NewsCryptoBits of Gold Data Breach Prompts Paz to Halt Bitcoin Purchases Through Yellow App

Bits of Gold Data Breach Prompts Paz to Halt Bitcoin Purchases Through Yellow App

Author: CoinLineup·

Key Takeaways

  • Bits of Gold detected unusual access to its data-analysis system and disconnected it from its data sources while investigating the cyber incident.
  • Paz temporarily froze Bitcoin purchases in the Yellow app until the investigation is completed.
  • Bits of Gold said funds, wallets, passwords, and digital assets were not exposed, but names, contact details, ID numbers, bank account details, and some public wallet addresses may have been affected.
  • Reporting linked the breach to Metabase CVE-2026-72898, a critical vulnerability that Metabase said has been actively exploited and patched in newer releases.
  • Bits of Gold said it notified Israeli authorities, and no public timeline has been announced for restoring Bitcoin buying through Yellow.
Bits of Gold Data Breach Prompts Paz to Halt Bitcoin Purchases Through Yellow App

Bitcoin purchases have been halted after a data breach at Israeli crypto broker Bits of Gold, with fuel and retail group Paz temporarily freezing the option to buy Bitcoin through its Yellow app while an investigation into the security incident continues.

Why Bitcoin purchases were halted

Bits of Gold said it identified unusual access to its data analysis system and disconnected the affected system from its data sources as part of its response to what the company described as a large-scale cyber incident, according to its incident update.

In response, Paz froze the option to buy Bitcoin through the Yellow app until the investigation concludes, CTech reported. Paz said there is no direct interface between the Yellow and Bits of Gold apps.

The pairing gives the incident broader retail reach than a broker-only outage would have: Paz is one of Israel's largest fuel and convenience retailers, and its Yellow app bundles loyalty and payment services with the Bitcoin buying option, putting crypto access in front of mainstream consumers. Bits of Gold, founded in 2013, is among Israel's longest-operating crypto brokers, serving the customer base that made the exposure scale significant.

The pause is a precautionary operational step tied directly to the breach response rather than a market-driven decision. Buying activity was suspended so the platforms could contain the incident before restoring access.

What the breach means for users

For customers, the immediate effect is that planned or pending Bitcoin purchases through Yellow cannot go through until the freeze lifts. The disruption affects buying access, not existing holdings.

Bits of Gold said passwords, verification codes, private keys, ID photos, full credit-card details, CVV codes, customer funds, accounts, wallets, and digital assets were not exposed in the incident. The company said digital assets and funds were not involved.

However, Bits of Gold said names, IP addresses, emails, phone numbers, bank account details, Israeli ID numbers, and some public wallet addresses may have been exposed. That gap matters because personal identifiers of this kind — names, contact details, and national ID numbers — are the raw material for phishing and impersonation attempts, so account-safety and identity concerns persist even though funds appear secure. The scope of the exposure remains a central question, as reporting indicates the breach may have affected a large customer base.

External reporting put the incident at roughly 200,000 affected customers, according to CoinDesk, though Bits of Gold's public notice does not publish a confirmed total affected-user count. That figure remains externally attributed rather than company-confirmed.

The distinction matters: the transaction disruption is temporary and reversible, while the potential exposure of personal data is a longer-running trust question that outlasts the buying freeze itself. The freeze also comes as Bitcoin trades near the levels that have drawn renewed debate over a sell-off around $65,000.

What needs to happen before purchases resume

Reporting has tied the incident to a critical flaw in Metabase, the data-analytics software, specifically CVE-2026-72898, though Bits of Gold's customer notice does not name Metabase or the CVE. That attribution comes from direct reporting rather than company confirmation.

The National Vulnerability Database lists CVE-2026-72898 at the maximum CNA severity of 10.0 CRITICAL, describing a flaw that allows a remote, unauthenticated attacker to inject arbitrary SQL through the reset-password endpoint. Metabase is a widely deployed open-source analytics platform used far beyond the crypto industry, so a maximum-severity flaw of this kind carried relevance for any organization running an unpatched instance, not only crypto platforms.

Metabase said it confirmed active exploitation of the flaw, blocked the attack endpoints, and published minimum safe releases — 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5 — in its security update. Patching to those versions is the remediation step that underpins any safe resumption of service.

Bits of Gold said it notified the relevant authorities, which CTech identified as Israel's Capital Market Authority and the National Cyber Directorate. Bits of Gold was the first company in Israel's market to receive a Capital Market Authority license to provide digital-asset financial services, and licensed providers in the country operate under Capital Market Authority supervision, placing the incident within an established regulatory review process rather than a purely internal one.

Before purchases resume, users will be looking for clear status updates confirming the affected system is secured, the vulnerability is patched, and the investigation with regulators has concluded. No public timeline for restoring Bitcoin buying through Yellow has been set.

The episode is the third crypto-industry data exposure disclosed within roughly a week, following incidents involving SafePal and Trezor vendors, per CoinDesk's reporting. That clustering has kept the security posture of consumer-facing crypto platforms under fresh scrutiny.