Bits of Gold Says Data Breach May Have Exposed Data of Up to 250,000 Customers
Key Takeaways
- •Bits of Gold, described as Israel's largest crypto firm, said a breach may have exposed the personal and financial data of up to 250,000 customers.
- •Bitcoin purchases were halted following the incident, and the disclosure concerns customer data exposure rather than a loss of funds.
- •The company had previously begun investigating a third-party customer data breach, indicating records may have been processed outside systems the broker directly operates.
- •Bits of Gold has operated since 2013 and has been supervised by Israel's anti-money-laundering authority since a 2017 legal amendment classified virtual currencies as financial assets.
- •Exposed personal and financial details could enable phishing, impersonation, and social-engineering attacks that may persist because identity data cannot be reset or revoked.

Bits of Gold, one of Israel's largest cryptocurrency brokers, has disclosed that a data breach may have exposed the personal and financial data of as many as 250,000 customers, making it one of the more significant security incidents to hit a regional crypto platform this year.
What Bits of Gold disclosed
The company said the breach may have exposed customer information, using cautious wording rather than confirming that data was actually stolen. The incident was reported by CoinDesk, which described Bits of Gold as Israel's largest crypto firm.
Bits of Gold has operated since 2013, making it one of the country's longest-running crypto brokers, and it works within a regulated framework: a 2017 amendment to Israel's Prohibition on Money Laundering Law classified virtual currencies as financial assets, bringing crypto service providers under the supervision of the country's anti-money-laundering authority. That status shapes the level of scrutiny applied to how such firms handle customer records.
Separate reporting put the scope at 250,000 users and noted that Bitcoin purchases were halted in the wake of the incident. The disclosure centers on customer data exposure rather than a loss of funds.
Israeli outlet Calcalist also covered the breach as it affected the broker's customer base. The situation follows an earlier disclosure in which the company began investigating a third-party customer data breach. If that third-party origin is confirmed, it would indicate customer records were processed outside systems the broker directly operates — a distinction that puts the spotlight on the security of service providers handling customer data, not only on the platform customers signed up with.
What data may have been exposed
Two categories of information are referenced in the reporting: personal data and financial data. Personal data typically covers the identity details customers submit during onboarding — the kind of information that, unlike a password, cannot simply be reset.
Financial data raises a separate set of concerns, touching on the payment and account details customers use to fund their purchases. When personal and financial information are exposed together, the combination increases both privacy and account-security risks, because attackers can pair identity details with financial context.
Beyond the two categories named in the reporting, no specific data fields have been confirmed. That mixed exposure profile is what elevates the stakes for affected users — a dynamic also seen when an order-tracking flaw exposed data from nearly 40,000 SafePal customers.
Why the breach matters for crypto customers
A breach at a crypto platform can erode customer confidence in how brokers safeguard sensitive records. For a company positioned as Israel's largest crypto firm, the trust dimension is central, particularly given the halt on Bitcoin purchases reported alongside the incident.
Exposure of personal and financial information can create downstream fraud and identity risks, including targeted phishing, impersonation, and social-engineering attempts aimed at customers. These follow-on risks often outlast the breach itself, since exposed identity data cannot be revoked. Data-handling scrutiny has grown across the sector, extending even to how exchanges share user records, as seen in reports that Binance shared user data with Russian investigators.
Affected users should watch for further company updates and any customer guidance Bits of Gold issues on protective steps, along with whether the reported halt on Bitcoin purchases is lifted. With the scope still framed as a potential exposure of up to 250,000 customers, the most important detail to track is whether the company confirms which data was actually accessed.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.