A data breach at Bits of Gold, Israel's largest regulated crypto broker, has led to a temporary suspension of Bitcoin purchases on Paz's Yellow app, with personal data of up to 250,000 users potentially exposed but customer funds reportedly unaffected
Bits of Gold, Israel's largest regulated cryptocurrency broker, is investigating a data breach that may have exposed sensitive personal information for as many as 250,000 customers. The incident has prompted Paz, a major Israeli retail and energy company, to suspend Bitcoin purchases through its Yellow convenience store app while the situation is assessed. According to Bits of Gold, customer funds and digital assets remain secure, but the breach has raised concerns about the risk of fraud and phishing attacks targeting affected users.
Scope of the Breach
The breach involved unauthorized access to a data-analysis system supporting Bits of Gold's operations. The company disclosed that the compromised data may include names, national identity numbers, phone numbers, email addresses, IP addresses, bank account details, and public crypto wallet addresses. Critically, Bits of Gold stated that account passwords and identification document images were not exposed, and the company does not store customers' private keys, full card details, or CVV codes. The incident was linked to an exploit affecting self-hosted versions of Metabase, an analytics software provider, identified as CVE-2026-72898.
Immediate Response and User Impact
Following the breach, Bits of Gold blocked access to the affected system, disconnected it from its data sources, and engaged a cybersecurity incident-response firm. The company also notified Israeli regulators, including the Capital Market Authority and the National Cyber Directorate. Paz, which had integrated Bits of Gold's Bitcoin purchasing service into its Yellow app, temporarily suspended the feature but indicated that Yellow customer data was not at risk due to the lack of a direct interface between the two platforms. The broader commercial relationship between the companies remains in place, and Bits of Gold's main brokerage services continue to operate.
Security Risks and Precautions
While no customer funds or digital assets were reported stolen, the exposure of personal and financial information increases the risk of phishing, social engineering, and fraud attempts. Bits of Gold has advised users to be vigilant for suspicious communications, avoid sharing verification codes or private keys, and reject unsolicited transfer requests. The company emphasized that no technical action, such as moving funds or changing wallets, is required at this time. This incident highlights a growing trend in the crypto sector, where attackers target user data rather than directly compromising digital assets, creating persistent risks for affected individuals.
According to a report from CTech, the breach was attributed to an active exploit in Metabase's self-hosted releases. Bits of Gold's swift response included isolating the compromised system and working with cybersecurity experts to assess the full impact. The company's notification to regulators aligns with increasing scrutiny of crypto service providers' data protection practices, especially as user data breaches become more common across the industry.
In recent months, several crypto firms have faced operational or security challenges that affected user access or confidence. For example, Fold's decision to sell Bitcoin reserves and propose a reverse stock split reflected the pressures companies face in maintaining both security and operational stability amid evolving risks and regulatory expectations.
Bits of Gold is Israel's first licensed virtual asset service provider, operating under the country's regulatory framework for digital asset businesses. The company's handling of the breach and communication with users and regulators will likely be scrutinized as authorities and customers assess the adequacy of its response and ongoing risk management.
As of August 2026, Bits of Gold has not reported any loss of customer funds or confirmed cases of fraud resulting from the breach. The company continues to monitor the situation and has committed to updating users as new information becomes available.
Data from Chainalysis and other blockchain analytics firms indicate that while direct theft of digital assets remains a significant threat, incidents involving the exposure of user data have increased in frequency over the past two years. These breaches often lead to secondary attacks, such as phishing campaigns, that can compromise user accounts or wallets if individuals are not vigilant.
When a crypto service provider suffers a data breach, the immediate risk to user funds may be limited if private keys and passwords are not exposed. However, the release of personal and financial information can enable attackers to craft convincing phishing messages or social engineering attacks. Users should be cautious with any unsolicited communication, especially those requesting sensitive information or transaction approval. Regulatory frameworks increasingly require crypto companies to report breaches and demonstrate robust data protection measures, but the effectiveness of these controls varies widely across jurisdictions and providers.