NewsCryptoBits of Gold Investigates Third-Party Breach That May Expose Data of 200,000 Customers; Crypto Funds Remain Safe

Bits of Gold Investigates Third-Party Breach That May Expose Data of 200,000 Customers; Crypto Funds Remain Safe

Author: Crypto Ninjas·

Key Takeaways

  • Bits of Gold said unauthorized access occurred in a third-party system used for data analysis and customer support.
  • The company said customer funds, crypto assets, passwords, private keys, and full card details were not exposed.
  • Potentially accessible information includes names, ID numbers, email addresses, phone numbers, IP addresses, banking details, and public wallet addresses.
  • Israeli media reported that up to 200,000 customers may be affected, but the company has not confirmed a final figure.
  • Bits of Gold said its trading services are unaffected and customers do not need to take action at this stage.
Bits of Gold Investigates Third-Party Breach That May Expose Data of 200,000 Customers; Crypto Funds Remain Safe

Bits of Gold, an Israel-based crypto brokerage, is investigating a security incident in which an unauthorized party gained access to a third-party system used for data analysis and customer support. The company said its core crypto assets and customer accounts remain secure, but some personal information may have been accessed. According to Israeli media reports, as many as 200,000 customers could be affected.

Unauthorized access to a third-party system

Bits of Gold said the incident occurred several days before customers were notified and was connected to a wider cyberattack involving a software provider used by multiple companies worldwide. That vendor-mediated pattern has become a recurring feature of the threat landscape, as seen in campaigns such as the 2023 MOVEit file-transfer attacks, where a single compromised vendor product cascaded across thousands of downstream organizations, often beyond the security perimeter of the affected companies themselves.

Upon detecting the breach, the company blocked the unauthorized access and cut off the affected system from its information sources. It has also engaged a third-party cybersecurity expert to investigate the hack and has alerted the appropriate authorities; in Israel, security incidents involving personal data fall under reporting obligations set out in the country's privacy regulations, which are overseen by the Privacy Protection Authority.

Information that may have been accessible through the compromised system includes complete names, identification numbers, email addresses, telephone numbers, IP addresses, banking details, and public cryptocurrency wallet addresses.

200,000 customers may be impacted

Israeli media reports suggest approximately 200,000 customers may be impacted, but Bits of Gold has not made public any final tally of affected users, and the 200,000-customer figure has not been independently verified. The company says its investigation of the impacted third-party system is still in progress.

According to information cited in the local press, Bits of Gold is one of Israel's established regulated crypto companies, with more than 300,000 registered customers. The firm has been operating since 2013 and was among the first Israeli crypto companies to be licensed under the regulatory framework that the Israel Securities Authority began applying to digital-asset service providers in 2019, which places such firms under formal regulatory oversight.

The company said it would establish exactly what information was viewed, how many customers were impacted, and whether any data was deleted from the system. The answers to those questions, along with any findings about how the unnamed software provider was compromised, are expected to define the incident's final scope.

Funds and crypto assets were not affected

Bits of Gold stated that the incident was not related to customer funds or digital currencies. Account passwords, private keys, ID-entry door scans, full credit card information, and CVV codes were not leaked, the company said, adding that it does not store any private keys or full card details.

There is also no evidence so far that the potentially exposed data has been used against customers. The trading services of Bits of Gold are unaffected, and customers should not have to take any action as a result of the incident, the company said.

Following the potential data leak, phishing and impersonation attacks remain a primary concern for those whose personal details may have been accessed. That concern has precedent in the crypto industry: after hardware wallet maker Ledger disclosed a 2020 breach of its e-commerce database that exposed personal details of roughly a million customers, affected users were targeted for years with phishing attempts and scam messages built on the leaked information.

Source: Crypto Ninjas