Bits of Gold told customers on 16 August 2026 that hackers reached a third-party data-analytics system and may have taken personal data on about 200,000 people. Names, Israeli national ID numbers, emails, phones, IP addresses, bank-account details, and public crypto wallet addresses are in the company’s inventory. Funds, private keys, passwords, CVV codes, and scanned ID photos are not, the broker says.
If you bought or sold bitcoin through Israel’s first licensed crypto broker, treat this as a confirmed Bits of Gold data breach — vendor-side, not a drained hot wallet. Canonical record: bits-of-gold2026.
What happened in the Bits of Gold data breach
The Tel Aviv broker’s Hebrew security update (16 August) says that several days earlier it found unauthorised access to a supporting analytics system, as part of a wider cyber incident that also hit other companies worldwide. On detection, Bits of Gold blocked access and disconnected the system from information sources so that access ended.
The security team opened a full investigation with an incident-response firm and notified relevant authorities. Services continued as normal. CEO Youval Rouach’s shop — founded 2013, more than 250,000 customers, Israel’s first permanent Financial Services Provider licence for a crypto firm, SOC 2 Type 2 — is telling customers their digital assets were not in the incident.
CoinDesk and DataBreaches.net carried the English summary on 17 August: roughly 200,000 customers, third-party analytics network, same field list, same “funds are safe” line. CoinDesk also noted it is the third crypto-industry personal-data story in a week after SafePal and Trezor — different vendors, same week, same phishing weather.
Bits of Gold has not named the analytics vendor in the public post. Until it does, treat “Bits of Gold support” emails that ask you to “verify with the analytics partner” as hostile. The company will not need your seed or your password to finish its own forensics.
What data was exposed — and what was not
Possibly accessed, per the company (Hebrew post + CoinDesk):
- Name
- Contact and identity details, including national ID number (teudat zehut), email, and phone
- IP address
- Bank account details
- Public cryptocurrency wallet address
Not involved, per Bits of Gold:
- Customer digital assets and funds
- Private keys (the broker says it does not hold customer private keys)
- Full payment-card numbers or CVV
- Account passwords
- Scanned identity-document photos
The company says there is no indication so far that the taken information has been misused. That is an early-investigation sentence, not a guarantee. National ID plus bank details plus a public wallet address is already a complete kit for impersonation, invoice fraud, and “your Bits of Gold withdrawal is stuck — send to this wallet to release it” calls.
What this is not: a chain-reorg, a hot-wallet drain, or a claim that every Israeli crypto user is in the file. The census is about 200,000 customers of this broker, via an analytics system, not the entire Israeli bitcoin market.
Why bank details and national IDs hurt more than an email dump
Hardware-wallet shipping leaks — SafePal (39,798 order records) and Trezor / ShipMonk (13,689) — give attackers a home address and a purchase. This Bits of Gold breach gives them a government ID number and a bank account attached to a known crypto customer. That is a different product.
Israeli national ID numbers are reused across banks, mobile carriers, and government services. Paired with a phone and email, they power SIM-swap social engineering and fake “bank compliance” calls. Paired with a public wallet address, they power a lure that quotes a real deposit you made last year. Paired with bank details, they power SEPA-style or local-transfer fraud that looks like a correction of a Bits of Gold payout.
The company’s own advice is the right shape: you do not need to move coins because of this incident; you do need to assume someone may call you using these fields. Bits of Gold, like other financial firms, will never ask for a password, an authentication code, a private key, or a transfer of funds or digital assets to another wallet.
How the attack is described
Public sources describe unauthorised access to a third-party analytics network, not a named ransomware affiliate on a leak site. Bits of Gold frames it as part of a broader global incident affecting other companies at the same time. That could mean a shared SaaS analytics vendor, a compromised integration token, or a campaign against several crypto firms’ data stacks. The company has not published IOCs or the vendor’s name in the blog post.
On detection: block access, disconnect the system from information sources, hire a specialist IR firm, notify authorities, keep trading services up. That is a containment story. It is not yet a root-cause report. Open questions:
- Which analytics product, and how long it had a live feed of customer fields
- Whether the 200,000 is every customer ever sent to the tool or a subset
- Whether logs show bulk export versus interactive browsing
- Whether other Israeli or global crypto firms using the same vendor will notify this week
Until those answers exist, customers should assume the field list in the post is the working inventory and ignore rumours that “private keys leaked from Bits of Gold.” The company says it does not hold those keys.
Who is at risk
Bits of Gold customers in the ~200,000. If you opened an account, KYC’d, or traded, assume your identity and bank fields may be in the analytics extract even if you have not used the app this year.
People who received payouts to a bank account. IBAN-class details plus a known crypto relationship are catnip for “failed withdrawal / send back” fraud.
Household members who share a phone number on the account. They will get the SMS even if they never traded.
Not automatically every Israeli bitcoin holder. Other exchanges and brokers have their own stacks. Copycat phishing will still name Bits of Gold to people who never had an account.
The unnamed analytics vendor’s other tenants. If this really is a multi-company incident, expect more brand notices. Do not wait for them to treat Bits of Gold-themed calls as live.
What Bits of Gold said
The Hebrew post is short and structured: detection, isolation, IR firm, authorities, funds safe, field list, no action required on the account, watch impersonation, we will never ask for secrets or transfers, more updates if material facts appear, [email protected].
CoinDesk adds company background (licence, SOC 2, 250,000+ customers) and places the story next to SafePal and Trezor. DataBreaches.net syndicated that summary. None of those English pieces replace the primary notice on the company blog. If an email disagrees with the blog, trust the blog you typed yourself — blog.bitsofgold.co.il — not a lookalike.
Industry context: a week of crypto personal data, not stolen seeds
August 2026’s crypto headlines have been about contact graphs and KYC side-cars, not about hardware Secure Elements failing. SafePal’s order-tracking plugin exposed shipping PII. Trezor’s fulfilment partner ShipMonk exposed addresses and phones. Bits of Gold’s analytics vendor exposed identity and bank fields. Three different companies, three different vendors, one user-facing lesson: the dangerous copy is the one that already knows you are a crypto customer.
Brokers sit in a worse seat than hardware brands. They collect national IDs because AML rules say so. They collect bank accounts because fiat on-ramps require them. They send slices of that data to analytics tools because marketing and risk models demand dashboards. Every extra processor is an extra breach surface. SOC 2 on the broker does not magically SOC 2 the analytics tenant.
For Israeli customers the national-ID piece is the sharp edge. Teudat zehut numbers are not a password you rotate. Treat this like a permanent identity-monitoring event, not a one-week password panic.
Was I affected?
Bits of Gold has not published a public lookup form in the notice. The census is “about 200,000 customers.” If you are a customer, plan as if you are in the set until the company tells you otherwise. If you never held an account, you are outside the attested extract — and still inside the phishing audience.
Do not upload your teudat zehut to a random “Bits of Gold breach checker.” Do not send a selfie to a Telegram admin who claims to work at the IR firm.
What you should do after the Bits of Gold breach
- Do not move coins solely because of this notice unless you already typed a seed or password into a fake site. The company says assets and keys were not in the incident.
- Read the official blog at blog.bitsofgold.co.il. Bookmark it. Ignore links in SMS.
- Assume impersonation. Anyone citing your name, last four of national ID, or a wallet address you used with Bits of Gold is not automatically support.
- Never give a password, SMS code, or private key to a caller or email. The company says it will never ask.
- Never send crypto or fiat to “unlock,” “verify,” or “reverse” a Bits of Gold transaction because a stranger told you to.
- Watch your bank account for unexpected mandates or “correction” transfers. Call the bank using the number on the back of your card, not the number in the SMS.
- If your phone number is a login identifier elsewhere, rotate those passwords and turn on MFA. This dump includes phones and emails.
- Tell household members who might answer “Bits of Gold compliance” calls.
- Questions: [email protected] from an address you type yourself — after you have read the blog, not from a reply-to on a random mail.
Phishing you should expect
- WhatsApp or SMS: “Your Bits of Gold withdrawal is pending — confirm IBAN”
- Email with a PDF “IR firm questionnaire” asking for a seed as “proof of control”
- Voice calls that open with your teudat zehut last digits
- Lookalike domains swapping Latin and Hebrew characters in “bitsofgold”
- Fake Bank of Israel or ISA (Israel Securities Authority) notices demanding an immediate transfer
The tell is urgency plus a request for something the real broker already has or should never need. Hang up. Open the app or the site you already use.
How this compares to SafePal and Trezor this week
SafePal: first-party plugin bug, ~40k shipping records, seeds not involved, forum seller later advertised the same corpus. Trezor: ShipMonk Metabase path, ~14k addresses and phones. Bits of Gold: third-party analytics, ~200k, national IDs and bank details. Scale and data types are worse here for identity fraud; hardware-wallet phishing is worse in the other two for seed-stealing. If you are a customer of more than one, you get both problems in the same inbox this month.
Ledger’s older Global-e payment-partner incident is the longer-running version of the same movie: crypto brand, shipping or payments vendor, physical-world PII, years of follow-on phishing. Bits of Gold’s 2026 analytics incident belongs on that shelf, not on the “exchange got drained” shelf.
Canonical record and sources
Canonical BreachHistory page: 2026 Bits of Gold — third-party analytics breach; ~200,000 customers.
Related: SafePal, Trezor / ShipMonk, Ledger / Global-e.
Sources: Bits of Gold security update, CoinDesk, DataBreaches.net.
For customers who used bank transfers
Fiat on-ramps are why this file is dangerous. If Bits of Gold ever paid you in shekels or received a bank transfer from you, assume the account identifiers sitting in analytics may now sit with someone who knows you buy bitcoin. Banks will not call you from a withheld number to “re-KYC Bits of Gold.” If your bank truly needs a conversation, you started it from the app or the branch.
Keep a written log of suspicious calls: date, number, what they already knew. That log helps both Bits of Gold support and your bank’s fraud desk if a real transfer attempt appears.
For other Israeli crypto firms
If you send customer dumps to the same unnamed analytics stack, do not wait for a journalist to call. Inventory which fields leave your VPC. Kill stale API keys. If Bits of Gold’s “broader global incident” line is accurate, you may already be in the same IR war-room you have not staffed yet.
Licensed brokers who advertised SOC 2 this year should still assume processors are in scope for customer notification. Israeli regulators who received Bits of Gold’s notice will ask the next firm why their analytics tenant had national IDs in a dashboard replica.
Reading the “no action required” line
The company said you do not need to take action on your account. That means: do not panic-move coins, do not paste a seed, do not pay a “release fee.” It does not mean ignore the phone. Identity fields do not become harmless because trading continued.
Scammers will quote the no-action line. “Bits of Gold said you don’t need to do anything except confirm this one form.” That is still phishing.
FAQ
Were my bitcoins stolen? The company says no. Assets and private keys were not in the analytics incident.
Should I close my Bits of Gold account? That is a personal choice, not a forensic requirement. Closing an account does not retract a copy of your national ID if it already left.
Is my scanned ID in the dump? Bits of Gold says scanned identity photos were not exposed.
Why 200,000 if they have 250,000+ customers? The notice says about 200,000. That may be the analytics cohort, not the all-time customer count. Until they publish a precise census, customers should assume inclusion.
Will they pay for credit monitoring? The public post does not offer a US-style monitoring product. Israeli customers should watch bank and mobile-account activity directly.
What remains unknown
Vendor name, dwell time, export volume, and whether a forum dump will appear are all open. BreachHistory will update the catalog row if Bits of Gold names the processor or revises the 200,000 figure. Do not treat Telegram screenshots as that update.
Support hygiene for the next month
If you email [email protected], describe the suspicious contact you received. Do not paste seeds, screenshots of authenticator apps, or full bank statements into that thread unless the company asks through the logged-in product. Real IR work does not start with you sending a recovery phrase “for matching.”
If the company later names the analytics vendor, that name will show up on the official blog first. Any LinkedIn recruiter or “vendor IR portal” that appears the same hour is probably a clone. Type URLs. Do not click.