CryptoMag
NEWS Published: AUG 19, 2026, 8:55 AM

Bits of Gold Reports Data Breach Affecting 200,000 Customers

Data Breach at Bits of Gold

Bits of Gold, Israel’s largest crypto broker, has reported a data breach affecting approximately 200,000 customers. The company announced that hackers accessed personal data through a third-party data analytics provider, leading to the exposure of names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses.

Security Measures Taken

Following the detection of the breach on Sunday, Bits of Gold stated that they promptly blocked access and disconnected their systems from the compromised sources. Importantly, the company confirmed that no funds, private keys, passwords, CVV codes, or scanned ID documents were compromised during the incident.

Broader Impact on the Crypto Industry

Bits of Gold reported that its initial findings indicate this attack is part of a wider global incident, which has also targeted other firms in the cryptocurrency sector. In the past week alone, three data breaches have been reported within the industry, impacting over 230,000 users. In a separate incident, around 40,000 SafePal users had their data stolen due to a third-party vendor breach. Previously, personal information from nearly 14,000 customers of Trezor wallets was also compromised.

Ongoing Investigation

The company has launched a comprehensive investigation with the assistance of a cybersecurity firm specialized in incident response. Bits of Gold emphasized the safety of its customers’ digital assets by stating, “it is important to emphasize: your digital assets and funds are safe and were not involved in the incident.”

About Bits of Gold

Founded in 2013, Bits of Gold was the first crypto company in Israel to obtain a permanent Financial Services Provider license. The company, led by CEO Youval Rouach, serves more than 250,000 customers and has achieved SOC 2 Type 2 certification. Bits of Gold reassured customers by reminding them that the company would never request passwords, verification codes, private keys, or fund transfers.

Source: coindesk.com