Data of 250,000 customers at risk: what leaked from Bits of Gold and how customers should act

Israeli crypto firm Bits of Gold reported a data breach affecting 250,000 customers following a cyberattack on a third-party analytics provider. While funds remain secure, the company warns of potential targeted phishing attempts.

CalcalistAuthor: Shaked Green Arava
Source
Data of 250,000 customers at risk: what leaked from Bits of Gold and how customers should act
Photo: Calcalist / צילום: רויטרס

The Israeli crypto company Bits of Gold, which has about 250,000 registered customers, reported a data security incident in which personal details of its customers were exposed as part of a broad global cyberattack on an external analytics service provider. The company emphasizes that customer funds and cryptocurrencies were not affected, but personal details were leaked that could be used for targeted fraud attempts.

What happened?

A few days ago, unauthorized access was identified to a data analysis support system used by Bits of Gold. Upon discovering the incident, the company disconnected the system from data sources and launched an investigation accompanied by a cyber incident response firm, alongside reporting to the relevant authorities, primarily the Capital Markets Authority.

What information was exposed?

Identification and contact details were likely exposed, including:

  • Full names

  • ID numbers

  • Phone numbers

  • Email addresses

  • IP addresses

  • Bank account details

  • Public crypto wallet addresses

The company emphasizes that login passwords, credit card numbers, CVV codes, or photos of ID cards were not exposed. Trading services continue to operate as usual.

What is the main danger?

The immediate danger is not a breach of the account, but a wave of social engineering and targeted phishing attacks. A combination of a full name, phone number, email, and the knowledge that the person holds a crypto trading account allows attackers to create highly credible fake approaches — via SMS, emails, or phone calls — while impersonating company representatives, banks, or law enforcement agencies. The increasing use of AI tools allows attackers to carry out sophisticated impersonation attacks much faster than before.

What should customers do now?

There is no need to perform technical actions on the account (such as changing a password or transferring funds), but high vigilance is required:

  1. Do not click on suspicious links in text messages or emails.

  2. Do not provide verification codes, one-time passwords, or private keys to any party.

  3. Remember: Bits of Gold will never request these details in an unsolicited approach.


Scope of the incident

Bits of Gold was not the direct target of the attack; it was an attack on the international software company Meta Bytes, which provides analytics and user behavior services to hundreds of companies worldwide. In Israel, Bits of Gold is the only company officially linked to the incident so far, but the Capital Markets Authority and the National Cyber Directorate are checking whether other financial entities used the same supplier and were exposed to the vulnerability.

Bits of Gold is the first active company among nine that received a license to trade in cryptocurrencies from the Capital Markets Authority. The company employs about 55 people, serves approximately 250,000 registered customers, and recently signed a cooperation agreement with the Paz Group for purchasing currencies through the Yellow wallet.

Related News