Bits of Gold CEO and Co-founder Youval Rouach.

Bits of Gold data breach exposes personal details of up to 250,000 crypto customers

The attack targeted an external analytics provider rather than Bits of Gold directly, raising concerns that stolen information could be used for sophisticated phishing and fraud.

Israeli crypto company Bits of Gold, which has about 250,000 registered customers, reported a cybersecurity incident on Sunday in which customers’ personal information was exposed as part of a global cyberattack targeting an external analytics service provider.
The company said that customer funds and cryptocurrencies were not affected. However, personal information was exposed that could be used to carry out targeted fraud and phishing attacks.
What information was leaked, who was behind the attack, and what should Bits of Gold customers do now? Calcalist breaks it down.
1 View gallery
Youval Rouach Bits of Gold
Youval Rouach Bits of Gold
Bits of Gold CEO and Co-founder Youval Rouach.
(Photo: Yael Tzur)
What happened in the cyber incident at Bits of Gold?
A few days ago, Bits of Gold detected unauthorized access to a supporting system used for data analysis. After discovering the incident, the company disconnected the system from its information sources and launched an investigation with the assistance of a cyber incident response company. It also reported the incident to the relevant authorities, including the Capital Market Authority.
What information was apparently exposed?
The exposed information reportedly included identification and contact details such as full names, ID numbers, phone numbers, email addresses and IP addresses, as well as bank account details and public crypto wallet addresses. A public crypto wallet address is somewhat analogous to a bank account number or email address in the traditional financial system.
The incident potentially affects information belonging to as many as 250,000 registered customers.
Bits of Gold said that customers' crypto assets and funds remain secure. It also said that login passwords, credit card numbers, CVV codes and photographs of identification documents were not exposed.
The company's trading services continue to operate normally.
What is the main danger for customers?
The immediate threat is not necessarily that attackers will gain direct access to customers' accounts. Rather, the exposed information could enable a wave of targeted social engineering and phishing attacks.
A combination of a person's full name, phone number, email address and knowledge that the individual has a crypto trading account can allow attackers to create highly convincing messages or phone calls. They could impersonate Bits of Gold employees, banks, government agencies or law enforcement authorities.
The attacks do not necessarily have to mention cryptocurrency. An attacker who knows a person's identity and contact details can use that information to construct seemingly legitimate requests on a range of subjects.
The growing availability of AI tools makes such attacks potentially more sophisticated and easier to conduct at scale. Attackers can use AI to produce convincing messages, tailor them to individual victims and automate parts of the process.
What should customers do now?
Customers do not need to take technical action on their accounts, such as transferring their funds or cryptocurrencies to another wallet.
But they should exercise heightened caution.
Do not click on suspicious links received by text message or email. Do not provide verification codes, one-time passwords or private keys to anyone. Customers should also be wary of anyone contacting them and claiming to represent Bits of Gold, a bank, a government agency or law enforcement.
Bits of Gold says it will never ask customers for such information.
Customers should also never transfer money or digital currencies to another account or wallet simply because they received an unsolicited request to do so.
Was Bits of Gold directly targeted?
No. The incident originated at Metabase, an international software company that provides analytics and user-behavior services to companies around the world.
The attackers exploited a security vulnerability at the provider, rather than directly breaching Bits of Gold's systems.
Were other Israeli companies affected?
The incident appears to be global and potentially involves hundreds of companies that use Metabase services.
So far, Bits of Gold is the only Israeli company whose name has been officially linked to the incident. However, the Capital Market Authority and the National Cyber Directorate are examining whether other Israeli financial institutions or companies used the same provider and may have been exposed to the vulnerability.
What is Bits of Gold?
Bits of Gold is one of Israel's established cryptocurrency companies and the first active company among nine firms that have received licenses to trade in cryptocurrencies from the Capital Market Authority.
The license means that the company operates under the authority's supervision.
Bits of Gold employs about 55 people and has approximately 250,000 registered customers.
Could an incident like this have been prevented?
Third-party risk is an inherent challenge for companies that rely on external technology providers. Even when a company has strong internal security, a vulnerability at one of its suppliers can expose its data.
The incident therefore illustrates a broader problem in cybersecurity: the security of a financial company can ultimately depend on the weakest link in its technology supply chain.
Metabase is a well-known and established technology provider, and there is currently no indication that Bits of Gold was unusually negligent in selecting it as a supplier.
Nevertheless, the Capital Market Authority is examining the circumstances of the incident, including how Bits of Gold managed the risks associated with the external provider.