Israeli Crypto Broker Bits of Gold Hit by Third-Party Data Breach
Personal customer data was exposed after a global cyberattack targeted a support system used by the regulated broker.
Israeli regulated cryptocurrency broker Bits of Gold has suffered a data breach that exposed the personal information of its customers. The company confirmed the leak resulted from unauthorized access to a third-party support system used for data analysis, rather than a direct compromise of its own core infrastructure.
According to company reports and reporting from Calcalist, the incident was part of a larger global cyberattack that impacted hundreds of different companies. The exposed data is extensive, including full names, ID numbers, email addresses, phone numbers, and IP addresses. Furthermore, the breach leaked sensitive financial information, specifically bank account details and public cryptocurrency wallet addresses. Bits of Gold explicitly stated in a message to customers, "Your digital assets and funds are safe and were not involved in the incident," confirming that passwords and digital holdings remained secure.
Regulatory Context
Bits of Gold occupies a unique position in the Israeli financial landscape as the first active company to receive a cryptocurrency trading license from the country's Capital Market Authority. Based in Tel Aviv, the broker serves approximately 300,000 registered customers. This regulatory status allows the firm to operate as a bridge between traditional banking systems and the digital asset market, providing a licensed framework for the storage and trading of cryptocurrencies within Israel.
Systemic Third-Party Risk
The breach underscores a growing systemic vulnerability for regulated financial institutions: the reliance on third-party software dependencies. While Bits of Gold maintained the security of its primary vaults and authentication systems, the vulnerability of a secondary support tool was sufficient to leak highly sensitive Know Your Customer (KYC) data. For the affected users, the exposure of government ID numbers and bank details creates a significant long-term risk of identity theft and highly targeted social engineering attacks, such as phishing, where attackers can use the leaked data to appear legitimate.
Future Outlook
As the company continues to manage the aftermath, the industry will be watching how Israeli regulators view the failure of third-party vendor security in licensed firms. While the immediate financial threat to customer funds has been ruled out, the full extent of the data's distribution remains a primary concern. It is not yet confirmed exactly how many of the 300,000 registered users were impacted by the specific third-party system breach, and the company has not yet detailed the specific nature of the global attack that triggered the event.