Israeli Crypto Broker Bits of Gold Warns Customers After a Data Breach

Bits of Gold says customer assets and passwords were not involved in its security incident. The more immediate concern is a convincing fake alert built around personal details that may have been accessed.
Key Takeaways
- Bits of Gold says an unauthorized party accessed a system used to support data analysis.
- Names, contact details, ID numbers, bank-account details, IP addresses and public wallet addresses may have been accessible.
- The company says customer funds, passwords, private keys and ID-document photos were not involved.
- Customers do not need to take account action, but should be alert to phishing and impersonation attempts.
Israeli crypto broker Bits of Gold disclosed unauthorized access to a system used to support data analysis. The company said the incident formed part of a broader cyber event that affected other companies worldwide.
It said it blocked the access, disconnected the system from its data sources and engaged a specialist cyber-incident response firm. The relevant authorities were notified, according to the notice, and services continue to operate normally.
Bits of Gold did not disclose how many customers may have been affected. Claims that the incident exposed data from 200,000 customers therefore go beyond what the company has confirmed.
The potentially exposed data can make a false message look real
Bits of Gold said an unauthorized party may have accessed names, contact and identification details, including ID numbers, email addresses and phone numbers. The possible data set also includes IP addresses, bank-account details and public crypto-wallet addresses.
The company said it has no indication that the information has been used. Even so, this mix of data can make a phishing attempt more convincing than a generic scam email or text.
A public wallet address does not give anyone control over crypto. It becomes more sensitive when it can be matched with a person’s identity and contact details. That information may help an impostor make a fake customer-support or compliance message sound credible.
Funds, passwords and private keys were not involved, the company says
Bits of Gold said customers’ digital assets and money were not involved in the incident. It also said it does not hold customers’ private keys, full card details or CVV codes.
According to the notice, account passwords and photographs of identification documents were not exposed either.
That narrows the immediate threat. The remaining concern is social engineering: an attacker does not need an account password to send a malicious link, ask for a verification code or urge someone to move crypto to a new wallet.
An unexpected security alert is not a reason to move funds
Bits of Gold says customers do not need to take action in their accounts. Its advice is to stay alert to phishing, impersonation and suspicious messages.
Customers should not click unexpected links, share personal details or verification codes, or move money or crypto because of an unsolicited contact. Bits of Gold says it will never ask for a password, verification code or private key, nor ask customers to transfer money or digital assets to another wallet.
Anyone who receives an alleged security message should contact the company through its stated support address, [[email protected]], rather than replying to the sender or using a link in the message.
The incident comes as crypto is becoming more visible within Israel’s established financial sector. Israel’s largest bank is planning to add Bitcoin trading to its banking app, making clear security communication increasingly important for people accessing digital assets through local financial platforms.
The scope of the incident is still unknown
The notice does not identify the data-analysis system, say whether it belonged to a third-party provider or confirm whether data was extracted. It also does not say whether every category of potentially accessible information applied to every affected customer.
Those details will determine the scale of the incident. The confirmed position is narrower: Bits of Gold says access occurred, certain personal and financial information may have been accessible, and it has found no indication that the information has been used.
The company says its review and system monitoring are ongoing and that it will provide a further update if material information emerges.









