Bits of Gold, Israel's largest regulated cryptocurrency broker, is investigating a data breach that may have exposed personal information of up to 250,000 customers. The company said in an Aug. 16 notice that an unauthorized party accessed a supporting data-analysis system several days earlier. Customer funds and digital assets remain secure, the firm stressed.
What was exposed
The compromised data includes names, national identity numbers, phone numbers, email and IP addresses, bank-account details, and public crypto wallet addresses. Bits of Gold said account passwords and images of identification documents were not exposed. The company also does not hold customers' private keys, full card details, or CVV codes, limiting the direct financial risk.
How Bits of Gold responded
Bits of Gold blocked access to the affected system, disconnected it from data sources, and brought in a cybersecurity incident-response firm. It also notified regulatory bodies, identified by Israeli media as the Capital Market Authority and the National Cyber Directorate. Customers were advised that no technical action — such as moving funds or crypto assets — was required, but were urged to stay alert for phishing attempts.
Paz halts Bitcoin purchases
The breach rippled into the retail sector. Paz, an Israeli retail and energy giant, temporarily halted Bitcoin purchases on its Yellow convenience store app. Paz said it was not concerned that Yellow customer information had leaked because the two applications lack a direct interface. The broader commercial agreement between Bits of Gold and Paz remains in effect, and Bits of Gold's primary services continue to operate normally.
A familiar pattern
The incident was attributed to an active exploit, CVE-2026-72898, affecting self-hosted releases of Metabase, an analytics software provider. It adds to a growing number of crypto-sector breaches where attackers gain access to customer information without directly compromising digital assets. Bits of Gold, Israel's first licensed virtual asset service provider, now faces the task of reassuring a quarter-million users while regulators review what went wrong.




