ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Israeli crypto broker Bits of Gold discloses breach tied to third-party software attack

Bits of Gold, a Tel Aviv-based cryptocurrency broker holding financial services license 56716 from Israel’s Capital Market, Insurance and Savings Authority, notified customers on Aug. 16 that unauthorized access had been found in a third-party system the company uses for customer support and data analysis. The company said it detected the intrusion several days before the notice, cut off the compromised system from its data sources, and alerted regulators.


The breach traces back to a software vendor used by Bits of Gold, not a direct strike on the broker’s own network. Bits of Gold said it was one of potentially hundreds of businesses worldwide caught up in the same attack on the software provider, and that available information does not indicate the company was deliberately singled out. The identity of the software vendor has not been made public.


An initial internal review found that intruders may have reached names, national identification numbers, email addresses, phone numbers, IP addresses, bank account numbers and public cryptocurrency wallet addresses tied to customer accounts. Bits of Gold said digital holdings, account passwords, scanned identification documents, full card numbers and card security codes were not affected, noting that it does not store customers’ private keys or complete card data. The company said it has so far found no sign that any of the exposed data has been used maliciously.


How many customers were affected has not been established. Figures placing the number near 200,000 have spread through social media and crypto news outlets, but Bits of Gold has not confirmed that count. The notice sent to customers did not specify a number of affected records, and the company’s website lists more than 300,000 total customers. No other Israeli firm had been identified as caught up in the same attack at the time of the disclosure.


"Similar to other financial entities, the company will never ask you to provide a password, verification code, or private key, and will not ask you to transfer money or digital assets to another wallet," Bits of Gold said in its customer notice. The company urged customers not to hand over passwords, verification codes or private keys, and not to send money or crypto assets in response to unexpected contact.


Bits of Gold said it has engaged a specialized cyber incident response firm to conduct a full review and that it continues to monitor its systems. It said its platform remains fully operational and that customers do not need to take any account action at this time.


The disclosure follows a separate third-party breach in the crypto industry in which an incident at fulfillment company ShipMonk exposed personal data belonging to 13,689 customers of hardware wallet maker Trezor, raising similar phishing concerns across the sector.


Bits of Gold has not disclosed the confirmed number of affected customers, the identity of the compromised software vendor, or whether the exposed data has been used for fraud. Those details remain outstanding as the investigation continues.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543