Israeli Crypto Firm Bits of Gold Exposes Personal Data of 250,000 Customers in Cyberattack
Bits of Gold, an Israeli cryptocurrency company with approximately 250,000 registered customers, reported a data breach following a global cyberattack on its external analytics service provider, Meta Bytes. The breach exposed personal customer information including full names, ID numbers, phone numbers, email addresses, IP addresses, bank account details, and public crypto wallet addresses. However, the company confirmed that customers' crypto assets and funds remain secure, and sensitive credentials such as passwords, credit card numbers, CVV codes, or ID scans were not compromised.
The unauthorized access was detected when hackers exploited a recently discovered vulnerability in Meta Bytes, a software firm providing user analytics services to hundreds of companies worldwide. Upon discovery, Bits of Gold disconnected the affected system, launched an investigation with cybersecurity experts, and notified relevant authorities including the Israeli Capital Market Authority. While Bits of Gold is the only Israeli company publicly linked to the incident so far, regulators are examining whether other local firms using Meta Bytes were affected.
The primary risk to customers is targeted social engineering and phishing attacks leveraging the leaked personal data combined with knowledge of their crypto trading accounts. Attackers may impersonate company representatives, banks, or government officials via SMS, email, or phone calls to deceive victims. Bits of Gold advises customers to remain vigilant, avoid clicking suspicious links, and never share verification codes, passwords, or private keys. The company emphasized it will never request such information or ask customers to transfer funds following unsolicited contact.
Bits of Gold is the first of nine Israeli firms licensed by the Capital Market Authority to trade cryptocurrencies and recently partnered with Paz Group to enable crypto purchases via the Yellow wallet. The incident highlights the inherent risks of third-party dependencies in financial technology, as security is only as strong as the weakest link. The Capital Market Authority is investigating the breach and the company’s risk management practices to prevent future incidents.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.