.
Customers were formally notified on August 16, with the firm explaining that it is in the midst of a detailed forensic review supported by a specialist cyber incident response team. Regular trading and account services reportedly continue to operate as normal.
What kind of data may have been exposed
An internal review suggests that a range of sensitive personal and financial details could have been viewed or obtained during the incident. The list includes:
– Full names
– National ID numbers
– Email addresses
– Phone numbers
– IP addresses
– Bank account details
– Public cryptocurrency wallet addresses
Bits of Gold emphasizes that some of the most sensitive data appears to have remained untouched. According to the company, there is no indication of access to:
– Digital asset balances or wallets
– Account passwords
– Private keys
– Scanned identity documents
– Full credit card numbers
– CVV security codes
At this stage, the broker also states it has not found evidence that any exposed data has been actively misused. However, investigators are still working to determine the full scope and impact of the intrusion.
Part of a wider global cyber incident
Bits of Gold links the breach to a broader, international cyber event targeting a software company that provides services to multiple businesses across different regions. Early reports suggest that potentially hundreds of organizations could be affected worldwide.
The name of the compromised software vendor has not been officially disclosed, and available information indicates that Bits of Gold itself was not the primary target but rather collateral damage within a much larger attack on the vendor’s infrastructure.
How many customers might be affected?
Unconfirmed estimates circulating in local media and industry circles suggest that data on roughly 200,000 customers may have been exposed. This figure needs to be treated with caution:
– The official customer notice does not specify how many records were accessed.
– Bits of Gold’s own public materials state that it serves more than 300,000 customers.
– The company has not yet confirmed, denied, or refined the 200,000 figure.
The final number of impacted users will be one of the most important disclosures still pending. Until the forensic review is complete, any specific count remains speculative.
The real immediate threat: phishing and social engineering
Because passwords and funds are said to be intact, the most pressing risk emerging from this incident is not direct theft from customer wallets, but targeted fraud. With access to names, contact information, bank details, and public wallet addresses, criminals can craft extremely convincing messages that mimic legitimate communication from:
– Bits of Gold
– Banks and payment providers
– Other financial or government institutions
Such social engineering attempts could take many forms: fake login alerts, fabricated “security checks,” bogus refund or tax messages, or urgent requests to “verify” an account by providing codes, passwords, or even transferring funds.
What Bits of Gold is telling customers to do
In response, Bits of Gold is strongly warning its users to be vigilant about any incoming communication, whether by email, phone, SMS, or messaging apps. The company has issued clear guidance:
– Do not share passwords, one‑time codes, or private keys with anyone.
– Do not approve transactions or transfers based on unsolicited requests.
– Do not click suspicious links or download attachments from unexpected messages.
– Verify any unusual request by independently contacting the company through known, official channels.
The firm stresses that it will never ask customers to disclose their full password or private keys, nor will it instruct them to move funds to “safe” or “temporary” wallets to resolve security issues.
Another example of third‑party risk in crypto
This incident follows a pattern increasingly seen in the digital asset sector, where attackers target service providers, logistics firms, marketing tools, or support platforms that serve multiple crypto businesses at once. A recent breach at a fulfillment company exposed personal data linked to thousands of hardware wallet customers, raising similar questions about targeted phishing.
In all these cases, it is not the core crypto platforms or wallets that are directly compromised, but the surrounding ecosystem: shipping companies, analytics tools, customer relationship software, and other auxiliary services. This highlights a key weakness in many security strategies: even if a crypto firm protects its own infrastructure well, its users can still be placed at risk if a vendor with access to user data is breached.
Regulatory context: a licensed, supervised crypto broker
Bits of Gold is not a fringe player in the Israeli market. It operates under financial services license number 56716 and presents itself as the first active Israeli crypto company to receive a permanent license from the Capital Market, Insurance and Savings Authority. The broker is one of a handful of entities formally authorized to trade cryptocurrencies under Israel’s evolving regulatory framework.
The company claims a customer base exceeding 300,000 users. Local media describe it as the first currently operating business among nine licensed cryptocurrency trading firms. Its compliance obligations include stringent anti‑money laundering controls, know‑your‑customer procedures, and ongoing supervision by regulators.
The current incident is therefore not only a technical and reputational challenge, but also a regulatory one. Authorities will likely review how Bits of Gold manages vendor risk, data protection, and incident response, and may use the case as a reference point for setting stricter expectations across the industry.
BILS: the shekel‑pegged stablecoin project
In addition to its brokerage activities, Bits of Gold has been expanding its role in Israel’s digital asset landscape through BILS, a stablecoin pegged to the Israeli shekel. The token went through an extended regulatory sandbox that lasted roughly two years.
Regulators granted approval for the issuance and distribution of BILS on April 27, with the company stating that each token is fully backed one‑to‑one by shekels held in reserve. This move widened Bits of Gold’s regulatory profile, bringing it closer to roles traditionally held by payment institutions and potentially setting a benchmark for future local stablecoin initiatives.
Although the breach did not involve stablecoin reserves or on‑chain transactions, any large‑scale data exposure at a licensed issuer may prompt regulators to revisit how customer and transaction data around such projects are stored, processed, and shared with partners.
How Bits of Gold is responding behind the scenes
Beyond the initial containment steps, Bits of Gold says its internal security team is working with an external cyber incident response firm to conduct a thorough investigation. This typically involves:
– Identifying the precise method of intrusion into the third‑party system.
– Determining the time window during which attackers had access.
– Mapping which databases and tables were accessed or exfiltrated.
– Assessing whether attackers moved laterally toward other systems.
– Implementing additional hardening measures and vendor security checks.
The company has also reiterated that its main services remain fully operational and that customers do not need to take any action regarding their accounts, beyond standard security hygiene and extra caution around communications.
What still remains unknown
Several critical questions are still unanswered and will shape the ultimate impact of this incident:
– The confirmed number of customers whose data was actually accessed or copied.
– The identity of the compromised software provider and which of its systems were involved.
– Whether all affected organizations used the same configuration or data‑sharing practices.
– The exact categories and depth of data taken in each case.
– Evidence, if any, that stolen data has been sold, leaked more broadly, or used in fraud.
Regulators, customers, and industry observers will be watching closely for the company’s next public updates. If the 200,000‑customer estimate proves accurate, this would rank among the more significant KYC‑style data exposures in the region’s crypto market.
What customers can do now to protect themselves
While individuals cannot retroactively shield data that may already have been exposed, they can significantly reduce the chances of falling victim to follow‑on attacks. Practical steps include:
– Scrutinize all messages claiming to be from Bits of Gold or your bank. When in doubt, initiate contact yourself via the company’s official app or known phone numbers.
– Enable two‑factor authentication (2FA) on all financial and email accounts, preferably using an authenticator app rather than SMS.
– Monitor bank and crypto accounts for any unusual activity or login attempts and report anomalies immediately.
– Use unique passwords for email, crypto, and banking accounts so that a breach of one service does not automatically compromise others.
– Update security details (such as passwords or PINs) if you suspect any related account may have been targeted.
Customers should assume that personalized phishing attempts may become more sophisticated over the coming weeks and months, especially if attackers test and refine their methods using the exposed information.
Lessons for the broader crypto industry
The Bits of Gold case underscores a broader reality: for regulated crypto businesses, security is no longer just about cold storage, private keys, and internal systems. Data security now hinges on the entire lattice of external partners, from analytics tools and cloud services to support platforms and marketing solutions.
Key takeaways for the industry include:
– Vendor risk management must be treated as a core security discipline, not a secondary concern.
– Contracts with third parties should specify strict data‑handling rules, encryption standards, and rapid incident reporting obligations.
– Regular security assessments and penetration tests should extend to how third‑party tools interact with customer data.
– Transparency in the event of a breach is critical to maintaining user trust, especially for licensed entities.
As regulators worldwide refine how they supervise digital asset companies, events like this are likely to influence new requirements around outsourcing, third‑party audits, and disclosure timelines.
What to watch for next
In the coming weeks, the most important developments will likely include:
– A formal statement from Bits of Gold confirming the number of impacted customers.
– Identification of the compromised software provider and any broader list of affected organizations.
– Any indication that exposed data has appeared on underground markets or has been tied to concrete fraud attempts.
– Potential regulatory responses, including guidance, fines, or new requirements for licensed crypto firms.
Until those details emerge, this incident stands as a reminder that even regulated, long‑standing players in the crypto space are exposed to the vulnerabilities of their partners. For users, heightened caution and strong personal security practices remain the best defense against the secondary threats that follow such breaches.
