Israel's Bits of Gold Confirms Data Breach, Exposing 200,000 Customer Records

The breach exposed specific personal data for roughly 200,000 Bits of Gold customers, including full names, ID numbers, email addresses, IP addresses and phone numbers, creating multiple avenues for phishing and social engineering.
Bits of Gold said the incident involved unauthorized access to a support system used for data analysis as part of a broader global cyber event affecting a software vendor used by the company; the firm blocked the access, disconnected the system from information sources, and has begun a security review with external experts while notifying authorities.
Bits of Gold’s BILS stablecoin project received regulatory traction, with an April 2026 approval to issue the stablecoin pegged 1:1 to the Israeli shekel; the initiative involved partnerships with Solana and Fireblocks and is being audited by EY.
Bits of Gold reiterated that customer funds and private keys were not compromised and that it does not hold customers’ private keys, full credit card details, or CVV codes, underscoring the narrative that the breach targeted data rather than assets.
Bits of Gold, Israel's largest regulated crypto broker, has disclosed a data breach affecting roughly 200,000 customers. Hackers gained unauthorized access to a support system and stole personal data including full names, ID numbers, email addresses, phone numbers, and IP addresses, according to crypto.news and KuCoin.
The company says customer funds and private keys were not touched. But the stolen identity data opens the door to phishing, SIM swapping, and social engineering attacks — putting all 200,000 affected users at serious risk.
Bits of Gold says the breach was not a direct attack on its exchange. Instead, hackers exploited a support system run by an outside software vendor, according to crypto.news. The company described the incident as part of a "broader global cyber event" hitting that vendor's clients.
Once the breach was found, Bits of Gold blocked the unauthorized access and cut the system off from its data sources. The firm brought in outside security experts to review what happened and notified the relevant authorities, Value the Markets reported.
The exposed data is highly sensitive. Hackers got full names, national ID numbers, email addresses, phone numbers, and IP addresses, according to Odaily. This combination is a goldmine for identity theft. A criminal can use it to impersonate a customer, trick them into giving up passwords, or hijack their phone number.
Bits of Gold was clear about what was not taken. The company said it does not store customers' private keys, full credit card numbers, or CVV codes. WEEX noted the firm stressed that digital assets held in cold storage — offline wallets — were never at risk.
Bits of Gold holds Israel's first VASP (Virtual Asset Service Provider) license, making it the country's top regulated crypto broker. The breach is a blow to a company that built its brand on safety and regulatory trust, Value the Markets reported.
The timing is especially awkward. In April 2026, Bits of Gold won approval to issue BILS, a stablecoin pegged 1:1 to the Israeli shekel. The project involves partnerships with Solana and Fireblocks and is being audited by EY. A security scandal could shake confidence in that initiative before it gets off the ground, according to KuCoin.
Security experts warn that 200,000 exposed users are now prime targets. Customers should watch for suspicious emails or texts pretending to be from Bits of Gold. They should also contact their mobile carrier to add a PIN, which makes SIM swapping much harder.
Bits of Gold says it will keep monitoring its systems as the investigation continues. The company urged customers to use two-factor authentication on their accounts. crypto.news noted the firm is working with external security professionals to find the full scope of the breach and prevent future incidents.
Publishers
10
Articles
1
Reach
11