Bits of Gold, Israel’s largest regulated cryptocurrency broker, disclosed on August 16, 2026 that an attacker gained unauthorized access to a third-party data analytics network and took personal data on approximately 200,000 customers.
The exposed fields: names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses.
Bits of Gold blocked access and disconnected the system from its information sources on detection. No funds, private keys, passwords, or card codes were exposed. The company’s own infrastructure was not compromised.
Reporting places the incident within a broader supply-chain compromise believed to have affected hundreds of firms, and it lands in a summer that also produced breaches at SafePal and at Trezor’s shipping partner.
”No Funds Were Taken” Is the Wrong Reassurance
Every crypto breach disclosure leads with the assurance that customer funds are safe. It is true here and it is not the point.
Consider what an attacker holding this specific combination can do. For each of 200,000 people they have: a verified legal identity with national ID number, a bank account, a phone number, and a public wallet address.
The wallet address is the multiplier. Blockchains are public ledgers. Given a wallet address, anyone can look up its complete transaction history and current balance. What this breach produces is not a customer list — it is a ranked list of identified individuals sorted by verifiable crypto holdings, with contact details and home jurisdiction attached.
That enables three attack classes, in ascending order of severity:
Targeted phishing and account takeover. An attacker who knows your name, your national ID number, your bank and your holdings can construct a support-impersonation pretext that no generic phishing filter catches and few customers refuse.
SIM swap. Phone number plus verified identity is the standard input for carrier social engineering. The subsequent step is SMS-based account recovery on every exchange the victim uses.
Physical coercion. This is the one that separates crypto breaches from the rest. Wrench attacks — home invasions targeting people known to hold crypto — have been a documented and rising phenomenon for several years, and the reason they remain relatively rare is that identifying wealthy holders by name and address is hard. A dataset mapping national identities to on-chain balances removes that difficulty for 200,000 people at once.
Bits of Gold’s customers did not lose money in this breach. Some of them now face a durable, non-remediable increase in personal risk, and there is no password reset for it.
The Vendor Was the Attack Surface
Bits of Gold is a regulated broker. Israeli licensing means capital requirements, AML/KYC obligations and supervisory oversight — the reason the company holds national ID numbers and bank details in the first place is regulatory compliance.
None of that regulation extended to the analytics provider.
The pattern is the one we have documented across every sector this year: the regulated entity hardens itself, then ships its regulated data to an unregulated processor for business intelligence, and the processor becomes the breach. It is the same shape as Polymarket’s supply chain compromise in crypto, Craneware’s reach into 2,000 hospitals in healthcare, and the MyDr breach that exposed half of Poland days earlier.
The ITRC’s H1 2026 figures put a number on it: 38 supply chain incidents generated 280.6 million victim notices — a fraction of the incidents producing most of the exposure.
Analytics platforms are a particularly bad instance of the general problem. They exist to receive comprehensive copies of production data, they are procured by growth and product teams rather than security, and the data minimization question — does the analytics vendor need national ID numbers and bank account details to produce a dashboard? — is almost never asked at procurement time.
The answer is no. It was no for Bits of Gold, and it is no for most of the analytics integrations running in most companies reading this.
The Human Layer Again
It is worth noting where crypto losses actually come from now. Coinbase’s $400 million breach was human error, not code — bribed overseas support agents, not a smart contract flaw.
Bits of Gold continues the trend one step further out: not the exchange’s people, not the exchange’s code, but a vendor’s network. The cryptographic core of the industry keeps holding. Everything wrapped around it — support desks, analytics pipelines, shipping partners, KYC processors — keeps failing.
For an industry whose security model is built on the premise that mathematics protects value, the operative threat has become the ordinary enterprise attack surface that surrounds the mathematics.
What Affected Customers Should Do
If you are a Bits of Gold customer, the response is not “change your password” — your password was not taken.
- Move funds to a new wallet address. Your existing address is now linked to your legal identity in a criminal dataset. A new address, funded through a path that does not trivially link back, restores the separation. This is the single highest-value action and most people will not take it.
- Remove SMS from every account recovery path. Your phone number and verified identity are both exposed; SIM swap is the obvious next step. Use hardware keys or an authenticator app.
- Treat all inbound contact as hostile. A caller who knows your national ID number, your bank and your holdings has proven nothing except that they read the breach data.
- Alert your bank. Account details plus verified identity supports fraudulent transfer attempts.
- Reassess physical security if your holdings are significant. This is unpleasant advice and it is the correct advice. Do not discuss holdings publicly, and consider what an attacker who knows your name and approximate balance could learn about your address from other sources.
The company’s disclosure was prompt and its containment sounds correct. Neither undoes the linkage between 200,000 legal identities and 200,000 public ledger entries, which is permanent.
Sources
- CoinDesk — Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
- DataBreaches.Net — Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
- crypto.news — Israel crypto broker Bits of Gold probes customer data breach
- Crypto Economy — Bits of Gold Confirms Major Data Breach Affecting 200,000 Crypto Customers



