Bits of Gold, Israel's largest crypto broker, confirmed this week that a data breach has exposed personal and financial information on roughly 200,000 customers. If that includes you, the immediate question isn't whether your bitcoin is gone — it isn't. This was not a hack of Bits of Gold's exchange or wallets. It was a breach of a third-party analytics tool the company used behind the scenes, and understanding that distinction is the difference between panicking and knowing what to actually do next.
What Happened in the Bits of Gold Data Breach
According to reporting first surfaced by CoinDesk and Israeli outlet Calcalist, attackers got in by exploiting a vulnerability tracked as CVE-2026-72898 in Metabase, a self-hosted business-intelligence tool used by over 100,000 companies worldwide to build dashboards and reports from their internal databases. Bits of Gold ran its own Metabase instance to analyze customer data internally. The flaw let attackers reach into that instance and pull records out — not because Bits of Gold's core trading or custody systems failed, but because a piece of software sitting next to those systems had a hole in it.
This matters because it reframes the story. It's a supply-chain incident: the weak point was a vendor's software, not Bits of Gold's handling of your crypto. The company says it moved quickly once it found out — cutting off access to the compromised system, bringing in an incident-response firm, and notifying Israel's Capital Market Authority and National Cyber Directorate.
Am I Affected, and What Was Actually Taken?
If you have or had a Bits of Gold account, treat yourself as potentially affected — roughly 200,000 customers is close to the platform's entire user base. What leaked is a personal and financial data set: full names, Israeli national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses.
What did not leak, based on the company's disclosure so far, is any funds, account passwords, or private keys. Scanned copies of ID documents also don't appear to be part of the exposed set. In plain terms: someone now has enough information to convincingly pretend to be Bits of Gold, or to pretend to be you when contacting your bank — but they don't have a way to walk into your account and move money out of it directly.
Why This Isn't a Hack of Your Funds
The distinction between a custody breach and a data breach is the whole story here. A custody breach — like an exchange getting drained through a compromised hot wallet — puts your assets at direct risk. A data breach like this one puts your identity at risk instead. The realistic threats are phishing emails that look like they're from Bits of Gold, phone calls impersonating support staff, and fraud attempts against your bank using the account details that leaked.
That's exactly why Bits of Gold's own customer advisory focuses entirely on social engineering: don't share one-time passwords (OTPs) with anyone, don't act on unsolicited calls asking you to move funds, and verify any contact claiming to be from the company through official channels only. If this were a custody breach, the advice would look completely different — it would be about moving funds or rotating keys. It isn't, because that's not what's at risk.
What Should I Do Now?
A few concrete steps, in order of priority. First, be suspicious of any contact referencing your Bits of Gold account, especially anything urgent — a call about a "suspicious login" or an email asking you to "verify" your account by entering a password or OTP is the most likely follow-on attack. Second, watch your bank account and cards for unusual activity, since bank details were part of the leaked set; consider a fraud alert with your bank if you're in Israel. Third, be alert to targeted phishing that uses real personal details — your actual name and ID number — to look credible; that specificity is what makes leaked-data phishing more convincing than the generic kind. Fourth, don't reuse the password you used on Bits of Gold anywhere else, and change it if you haven't already.
What you don't need to do is move your crypto off the platform in a panic or assume your holdings are compromised — the data taken doesn't give anyone a path to your assets.
The Bigger Pattern: A Bad Week for Crypto Data
Bits of Gold is the third crypto-adjacent breach disclosed in about a week, following Trezor and SafePal hardware-wallet data leaks earlier in August. It's worth keeping these separate in your head. The Trezor and SafePal incidents exposed verified names and home addresses tied to hardware-wallet ownership — a physical-safety risk. Bits of Gold exposed identity and banking data tied to exchange accounts — a financial-fraud and impersonation risk. Different victim pools, different data, different threats, even though headlines are lumping them together as one wave of "crypto breaches."
The open thread to watch is regulatory: Israel's Capital Market Authority and National Cyber Directorate are reportedly checking whether other local financial firms ran the same vulnerable Metabase setup. If they find more exposed institutions, this stops being a single-company story and becomes a sector-wide one about how much financial infrastructure quietly depends on the same third-party tools. For now, if you're a Bits of Gold customer, the practical task is narrower: assume your name, ID number, and bank details are out there, and treat every unexpected message referencing your account as a phishing attempt until proven otherwise.
Sources
- https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers
- https://www.calcalistech.com/ctechnews/article/v90cccn73
- https://www.calcalistech.com/ctechnews/article/hkserzkvfe
- https://databreaches.net/2026/08/17/israels-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200000-customers/
- https://cryptoslate.com/bitcoin-purchases-halted-after-data-breach-puts-250000-crypto-users-at-risk/
- https://crypto.news/bits-of-gold-probes-customer-data-breach/