Israeli broker Bits of Gold says vendor breach exposed data on 200,000 customers
Bits of Gold says a hacker reached a third-party analytics vendor and took names, national ID numbers and bank details for roughly 200,000 customers — about 80% of its user base — with no funds or keys touched.
Bits of Gold, the Tel Aviv-based brokerage that in 2013 became the first Israeli crypto firm to hold a permanent Financial Services Provider licence, disclosed on Sunday that an intruder reached customer records held by a third-party data analytics provider. CoinDesk, reporting the disclosure on Monday, put the number of affected customers at roughly 200,000.
The company's account of what was taken is specific: names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details and public wallet addresses. Its account of what was not taken is equally specific: no funds, no private keys, no passwords, no CVV codes, no scanned identity documents. "Upon detection of the incident, we blocked access and disconnected the system from the information sources, so this access ended," the firm said in the statement quoted by CoinDesk. It said an outside cyber incident response firm is assisting its investigation, and warned customers it will never ask for passwords, verification codes, private keys or fund transfers — the standard follow-on precaution when contact details leak.
It is the third such disclosure in the sector inside a week, and all three run through suppliers rather than the companies themselves. Data on nearly 40,000 SafePal users was taken on Sunday after a vendor compromise, per CoinDesk; data on almost 14,000 Trezor customers was exposed on 13 August after fulfilment partner ShipMonk was breached. Bits of Gold said its initial findings point to a wider global attack that hit multiple companies at once.
Key facts
- ~200,000 customers affected; company reports more than 250,000 total customers — CoinDesk
- Breach disclosed Sunday, 16 August 2026; entry point was a third-party data analytics network — Bits of Gold statement via CoinDesk
- Exposed: names, national ID numbers, emails, phone numbers, IP addresses, bank account details, public wallet addresses — Bits of Gold
- Not exposed, per the company: funds, private keys, passwords, CVV codes, scanned IDs — Bits of Gold
- Prior week: SafePal ~40,000 users; Trezor ~14,000 users via ShipMonk on 13 August — CoinDesk
- Company profile: founded 2013, CEO Youval Rouach, SOC 2 Type 2 certified — CoinDesk
The real-world read
Every substantive detail here comes from the breached company's own statement; no regulator, law-enforcement body or the unnamed vendor has confirmed any of it, and the "broader global incident" framing is the company's own initial finding, not an independent conclusion. That framing conveniently distributes blame.
Three things go unsaid. The vendor is not named. Neither is the date the intrusion began — only the date it was detected and cut off. And 200,000 of 250,000-plus customers is roughly 80% of the book, a proportion the disclosure states only by implication.
"Your digital assets and funds are safe" is true and beside the point. The exposed combination — national ID number, bank account, phone number, verified crypto customer — is the raw material for identity fraud and SIM-swap targeting, and it now sits outside the company's control. No credit monitoring or identity-protection offer was mentioned. The SOC 2 Type 2 certification cited in the company's profile audits Bits of Gold's controls, not its suppliers' — which is precisely where all three of this week's breaches happened.
Opinion, and whose
No analyst forecasts or market calls were attached to this story. Bits of Gold's assessment that the attack was part of a coordinated global campaign is the company's own preliminary view, offered by an interested party, and remains unverified.
Sources
- CoinDesk (17 August 2026) — the sole account, reporting Bits of Gold's Sunday disclosure, the ~200,000 figure, the data categories, direct quotes from the company statement, and the SafePal and Trezor incidents for context. Secondary reporting; its underlying source for the breach details is the company itself.
Nothing here is financial advice.