Bits of Gold, described by two outlets as Israel’s largest crypto broker, said hackers stole personal data belonging to roughly 200,000 customers. The story broke on Aug. 16 with few specifics about what was actually taken. By Aug. 17, a follow-up carried the company’s own account of exactly which data fields were exposed — and placed the breach inside a broader wave hitting crypto-adjacent vendors.
Crypto Briefing reported on Aug. 16, citing calcalist.co.il, that a hacker had stolen personal data belonging to roughly 200,000 Bits of Gold customers, potentially touching the platform’s entire user base. At that point, Crypto Briefing said the specific types of personal information compromised had not been publicly detailed.
A day later, CoinDesk reported that Bits of Gold had disclosed the breach directly, saying a hacker gained unauthorized access to a third-party data analytics network. According to CoinDesk, the breach compromised a wide set of personal data — customer names and national ID numbers, contact details including phone numbers and email addresses, along with IP addresses, banking information and public wallet addresses. The company said no funds, private keys, passwords, CVV codes or scanned ID documents were exposed.
Bits of Gold said in a statement reported by CoinDesk: “Upon detection of the incident, we blocked access and disconnected the system from the information sources, so this access ended.” The company added it had brought in outside help, saying: “Our security team has begun a comprehensive investigation of the incident, with the assistance of a company specializing in cyber incident investigation and response.” It also sought to reassure customers directly: “It is important to emphasize: your digital assets and funds are safe and were not involved in the incident.”
Both outlets agree on the headline figure — roughly 200,000 affected customers — and both describe Bits of Gold as Israel’s leading regulated crypto broker. That is where the overlap ends.
Crypto Briefing’s Aug. 16 report, sourced to calcalist.co.il, offered no detail on which data categories were stolen. CoinDesk’s Aug. 17 report, carrying the company’s direct statement, filled that gap with a specific list of exposed fields and an explicit denial that funds or credentials were touched.
The two outlets also describe Bits of Gold’s regulatory pedigree differently. Crypto Briefing said the company received Israel’s first VASP license from the Capital Market Authority in September 2022. CoinDesk, by contrast, said Bits of Gold was the first crypto company in Israel to receive a permanent Financial Services Provider license. Neither article clarifies whether these are two names for the same license or two distinct regulatory milestones — an unresolved discrepancy in how Bits of Gold’s founding credential is characterized.
Only CoinDesk reported that the incident fits a broader pattern: it said the Bits of Gold breach was the third data breach reported in the crypto industry within the past week, following breaches affecting nearly 40,000 SafePal users and almost 14,000 Trezor customers, the latter tied to compromise of Trezor’s fulfillment partner, ShipMonk, on Aug. 13. CoinDesk also reported that Bits of Gold’s own initial findings indicate its breach was part of a broader global incident hitting other companies simultaneously — a claim attributed to the company, not independently verified by CoinDesk.
Details found only in CoinDesk’s report include that Bits of Gold has more than 250,000 customers, holds SOC 2 Type 2 certification, was founded in 2013, and is led by CEO Youval Rouach. Details found only in Crypto Briefing’s report include that Bits of Gold received approval in April 2026 to issue the BILS stablecoin, backed 1:1 by the Israeli shekel and developed with Solana and Fireblocks, with auditing by EY.
The identity of the compromised third-party data analytics provider has not been disclosed by either outlet. Whether the Bits of Gold breach shares an attacker or vendor infrastructure with the SafePal and Trezor incidents is, per CoinDesk’s own framing of the company’s findings, still described only as part of a broader incident — not confirmed as linked. It also remains unclear how many of Bits of Gold’s total customer base of over 250,000, as reported by CoinDesk, overlaps with the roughly 200,000 whose data was confirmed stolen.
This is the third vendor-linked crypto data breach disclosed within a week, according to CoinDesk’s reporting, following incidents at SafePal and Trezor. The pattern suggests attackers are targeting the outsourced infrastructure — analytics providers, fulfillment partners — that crypto firms depend on, rather than firms’ own custody systems directly. For Bits of Gold, a company both outlets frame as built on regulatory credibility, the breach tests whether that reputation survives an incident involving customer identity data rather than crypto holdings.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.